tools:ipdr_watchdog
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
tools:ipdr_watchdog [2024/05/09 18:49] – vignesh | tools:ipdr_watchdog [2024/05/24 13:06] (current) – vignesh | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== IPDR Watchdog ====== | ====== IPDR Watchdog ====== | ||
+ | {{ : | ||
**What is the use of this tool ?** | **What is the use of this tool ?** | ||
Real time IPDR monitoring system that alerts when IPDR is down by sending email and syslog. | Real time IPDR monitoring system that alerts when IPDR is down by sending email and syslog. | ||
| | ||
**How it works ?** \\ | **How it works ?** \\ | ||
- | First it checks the flush logs and compares | + | |
- | | + | * Then it get the location of the log file from Hub-config.xml file |
- | will send mail. | + | * After getting |
+ | | ||
+ | * Then it checks the current log file is new or not.If | ||
+ | * You can run this script for netflow as well as tap mode. You have to provide this in argument | ||
+ | * It checks each engine is flushing or not by fetching each engine log entries | ||
+ | | ||
+ | * The script deliver the alert log to the syslog . You have to configure the email to receive | ||
**Procedure before running the script** | **Procedure before running the script** | ||
Line 17: | Line 24: | ||
* Go to profile0 -> All groups alert -> and click edit option -> change Send to Syslog/ | * Go to profile0 -> All groups alert -> and click edit option -> change Send to Syslog/ | ||
* Log into trisul server and assign a cronjob to run ipdr_watchdog script or you can run manually. | * Log into trisul server and assign a cronjob to run ipdr_watchdog script or you can run manually. | ||
+ | <note important> | ||
**Options** | **Options** | ||
Line 24: | Line 31: | ||
| -c | | -c | ||
| -s | | -s | ||
- | | -k | + | | -k |
+ | | -t | ||
+ | | -r | ||
+ | | -f | ||
+ | If the trisul is running in netflow mode then run the script with -f option or -r option if it is running with tap mode | ||
+ | |||
< | < | ||
Line 42: | Line 55: | ||
** When your system is started after the down stauts you will get this syslog ** \\ | ** When your system is started after the down stauts you will get this syslog ** \\ | ||
May 9 05:55:01 IPDR-TESTING trisul_flushd: | May 9 05:55:01 IPDR-TESTING trisul_flushd: | ||
- | < | + | < |
**Examples without using cronjob** | **Examples without using cronjob** |
tools/ipdr_watchdog.1715260760.txt.gz · Last modified: 2024/05/09 18:49 by vignesh