Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Victor Kirhenshtein

#7396
Punkt 2 ja bi sformuliroval kak "prekratit' dal'nejshuju obrabotku sobitija".

V privedennom primere esli prihodit sobitie SYS_IF_DOWN, to budet sozdan alarm, vipolnen action SendMail_Down_IF, i na etom obrabotka sobitija zavershitsja. T.e. esli daze dal'she budet pravilo

Source Any
Event Any
Severity Any
Action SendMail

to vipolneno ono uze ne budet.

T.e. summiruja - dlja kazdogo sobitija server beret pravila po porjadku, proverjaet sobiti e na sootvestvie usloviju, esli uslovie istinno - vipolnjaet ukazannie v pravile dejstvija. V normal'noj situacii kazdoe sobitie propuskaetsja cherez kazdoe pravilo, no "stop processing" mozet dosrochno prervat' obrabotku sobitija (konechno esli sobitie sootvetstvuet usloviju v pravile).
#7397
Dlja System.ProcessList:

PID ProcessName

Prichem teoreticheski v imeni processa mogut bit' i probeli, t.e. vse chto idet posle pervogo probela i do konca stroki - eto imja processa.


Dlja System.ActiveUserSessions:

"username" "terminal" "client_name"

Best regards,
Victor
#7398
Hello!

You can put interfaces you are not interesting in into "unmanaged" state - then they will be excluded from polling or status calculation. To do so, select interface object in object browser, right-click on it and select "Unmanage". Alternatively, if you need to unmanage multiple interfaces at a time, select switch object in object browser, open "Subordinates" tab, select all interfaces you wish to unmanage, right-click and select "Unmanage".

Best regards,
Victor
#7399
Podozrevaju chto problema kak-to svjazana s tem faktom, chto Windows russkij - no proverit' tak shodu ne mogu, russkogo Windows'a pod rukoj net. Na sledujuschej nedele budu obratno v Rige, postavlju virtual'nuju mashinu i proverju.
#7400
Zapustit'


nxget -l my_host Agent.SupportedEnums


vidast spisok vozmoznih tablic. S kolonkami sloznee - nuzno znat' chto est' chto. Sprashivajte chto nuzno, budu otvechat'. Tak i zadokumentiruem :)
#7401
Naprimer u menja mnogo pravil takogo vida:

any_host event1 - do actions
any_host event2 - do actions
...
any_host eventN - do actions

I ja hochu iskljuchit' odin konkretnij host iz processinga - ja konechno mogu v kazdom pravile propisat' ego i postavit' "Negate", no proshe do togo sdelat' pravilo

bad_host any_event - stop processing

T.e. mozno ispol'zovat' esli snahala idet specializirovannaja obrabotka eventa dlja hostov, a potom - obschee pravilo dlja vseh ostal'nih. Togda v spec. pravilah stavim "stop processing" i obschee pravilo budet prosche.

Nu i mozno kazdoe pravilo otmechat' flazkom "stop processing" - togda budet logika kak u firewall policy - komu-to eto mozet bit' prosche.
#7402
Pro SNMP - ochen' slozno skazat' bez dopolnitel'noj informacii. Mne takuju situaciju poluchit' ne udalos'. Mozet bit' est' vozmoznost' tcpdump'om sobrat' paketi otsilaemie snmpwalk i nxsnmpwalk chtobi ih sravnit'?
#7403
Hello!

It's just a built-in alias for \PhysicalDisk(_Total)\% Disk Time performance counter. It is the percentage of elapsed time that all disk drives were busy servicing read or write requests. It can be used to measure physical disk load, but it is not related to % of CPU time spent on I/O.

Best regards,
Victor
#7404
Quote from: Alex on February 26, 2008, 02:06:38 PM
Еще одна проблема выскочила. Логинюсь под admin все путем. Но если я логинюсь под обычным пользователем пишет: Unable to connect: Access denied. Хотя в dev2 все работало прекрасно. :( Что интересно такая же бодяга как на рабочем сервере, так и на тестовом :( Менял права юзверям, однофигственно. В чем может быть проблема?

Eto bug, vilozil installer s ispravlennoj konsol'ju.
#7405
Quote from: weec on February 26, 2008, 01:47:49 PM
хотелось бы увидеть изменения RC1->RC2

Primerno vot on:

- move dlja template'ov
- "stop processing" flazok v event processing policy
- nxalarm
- Sinhronizacija imen ob'ektov node s DNS
- Interface names polling

Nu i iz nedodelannogo - advanced event corelation.

I razlichnie melkie izmenenija - no SNMP biblioteku ja vrode kak davno uze ne trogal...
#7406
Quote from: Alex on February 26, 2008, 11:45:28 AM
Нашлась проблема с SNMP

# /usr/local/bin/nxsnmpwalk -c public host .1
SNMP Error: Request timed out

при этом

# snmpwalk -c public host .1
SNMPv2-MIB::sysDescr.0 = STRING: SunOS release:5.8 version:Generic_117350-02 machine:sun4u
SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises.99.1.1.3.34
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (31764508) 3 days, 16:14:05.08

A esli poprobovat' zadat' versiju: "-v 1" ili "-v 2c" ?
#7407
AlarmViewer uses Internet Explorer to render the information page, and it looks like after upgrade to IE7 something was broken. We are working on a comletely new Alarm Viewer which will replace the old one.

Best regards,
Victor
#7408
Vilozil RC2 v download/rc.

Best regards,
Victor
#7409
Нет такой возможности пока. Сделал в 0.2.20.

С уважением,
Виктор
#7410
General Support / Re: Securing the agent
February 21, 2008, 09:54:24 PM
It should be safe. Agent will accept connections only from hosts listed in configuration file. Connections from all other addresses will be closed immediatelly without sending or receiving any data. Also, you may configure agent to require additional authentication with shared secret, and to require encrypted connections.

Best regards,
Victor