In case of passive checks as for example SNMP traps or notifications via email from external checking systems, it is not always possible to know if these controls are correctly performed.
This is the reason that made us decide to look for a solution able to ensure that the passive checks are being regularly provided by external applications. To reach our target we opted for the freshness check of Nagios, that as the word itself is suggesting is a check that verifies the freshness of the results provided.
Nagios, in fact, supports freshness checks on host and service passive check results. The freshness check aims to ensure that host and service checks are being passively provided by external applications on a regular basis. In particular, it will be guaranteed that the passive checks are registered in the expected time period. For example, if you have a daily check at 8 a.m., the freshness check will verify that the results are received exactly in that configured time frame.
How does it work?
Nagios performs periodic checks to verify the passive check results for all those hosts and services that have the freshness check enabled.
A “freshness” threshold is calculated for each host or service
For each host/service, the age of its last check result is compared with the freshness threshold.
If last check result is received on a time above the freshness threshold, the check result is considered “stale”.
How is the Freshness Check enabled?
Here the procedure to follow to enable the freshness check:
Enable freshness checking on a host- and service-specific basis by setting the check_freshness option and activating the checkbox near the same option in Monarch
Configure freshness thresholds by setting the freshness_threshold option in your host and service definitions
Configure the check_command option in your host or service definitions to reflect a valid command that should be used to actively check the host or service when it is detected as “stale”
The check_period option in your host and service definitions is used when Nagios determines when a host or service can be checked for freshness, so make sure it is set to a valid timeperiod
I have over 20 years of experience in the IT branch. After first experiences in the field of software development for public transport companies, I finally decided to join the young and growing team of Würth Phoenix. Initially, I was responsible for the internal Linux/Unix infrastructure and the management of CVS software. Afterwards, my main challenge was to establish the meanwhile well-known IT System Management Solution WÜRTHPHOENIX NetEye. As a Product Manager I started building NetEye from scratch, analyzing existing open source models, extending and finally joining them into one single powerful solution. After that, my job turned into a passion: Constant developments, customer installations and support became a matter of personal. Today I use my knowledge as a NetEye Senior Consultant as well as NetEye Solution Architect at Würth Phoenix.
Author
Juergen Vigna
I have over 20 years of experience in the IT branch. After first experiences in the field of software development for public transport companies, I finally decided to join the young and growing team of Würth Phoenix. Initially, I was responsible for the internal Linux/Unix infrastructure and the management of CVS software. Afterwards, my main challenge was to establish the meanwhile well-known IT System Management Solution WÜRTHPHOENIX NetEye. As a Product Manager I started building NetEye from scratch, analyzing existing open source models, extending and finally joining them into one single powerful solution. After that, my job turned into a passion: Constant developments, customer installations and support became a matter of personal. Today I use my knowledge as a NetEye Senior Consultant as well as NetEye Solution Architect at Würth Phoenix.
Elastic 8.16, which comes with NetEye 4.39, made Elastic Universal Profiling generally available for self-hosted installations. This means that NetEye SIEM installations will now be able to take advantage of the continuous profiling solution by Elastic. In this blogpost we'll Read More
In the first part of this series, we explored how Jira Service Management (JSM) helps streamline Incident Management, aligning with ITIL v4 best practices. Incident Management aims to restore normal service operation as quickly as possible after a disruption, ensuring Read More
Hello everyone! Today, I'd like to briefly discuss an improvement to the update and upgrade procedures that we've started to adopt with NetEye 4.39! What we wanted to improve One aspect that made quite an impact was that whenever the Read More
Hello everyone! Today, I’d like to share an exciting improvement we’ve made to the installation and upgrade procedures in NetEye, introducing a faster and more efficient parallel architecture! Why Modernize the Installation and Upgrade Processes? At Würth Phoenix, we strive Read More
Note: This description of a security analyst's daily routine is fictitious. However, the osquery examples have been tested and can therefore be used as a template for your own research. 1. Alarm Detection Today started with a high-severity alarm from our Read More