Hello!
Just installed cacti with thold. What a great stuff!!
For me is just one very important thing is still missed... I wanna not only know when my network links are overused but also know who use them, who puts a lot of traffic on them. So there must be some kind of "thold+netflowmonitor" plugin. One part detects that thershold is reached, send signal to netflow analyzator which make an analysis for last maybe 30 min and sends report via email to administrator. So admin will know that in last 30 min link is used for 90% and that particular source/destenation IPs do that. - Everything in one mail with all graphs.. or just a link to this report in cacti web page.
I think its pretty obvious that that kind of plugin should exist.... but i cant find anything. There is thold and there is flowview. But they are separated.
Am I wrong about non-existence?
With Best Regards for all developers!
thold + flowview = cool reports
Moderators: Developers, Moderators
- TheWitness
- Developer
- Posts: 17061
- Joined: Tue May 14, 2002 5:08 pm
- Location: MI, USA
- Contact:
Re: thold + flowview = cool reports
Thold 0.4.6 is almost there stand alone. However, as a technique, you can combine the following plugins:
1) Thold 0.4.6 and RPN Based Thresholds. An example RPN for a Traffic Graph would be:
|ds:traffic_in|,|query_ifHighSpeed|,1000,8,*,*,/,100,*
Which would provide (I think) percent utilization (oh and your Traffic Template needs ifHighSpeed)
You would log the Thold Triggers and Alarms to Syslog
2) Install Syslog 1.22 and Create Alarms based upon the Substring Matches from the Thold
3) Execute a command based upon that alarm Syslog triggering.
4) Make sure THold is ahead of Syslog in the Plugins Ordering
Mission Impossible, Accomplished.
TheWitness
1) Thold 0.4.6 and RPN Based Thresholds. An example RPN for a Traffic Graph would be:
|ds:traffic_in|,|query_ifHighSpeed|,1000,8,*,*,/,100,*
Which would provide (I think) percent utilization (oh and your Traffic Template needs ifHighSpeed)
You would log the Thold Triggers and Alarms to Syslog
2) Install Syslog 1.22 and Create Alarms based upon the Substring Matches from the Thold
3) Execute a command based upon that alarm Syslog triggering.
4) Make sure THold is ahead of Syslog in the Plugins Ordering
Mission Impossible, Accomplished.
TheWitness
True understanding begins only when we realize how little we truly understand...
Life is an adventure, let yours begin with Cacti!
Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages
For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
Life is an adventure, let yours begin with Cacti!
Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages
For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
Re: thold + flowview = cool reports
Good Day!
Hmm... So, Thold will generate syslog message when thershold is reached. That message will go into syslog server where it will be analysed by server and will trigger some syslog server's alarm which will execute some command (script). Right? But where is netflow info? That script executed by syslog server will do something with netflow analyzator? If so, then this is very tricky thing for me. So mission is not accomplished %)
Anyway thank you!
Best Regards,
elkoba
Hmm... So, Thold will generate syslog message when thershold is reached. That message will go into syslog server where it will be analysed by server and will trigger some syslog server's alarm which will execute some command (script). Right? But where is netflow info? That script executed by syslog server will do something with netflow analyzator? If so, then this is very tricky thing for me. So mission is not accomplished %)
Anyway thank you!
Best Regards,
elkoba
- Howie
- Cacti Guru User
- Posts: 5508
- Joined: Thu Sep 16, 2004 5:53 am
- Location: United Kingdom
- Contact:
Re: thold + flowview = cool reports
Nothing to do with Cacti, but nfsen/nfdump lets you write fairly complex queries against netflow data to generate alerts.
Weathermap 0.98a is out! & QuickTree 1.0. Superlinks is over there now (and built-in to Cacti 1.x).
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
- TheWitness
- Developer
- Posts: 17061
- Joined: Tue May 14, 2002 5:08 pm
- Location: MI, USA
- Contact:
Re: thold + flowview = cool reports
Yea, just took a cursory look. I definately get's the job done. The only way to do better is use a Database, which is supported using flow-tools when using MySQL. But it's so much work.
http://nfsen.sourceforge.net/
TheWitness
http://nfsen.sourceforge.net/
TheWitness
True understanding begins only when we realize how little we truly understand...
Life is an adventure, let yours begin with Cacti!
Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages
For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
Life is an adventure, let yours begin with Cacti!
Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages
For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
- Howie
- Cacti Guru User
- Posts: 5508
- Joined: Thu Sep 16, 2004 5:53 am
- Location: United Kingdom
- Contact:
Re: thold + flowview = cool reports
And I need a 620GB database like I need a hole in my head. (current size of our nfsen data pool - covers a couple of months)TheWitness wrote:Yea, just took a cursory look. I definately get's the job done. The only way to do better is use a Database, which is supported using flow-tools when using MySQL. But it's so much work.
http://nfsen.sourceforge.net/
TheWitness
Weathermap 0.98a is out! & QuickTree 1.0. Superlinks is over there now (and built-in to Cacti 1.x).
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
Who is online
Users browsing this forum: No registered users and 1 guest