Xymon Mailing List Archive search

Problem with false procs Update

2 messages in this thread

list Greg Shea · Thu, 4 Nov 2010 12:21:03 -0400 ·
RESOLVED, skip to bottom for resolution or read on

Hi all,

As reported earlier, http://www.xymon.com/archive/2010/04/msg00058.html
I've been having a problem with false
procs showing up on other pages and causing alerts to go out that aren't
for that host.  Strange trying to 
explain it but for my dev box hobbitdev, I'm only interested in
hobbitd_channel and heartbeat as seen from the
snippet of my hobbit-clients.cfg file  For certain ESX servers I'm
looking for the specific procs listed below
in the ESX VI Servers section.  What's happening is, the procs from the
ESX VI Servers page is merging with the
procs from the HOST hobbitdev 

From hobbitdev procs web page:
hobbitdev - procs Thu Nov 04 10:08:10 EDT 2010  

     
Thu Nov 4 10:08:04 EDT 2010 - Processes NOT ok
G hobbitd_channel (found 6, req. 1 or more)
Y heartbeat (found 0, req. between 1 and 1)
G /usr/sbin/sshd (found 1, req. 1 or more)
R /opt/vmware/vpxa/vpx/vpxa (found 0, req. 1 or more)
R /usr/lib/vmware/hostd/vmware-hostd (found 0, req. 1 or more)
G /usr/sbin/snmpd (found 1, req. 1 or more)
G cron (found 1, req. 1 or more)
G sshd (found 5, req. 1 or more)
...
... 


From hobbit-clients.cfg:
HOST=hobbitdev
        LOAD    40.0 50.0
        PROC    hobbitd_channel
        PROC    heartbeat 1 1 yellow GROUP=HHEARTBEAT
        FILE    /apps/hobbit/server/etc/bb-hosts yellow MTIME>600 TRACK
        FILE    /apps/hobbit/server/etc/hobbit-alerts.cfg yellow
MTIME>600 TRACK
        FILE    /apps/hobbit/server/etc/hobbit-clients.cfg yellow
MTIME>600 TRACK
        PORT    LOCAL=0.0.0.0:1984 TEXT=HobbitD

############################################################
..SNIP..
## ESX VI Servers
PAGE=ESXVI
        LOAD    5.0 8.0
        PROC    /usr/sbin/sshd 1 -1
        PROC    /opt/vmware/vpxa/vpx/vpxa 1 -1
        PROC    /usr/lib/vmware/hostd/vmware-hostd 1 -1
        PROC    /usr/sbin/snmpd 1 -1

############################################################
..SNIP..

DEFAULT
        # These are the built-in defaults.
        #UP      1h
        UP      30m
        LOAD    8.0 10.0
        DISK    "%^/mnt.*|^/cdrom.*" 102 102
        DISK    * 90 95
        MEMPHYS 101 102
        MEMSWAP 85 95
        MEMACT  90 95
        LOG /var/log/messages "%(?-i)NOTICE"
        LOG /var/log/messages "%(?-i)WARNING" COLOR=yellow
        LOG /var/adm/messages "%(?-i)NOTICE" "IGNORE=%(file system
full|disabled dmpnode|di\
sabled path|enabled dmpnode|enabled
path|vx_nospace|vxdmp|dmp_tur_temp_pgr|pure-ftpd|rdftp|\
downloaded|uploaded|Deleted|acl_server|unrecognized
ioctl|Unknown:|exited without|uid 29108\
|unregistered|pcn: possible RX|nfssrv)"


RESOLUTION
In hobbit-clients.cfg there's an entry for ESX VI Servers, well this
doesn't exist.  I'm not
watching those ESX servers from my dev box and there is no entry in
bb-hosts for this as well.
I've removed the PAGE=ESXVI entry from hobbit-clients.cfg and the
"phantom" processes are now
gone.  Sorry for being long winded here, just wanted to post so no one
else runs into this
bone-headed mistake.

Regards
Gregory R Shea
EMC Corporation
list Greg Shea · Thu, 4 Nov 2010 17:09:40 +0000 (UTC) ·
I didn't see this posted so trying again

-----Original Message----- From: shea, greg Sent: Thursday, November 04, 2010 12:21 PM To: 'xymon at xymon.com' Cc: shea, greg Subject: Problem with false procs Update 
quoted from Greg Shea
RESOLVED, skip to bottom for resolution or read on 
Hi all, 
As reported earlier, http://www.xymon.com/archive/2010/04/msg00058.html I've been having a problem with false procs showing up on other pages and causing alerts to go out that aren't for that host.  Strange trying to explain it but for my dev box hobbitdev, I'm only interested in hobbitd_channel and heartbeat as seen from the snippet of my hobbit-clients.cfg file  For certain ESX servers I'm looking for the specific procs listed below in the ESX VI Servers section.  What's happening is, the procs from the ESX VI Servers page is merging with the procs from the HOST hobbitdev 
From hobbitdev procs web page: hobbitdev - procs Thu Nov 04 10:08:10 EDT 2010   
------------------------------------------------------------------------ --------      Thu Nov 4 10:08:04 EDT 2010 - Processes NOT ok G hobbitd_channel (found 6, req. 1 or more) Y heartbeat (found 0, req. between 1 and 1) G /usr/sbin/sshd (found 1, req. 1 or more) R /opt/vmware/vpxa/vpx/vpxa (found 0, req. 1 or more) R /usr/lib/vmware/hostd/vmware-hostd (found 0, req. 1 or more) G /usr/sbin/snmpd (found 1, req. 1 or more) G cron (found 1, req. 1 or more) G sshd (found 5, req. 1 or more) ... ... 
From hobbit-clients.cfg: HOST=hobbitdev         LOAD    40.0 50.0         PROC    hobbitd_channel         PROC    heartbeat 1 1 yellow GROUP=HHEARTBEAT         FILE    /apps/hobbit/server/etc/bb-hosts yellow MTIME>600 TRACK         FILE    /apps/hobbit/server/etc/hobbit-alerts.cfg yellow MTIME>600 TRACK         FILE    /apps/hobbit/server/etc/hobbit-clients.cfg yellow MTIME>600 TRACK         PORT    LOCAL=0.0.0.0:1984 TEXT=HobbitD 
############################################################ ..SNIP.. ## ESX VI Servers PAGE=ESXVI         LOAD    5.0 8.0         PROC    /usr/sbin/sshd 1 -1         PROC    /opt/vmware/vpxa/vpx/vpxa 1 -1         PROC    /usr/lib/vmware/hostd/vmware-hostd 1 -1         PROC    /usr/sbin/snmpd 1 -1 
############################################################ ..SNIP.. 
DEFAULT         # These are the built-in defaults.         #UP      1h         UP      30m         LOAD    8.0 10.0         DISK    "%^/mnt.*|^/cdrom.*" 102 102         DISK    * 90 95         MEMPHYS 101 102         MEMSWAP 85 95         MEMACT  90 95         LOG /var/log/messages "%(?-i)NOTICE"         LOG /var/log/messages "%(?-i)WARNING" COLOR=yellow         LOG /var/adm/messages "%(?-i)NOTICE" "IGNORE=%(file system full|disabled dmpnode|di\ sabled path|enabled dmpnode|enabled path|vx_nospace|vxdmp|dmp_tur_temp_pgr|pure-ftpd|rdftp|\ downloaded|uploaded|Deleted|acl_server|unrecognized ioctl|Unknown:|exited without|uid 29108\ |unregistered|pcn: possible RX|nfssrv)" 


RESOLUTION In hobbit-clients.cfg there's an entry for ESX VI Servers, well this doesn't exist.  I'm not watching those ESX servers from my dev box and there is no entry in bb-hosts for this as well. I've removed the PAGE=ESXVI entry from hobbit-clients.cfg and the "phantom" processes are now gone.  Sorry for being long winded here, just wanted to post so no one else runs into this bone-headed mistake. 
Regards Gregory R Shea EMC Corporation