NetCrunch Knowledge Base

How-tos, troubleshooting and answers about NetCrunch.

How to monitor logs of popular Linux/Unix services by NetCrunch?

Please take note that this tutorial was tested on: CentOS (64-bit) release 6.5 (Final), Fedora(64-bit) release 18 (Spherical Cow). There may be insignificant differences on other Linux distributions

Applies to 9.x 8.x

Requirements to monitor Linux/Unix services using system/service logs:

  1. FTP server
  2. User with system privileges (i.e. SELinux) and access to var/log directory

Steps to configure FTP sensor:

  1. Locate the node where FTP server is installed by either the IP address or the DNS name (to do this follow the instructions below)
  2. Click on Network Atlas View -> Network Atlas -> Nodes -> Details (To locate the node by DNS name scroll down the list until you find the node. To locate the node by IP address, click on the search icon in the top right hand corner , and enter the IP you're looking for)
  3. Double click on the chosen node -> Press F2
  4. Go to Monitoring Sensors -> Add Monitoring Sensor from the drop down menu choose File/FTP
  5. In File path typein the correct file path, and user credentials
  6. Go to Connection Settings and change them to reflect your FTP server configuration

To Create a failed SSH authorization Alert:

  1. Locate the node where FTP server is installed by either the IP address or the DNS name (to do this follow the instructions below)
  2. Click on Network Atlas View -> Network Atlas -> Nodes -> Details (To locate the node by DNS name scroll down the list until you find the node. To locate the node by IP address, click on the search icon in the top right hand corner , and enter the IP you're looking for)
  3. Double click on the chosen node -> Press F2
  4. While in Monitoring Sensors click on File: FTP -> Add Alert -> Create New Alert on Text Log Entry -> Edit event Definition -> Description (here type: SSH authentication failure)
  5. Configure Severity/State/Application group
  6. In Match log line by text enter authentication failure (provided the access log matches entry: Oct 2 10:16:00 DnsHostName sshd[30898]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=IPAddress user=userlog )
  7. Click OK. At this point you have successfully set up your Alert
  8. Newly created Alerts can be found by going to Node -> Alert

To Create a failed authorization Alert (non SSH alert):

  1. Locate the node where FTP server is installed by either the IP address or the DNS name (to do this follow the instructions below)
  2. Click on Network Atlas View -> Network Atlas -> Nodes -> Details (To locate the node by DNS name scroll down the list until you find the node. To locate the node by IP address, click on the search icon in the top right hand corner , and enter the IP you're looking for)
  3. Double click on the chosen node -> Press F2 4.While in Monitoring Sensors click on File: FTP -> Add Alert -> Create New Alert on Text Log Entry -> Edit event Definition -> Description (here type: authentication failure)
  4. Configure Severity/State/Application group
  5. In Match log line by text enter check|authentication|password\sfail (provided the access log matches entry: ... Oct 2 10:17:58 DnsHostName unix_chkpwd[31651]: password check failed for user (userlog) ... ... Oct 2 10:17:58 DnsHostName su: pam_unix(su:auth): authentication failure; logname=test uid=1000 euid=0 tty=pts/0 ruser=test rhost=IPAddress user=userlog ... )

  6. Before clicking OK check off Regular expression box. Click OK.

Note: At this point you have succesfully set up your Alert. Newly created Alerts can be found by going to Node -> Alert

NetCrunch. Answers not just pictures

Maps → Alerts → Automation → Intelligence