Xymon Mailing List Archive search

Bogus hosts filling up alert.log

list David Mills
Tue, 31 Oct 2017 20:54:46 +0000
Message-Id: <user-76aaf967977c@xymon.invalid>

Thx, John!

Here's the output, though I'm not quite sure what to make of it:

.../xymon> /usr/share/xymon/bin/xymoncmd /usr/share/xymon/bin/xymond_alert --test 0FS_96_192_168_22_1__export --color=RED
2017-10-31 15:41:18.587126 Host not found in hosts.cfg - assuming it is on the top page
00081791 2017-10-31 15:41:18 send_alert 0FS_96_192_168_22_1__export:--color=RED state Paging
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 121
00081791 2017-10-31 15:41:18 Failed 'GROUP=phys-dba' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 124
00081791 2017-10-31 15:41:18 Failed 'GROUP=lgcl-dba' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 127
00081791 2017-10-31 15:41:18 Failed 'GROUP=maxi-dba' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 131
00081791 2017-10-31 15:41:18 Failed 'GROUP=unix-sadm' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 134
00081791 2017-10-31 15:41:18 Failed 'GROUP=windows-sadm' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 138
00081791 2017-10-31 15:41:18 Failed 'GROUP=env-mgmt' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 141
00081791 2017-10-31 15:41:18 Failed 'GROUP=tools-adm' (group not in include list)
2017-10-31 15:41:18 Checking criteria for host '0FS_96_192_168_22_1__export', which is not yet defined; some alerts may not immediately fire
00081791 2017-10-31 15:41:18 Matching host:service:dgroup:page '0FS_96_192_168_22_1__export:--color=RED:(NULL):' against rule line 146
00081791 2017-10-31 15:41:18 Failed 'GROUP=net-adm' (group not in include list)

--

~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~
David Mills
Systems Administrator
Northrop Grumman
(XXX) XXX-XXXX (mobile)

-----Original Message-----
From: Xymon [mailto:xymon-bounces at xymon.com] On Behalf Of John Thurston
Sent: Tuesday, October 31, 2017 3:38 PM
To: xymon at xymon.com
Subject: Re: [Xymon] Bogus hosts filling up alert.log

On 10/31/2017 12:31 PM, Mills,David (HHSC Contractor) wrote:
This “host” is not a real client host but an artifact I’ve created on 
the server side to represent a file system I’m monitoring in a 
server-side ext script, so I know it is not announcing it’s presence 
over port 1984. For the life of me I can’t figure out where the alerts 
daemon is running across this hostname.
Do you get any information if you ask xymond_alert to react in the foreground?
xymoncmd xymond_alert --test 0FS_96_192_168_22_1__export_ foo 
--color=red

--
    Do things because you should, not just because you can.

John Thurston    XXX-XXX-XXXX
user-ce4d79d99bab@xymon.invalid
Department of Administration
State of Alaska