Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Node activity

Created: 05 Sep 2010 | 6 comments
Nazim Akbarov's picture
0 0 Votes
Login to vote

There are several hundred nodes connected to my company SIM environment.
Is there any built-in capability to monitor which nodes stopped sending me events?
(for me it means that the node is alive or not).
Can I create an incident when the node stops sending me events after a certain amount of time?
Will appreciate your help.

Comments

Laurent_c's picture
05
Sep
2010
0 Votes 0
Login to vote

Monitor There is a monitor

Monitor

There is a monitor that will create an alert, if you go to rules tab, monitor, system, there are 2 default. One for asset creation and one for monitoring activity.

You set the timeout parameters, I believe it is 400s by default. Note, this will only works for agent/collector/sensor, but not for a node like a syslog device stopping sending event.

Nazim Akbarov's picture
05
Sep
2010
0 Votes 0
Login to vote

Thx Laurent-c.Half of the

Thx Laurent-c.
My environment contains 50% of the nodes reporting through syslog (agentless ciscos, some production unixes).
Is there anyway to monitor their "aliveness" using SIM rules? 
Regards.

Laurent_c's picture
07
Sep
2010
0 Votes 0
Login to vote

If you are running 4.7 there

If you are running 4.7 there is a new type of rule called "X not followed by X"

An example is a system rule called potential Agent Malfunction.

This should be able to monitor the list of IP you need. I will try to see if I can find a good example.

Laurent_c's picture
07
Sep
2010
0 Votes 0
Login to vote

Rule Type "X not followed by X"

It works, I have ran a few test, I need to review the rule but it seems to be doing the job you are looking for. Once I finalise I will post a KB.

Nazim Akbarov's picture
07
Sep
2010
0 Votes 0
Login to vote

lovely. thank you for your

lovely.
thank you for your help and waiting for a KB.

Laurent_c's picture
08
Sep
2010
0 Votes 0
Login to vote

I have the KB nearly ready,

I have the KB nearly ready, but it won't be puplished yet so here is an extract, keep it mind it works well in my environment, the rule is only a example and will need to be tweakd to suit your need.

How to use this rule type to monitor missing host

 

and

 Note: This rule might need to be changed depending of the point product you are collecting from. In the case of UNIX, PIX and Snare Collector, the Logging Device Name is the name of the Appliance forwarding. Depending of the product you want to use, you might need to change this value to match the field you are looking for.

I have not able to attach a exported rule to this forum, but the 2 screenshots should give you a guideline.

Article is TECH139302 (When this will be public)