mirror of
https://github.com/ntop/ntopng.git
synced 2026-05-23 03:50:20 +00:00
[AlertsK] Implements alert consts builder [AlertsK] alert_threshold_cross.lua [AlertsK] too_many_drops.lua [AlertsK] alert_test_failed.lua [AlertsK] alert_flows_flood.lua alert_tcp_syn_flood.lua lert_tcp_syn_scan.lua [AlertsK] alert_snmp_topology_changed.lua [AlertsK] snmp_device_reset.lua [AlertsK] alert_slow_periodic_activity.lua [AlertsK] alert_port_status_change.lua [AlertsK] alert_port_status_change.lua [AlertsK] alert_port_load_threshold_exceeded.lua [AlertsK] alert_port_errors.lua [AlertsK] alert_port_duplexstatus_change.lua [AlertsK] alert_periodic_activity_not_executed.lua [AlertsK] alert_misbehaving_flows_ratio.lua [AlertsK] alert_influxdb_error.lua [AlertsK] alert_influxdb_dropped_points.lua [AlertsK] alert_dropped_alerts.lua [AlertsK] alert_am_threshold_cross.lua [AlertsK] alert_broadcast_domain_too_large.lua [AlertsK] alert_device_connection.lua [AlertsK] alert_device_connection.lua [AlertsK] alert_host_pool_connection.lua alert_host_pool_disconnection.lua [AlertsK] alert_ghost_network.lua [AlertsK] alert_ip_outsite_dhcp_range.lua [AlertsK] alert_list_download_failed.lua [AlertsK] alert_login_failed.lua [AlertsK] alert_mac_ip_association_change.lua [AlertsK] alert_slow_purge.lua [AlertsK] alert_request_reply_ratio.lua [AlertsK] alert_quota_exceeded.lua [AlertsK] alert_process_notification.lua [AlertsK] alert_nfq_flushed.lua [AlertsK] alert_misconfigured_app.lua alert_new_device.lua [AlertsK] alert_influxdb_export_failure.lua [AlertsK] alert_unresponsive_device.lua [AlertsK] alert_user_activity.lua [AlertsK] alert_user_script_calls_drops.lua [AlertsK] minor fix
76 lines
2.5 KiB
Lua
76 lines
2.5 KiB
Lua
--
|
|
-- (C) 2020 - ntop.org
|
|
--
|
|
|
|
-- ##############################################
|
|
|
|
local alert_builders = {}
|
|
|
|
-- ##############################################
|
|
|
|
-- @brief Prepare an alert table used to generate the alert
|
|
-- @param alert_severity A severity as defined in `alert_consts.alert_severities`
|
|
-- @param alert_subtype A string indicating the subtype for this threshold cross (e.g,. 'bytes', 'active', 'packets', ...)
|
|
-- @param alert_granularity A granularity as defined in `alert_consts.alerts_granularities`
|
|
-- @param metric Same as `alert_subtype`
|
|
-- @param value A number indicating the measure which crossed the threshold
|
|
-- @param operator A string indicating the operator used when evaluating the threshold, one of "gt", ">", "<"
|
|
-- @param threshold A number indicating the threshold compared with `value` using operator
|
|
-- @return A table with the alert built
|
|
function alert_builders.buildThresholdCross(alert_severity, alert_subtype, alert_granularity, metric, value, operator, threshold)
|
|
local threshold_type = {
|
|
alert_subtype = alert_subtype,
|
|
alert_granularity = alert_granularity,
|
|
alert_severity = alert_severity,
|
|
alert_type_params = {
|
|
metric = metric,
|
|
value = value,
|
|
operator = operator,
|
|
threshold = threshold,
|
|
}
|
|
}
|
|
|
|
return threshold_type
|
|
end
|
|
|
|
-- ##############################################
|
|
|
|
-- @brief Prepare an alert table used to generate the alert
|
|
-- @param alert_severity A severity as defined in `alert_consts.alert_severities`
|
|
-- @param device The a string with the name or ip address of the device that connected/disconnected
|
|
-- @return A table with the alert built
|
|
function alert_builders.buildDeviceConnectionDisconnection(alert_severity, device)
|
|
local built = {
|
|
alert_severity = alert_severity,
|
|
alert_type_params = {
|
|
device = device,
|
|
},
|
|
}
|
|
|
|
return built
|
|
end
|
|
|
|
-- ##############################################
|
|
|
|
-- @brief Prepare an alert table used to generate the alert
|
|
-- @param alert_severity A severity as defined in `alert_consts.alert_severities`
|
|
-- @param host_pool The a string with the host pool details
|
|
-- @return A table with the alert built
|
|
function alert_builders.buildPoolConnectionDisconnection(alert_severity, host_pool)
|
|
local host_pools_utils = require("host_pools_utils")
|
|
|
|
local built = {
|
|
alert_severity = alert_severity,
|
|
alert_type_params = {
|
|
host_pools_utils.getPoolName(interface.getId(), host_pool),
|
|
},
|
|
}
|
|
|
|
return built
|
|
end
|
|
|
|
-- ##############################################
|
|
|
|
return alert_builders
|
|
|
|
-- ##############################################
|