Skip to content

Help with SQL Expression possibilities :) #229

Description

@jdcoats

I need assistance with an expression for syslog. I have firewall syslog messages example:

Teardown TCP connection 1067175433 for inside:10.1.5.21/60506 to outside:35.184.35.160/443 duration 0:01:27 bytes 18844 TCP FINs from outside 

The objective is to alert on bytes > 200000000 or some threshold.
This doesn't work but shows the spirit of the task anyway

select * from syslog.syslog_incoming where host = 'FTD-Primary' and message like '%bytes > 200000000%'; 

Is there a way to do this without the # being in a column of its own?

Activity

  1. TheWitness commented on Aug 22, 2024

    @TheWitness
    Member

    @jdcoats , I would do use the flowview plugin, and then with your help get those bad boys nailed down. Make sure you have space.

    There is a ticket we've asked for help on. Where if the stream is coming from a FW, we can collect the client indpoint traffic if it relevant.

    The issue then becomes, how to trigger an alert.

    Syslog may be quicker...

  2. TheWitness commented on Aug 22, 2024

    @TheWitness
    Member

    If only my alerting plugin that has the capability to do SQL queries was available and QA'd for normal Cacti. It's specifically designed for RTM. It's out on GitHub but no guarantees that will work for this particular use case. It's called gridalarms.

  3. TheWitness commented on Aug 22, 2024

    @TheWitness
    Member

    It looks and feels a lot like thold but designed for either running scripts or queries.

  4. jdcoats commented on Aug 23, 2024

    @jdcoats
    Author

    it looks to be packaged as a whole new cacti install with a few new plugins in it. Doesn't seem like a simple plugin install.

  5. jdcoats commented on Aug 23, 2024

    @jdcoats
    Author

    That makes a mess

    +
    ![image](https://github.com/user-attachments/assets/6b06ec6c-574d-4d75-ab7f-8ffeb2e11e1c)
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions