thold + flowview = cool reports

General discussion about Plugins for Cacti

Moderators: Developers, Moderators

Post Reply
elkoba
Posts: 2
Joined: Mon Jul 25, 2011 1:52 am

thold + flowview = cool reports

Post by elkoba »

Hello!

Just installed cacti with thold. What a great stuff!!

For me is just one very important thing is still missed... I wanna not only know when my network links are overused but also know who use them, who puts a lot of traffic on them. So there must be some kind of "thold+netflowmonitor" plugin. One part detects that thershold is reached, send signal to netflow analyzator which make an analysis for last maybe 30 min and sends report via email to administrator. So admin will know that in last 30 min link is used for 90% and that particular source/destenation IPs do that. - Everything in one mail with all graphs.. or just a link to this report in cacti web page.

I think its pretty obvious that that kind of plugin should exist.... but i cant find anything. There is thold and there is flowview. But they are separated.

Am I wrong about non-existence?

With Best Regards for all developers! :)
User avatar
TheWitness
Developer
Posts: 17061
Joined: Tue May 14, 2002 5:08 pm
Location: MI, USA
Contact:

Re: thold + flowview = cool reports

Post by TheWitness »

Thold 0.4.6 is almost there stand alone. However, as a technique, you can combine the following plugins:

1) Thold 0.4.6 and RPN Based Thresholds. An example RPN for a Traffic Graph would be:

|ds:traffic_in|,|query_ifHighSpeed|,1000,8,*,*,/,100,*

Which would provide (I think) percent utilization (oh and your Traffic Template needs ifHighSpeed)

You would log the Thold Triggers and Alarms to Syslog

2) Install Syslog 1.22 and Create Alarms based upon the Substring Matches from the Thold

3) Execute a command based upon that alarm Syslog triggering.

4) Make sure THold is ahead of Syslog in the Plugins Ordering

Mission Impossible, Accomplished.

TheWitness
True understanding begins only when we realize how little we truly understand...

Life is an adventure, let yours begin with Cacti!

Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages


For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
elkoba
Posts: 2
Joined: Mon Jul 25, 2011 1:52 am

Re: thold + flowview = cool reports

Post by elkoba »

Good Day!

Hmm... So, Thold will generate syslog message when thershold is reached. That message will go into syslog server where it will be analysed by server and will trigger some syslog server's alarm which will execute some command (script). Right? But where is netflow info? That script executed by syslog server will do something with netflow analyzator? If so, then this is very tricky thing for me. So mission is not accomplished %)

Anyway thank you!


Best Regards,
elkoba
User avatar
Howie
Cacti Guru User
Posts: 5508
Joined: Thu Sep 16, 2004 5:53 am
Location: United Kingdom
Contact:

Re: thold + flowview = cool reports

Post by Howie »

Nothing to do with Cacti, but nfsen/nfdump lets you write fairly complex queries against netflow data to generate alerts.
Weathermap 0.98a is out! & QuickTree 1.0. Superlinks is over there now (and built-in to Cacti 1.x).
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
User avatar
TheWitness
Developer
Posts: 17061
Joined: Tue May 14, 2002 5:08 pm
Location: MI, USA
Contact:

Re: thold + flowview = cool reports

Post by TheWitness »

Yea, just took a cursory look. I definately get's the job done. The only way to do better is use a Database, which is supported using flow-tools when using MySQL. But it's so much work.

http://nfsen.sourceforge.net/

TheWitness
True understanding begins only when we realize how little we truly understand...

Life is an adventure, let yours begin with Cacti!

Author of dozens of Cacti plugins and customization's. Advocate of LAMP, MariaDB, IBM Spectrum LSF and the world of batch. Creator of IBM Spectrum RTM, author of quite a bit of unpublished work and most of Cacti's bugs.
_________________
Official Cacti Documentation
GitHub Repository with Supported Plugins
Percona Device Packages (no support)
Interesting Device Packages


For those wondering, I'm still here, but lost in the shadows. Yearning for less bugs. Who want's a Cacti 1.3/2.0? Streams anyone?
User avatar
Howie
Cacti Guru User
Posts: 5508
Joined: Thu Sep 16, 2004 5:53 am
Location: United Kingdom
Contact:

Re: thold + flowview = cool reports

Post by Howie »

TheWitness wrote:Yea, just took a cursory look. I definately get's the job done. The only way to do better is use a Database, which is supported using flow-tools when using MySQL. But it's so much work.

http://nfsen.sourceforge.net/

TheWitness
And I need a 620GB database like I need a hole in my head. (current size of our nfsen data pool - covers a couple of months)
Weathermap 0.98a is out! & QuickTree 1.0. Superlinks is over there now (and built-in to Cacti 1.x).
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests