Created new event correlation rule with id syno6
This commit is contained in:
@@ -2,4 +2,4 @@
|
||||
# encoding: utf-8
|
||||
|
||||
rule_packs += \
|
||||
[{'id': 'eventconsoletest', 'title': 'Simple rule pack for testing', 'disabled': False, 'rules': [{'id': 'syno5', 'description': 'Drop all messages related SMB', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': True, 'state': -1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '(.*)CIFS(.*)', 'invert_matching': False}, {'id': 'syno4', 'description': 'Drop messages from check_mk-Server', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': True, 'state': -1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '(.*)Gorden(.*)192.168.0.99(.*)', 'invert_matching': False, 'hits': 13}, {'id': 'syno2', 'description': "If system doesn't get its external IP", 'comment': '2022-03-30 caelebfi: check log for messages of failed message about getting the external IP\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 2, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': ['emailcrit'], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*failed to get External IP.*', 'invert_matching': False, 'hits': 0}, {'id': 'syno', 'description': 'If someone get blocked trying to connect to rsync', 'comment': '2022-03-30 caelebfi: modified text to match\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': ['emailwarn'], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*RSYNC.*', 'invert_matching': False, 'hits': 0}, {'id': 'catchall', 'description': 'All events that did not match any rule', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 0, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*', 'invert_matching': False, 'hits': 35}], 'hits': 48}, {'id': 'default', 'title': 'Default rule pack', 'disabled': False, 'rules': [], 'hits': 0}]
|
||||
[{'id': 'eventconsoletest', 'title': 'Simple rule pack for testing', 'disabled': False, 'rules': [{'id': 'syno6', 'description': 'Drop all SYSTEM: Last message repeat', 'comment': '2022-03-31 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': True, 'state': -1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': 'SYSTEM: Last message.*', 'invert_matching': False}, {'id': 'syno5', 'description': 'Drop all messages related SMB', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': True, 'state': -1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '(.*)CIFS(.*)', 'invert_matching': False, 'hits': 20}, {'id': 'syno4', 'description': 'Drop messages from check_mk-Server', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': True, 'state': -1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '(.*)Gorden(.*)192.168.0.99(.*)', 'invert_matching': False, 'hits': 1279}, {'id': 'syno2', 'description': "If system doesn't get its external IP", 'comment': '2022-03-30 caelebfi: check log for messages of failed message about getting the external IP\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 2, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': ['emailcrit'], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*failed to get External IP.*', 'invert_matching': False, 'hits': 0}, {'id': 'syno', 'description': 'If someone get blocked trying to connect to rsync', 'comment': '2022-03-30 caelebfi: modified text to match\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 1, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': ['emailwarn'], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*RSYNC.*', 'invert_matching': False, 'hits': 0}, {'id': 'catchall', 'description': 'All events that did not match any rule', 'comment': '2022-03-30 caelebfi: created rule\n', 'docu_url': '', 'disabled': False, 'drop': False, 'state': 0, 'sl': {'value': 0, 'precedence': 'message'}, 'actions': [], 'actions_in_downtime': True, 'cancel_actions': [], 'cancel_action_phases': 'always', 'autodelete': False, 'event_limit': None, 'match': '.*', 'invert_matching': False, 'hits': 49}], 'hits': 1348}, {'id': 'default', 'title': 'Default rule pack', 'disabled': False, 'rules': [], 'hits': 0}]
|
||||
|
||||
Reference in New Issue
Block a user