Balabit - Alerting and monitoring (site 1)
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring
0 as recorded; the design does not say what a zero does there.The thresholds of the appliance's health monitoring and, for every alert the appliance knows, whether it is sent as e-mail, as an SNMP trap, or not at all. As built, alerts went out by e-mail only, to the distribution group scb_mail_group; no alert was sent as an SNMP trap.
| Item | Value |
|---|---|
| Where | SCB web interface, Basic Settings > Alerting & Monitoring |
| Cluster | dc1-s-xblb001, site 1 |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.2.19 "Management – Alerting & Monitoring", three tables |
| Recipients | Set on the Management page: Management and date and time (site 1) |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.19 Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / Value = 80 (%) Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / Email = Yes Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / SNMP = No Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / Value = 70 (%) Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / Email = Yes Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / SNMP = No Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 1 min) Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 5 min) Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 15 min) Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Email = Yes Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Login failed (xcbLoginFailure) / Email = No Basic Settings > Alerting & Monitoring > System related traps > Login failed (xcbLoginFailure) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Successful login (xcbLogin) / Email = No Basic Settings > Alerting & Monitoring > System related traps > Successful login (xcbLogin) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Logout from the management interface (xcbLogout) / Email = No Basic Settings > Alerting & Monitoring > System related traps > Logout from the management interface (xcbLogout) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Configuration changed (xcbConfigChange) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Configuration changed (xcbConfigChange) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > General alert (xcbAlert) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > General alert (xcbAlert) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > General error (xcbError) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > General error (xcbError) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Data and configuration backup failed (xcbBackupFailed) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Data and configuration backup failed (xcbBackupFailed) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Data archiving failed (xcbArchiveFailed) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Data archiving failed (xcbArchiveFailed) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Database error occurred (xcbDBError) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Database error occurred (xcbDBError) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > License limit reached (xcbLimitReached) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > License limit reached (xcbLimitReached) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > HA node state changed (xcbHaNodeChanged) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > HA node state changed (xcbHaNodeChanged) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Timestamping error occurred (xcbTimestampError) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Timestamping error occurred (xcbTimestampError) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Time sync lost (xcbTimeSyncLost) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Time sync lost (xcbTimeSyncLost) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Raid status changed (xcbRaidStatus) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Raid status changed (xcbRaidStatus) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Hardware error occurred (xcbHWError) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Hardware error occurred (xcbHWError) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Firmware is tainted (xcbFirmwareTainted) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Firmware is tainted (xcbFirmwareTainted) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > Too many login attempts (xcbBruteforceAttempt) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > Too many login attempts (xcbBruteforceAttempt) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > License expires soon (xcbLicenseAlmostExpired) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > License expires soon (xcbLicenseAlmostExpired) / SNMP = No Basic Settings > Alerting & Monitoring > System related traps > A system service failed (xcbInitSystemUnitFailed) / Email = Yes Basic Settings > Alerting & Monitoring > System related traps > A system service failed (xcbInitSystemUnitFailed) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Channel opening denied (scbChannelDenied) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Channel opening denied (scbChannelDenied) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection denied (scbConnectionDenied) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection denied (scbConnectionDenied) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated (scbAuthSuccess) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated (scbAuthSuccess) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed (scbAuthFailure) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed (scbAuthFailure) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > SSH host key mismatch (scbSshHostKeyMismatch) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > SSH host key mismatch (scbSshHostKeyMismatch) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > New SSH host key learned (scbSshHostKeyLearned) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > New SSH host key learned (scbSshHostKeyLearned) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection timed out (scbConnectionTimedout) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection timed out (scbConnectionTimedout) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Protocol violation (scbProtocolViolation) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Protocol violation (scbProtocolViolation) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection to the server failed (scbConnectionFailed) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Connection to the server failed (scbConnectionFailed) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated on the gateway (scbGWAuthSuccess) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated on the gateway (scbGWAuthSuccess) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed on the gateway (scbGWAuthFailure) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed on the gateway (scbGWAuthFailure) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > User mapping failed on the gateway (scbUserMappingFailure) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > User mapping failed on the gateway (scbUserMappingFailure) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Decryption of a credential failed (scbCredStoreDecryptError) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Decryption of a credential failed (scbCredStoreDecryptError) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > The requested credential store is closed (scbCredStoreClosed) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > The requested credential store is closed (scbCredStoreClosed) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Failed to unlock credential store (scbCredStoreUnlockFailure) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Failed to unlock credential store (scbCredStoreUnlockFailure) / SNMP = No Basic Settings > Alerting & Monitoring > Traffic related traps > Real-time audit event detected (scbRealTimeAlert) / Email = No Basic Settings > Alerting & Monitoring > Traffic related traps > Real-time audit event detected (scbRealTimeAlert) / SNMP = No
The page path carries the description of each alert and, in brackets, its name as the design gives it.
| Group | What is switched on |
|---|---|
| Health monitoring | Disk above 80 % and swap above 70 % send e-mail. The disk threshold is the same 80 % at which the Management page starts to disconnect clients, so the warning and the cut-off come together |
| System related, 19 alerts | 16 by e-mail; only failed login, successful login and logout of the web interface are off. On are among others configuration change, backup and archive failures, HA node state change, timestamping error, lost time synchronisation, RAID status, tainted firmware, too many login attempts, licence limit and a failed system service |
| Traffic related, 16 alerts | All off: denied channels and connections, user authentication on the server or on the gateway, SSH host keys learned or mismatched, timeouts, protocol violations, credential store events and real-time audit events produce no alert |
| SNMP column | No throughout. Sensu queried the appliance over SNMPv3 (see Local services (site 1)); nothing was pushed as a trap |
The analysis asked for "real-time alerting" on RDP sessions, not blocking but alerting, with an SNMP trap as the preference at the time. In the as-built table the real-time audit event is off for both e-mail and SNMP, and no content policy that would raise one was linked to the RDP channels; see Connection and channel policies.
The exported config.xml of the site 2 cluster (5.0.6, 2018-09-17, element <alert_monitor>) lists the alerts by OID instead of by name. It has the same health thresholds (disk 80, swap 70, the three loads 0), the same 16 traffic alerts all off, and 23 system alerts of which 19 send e-mail: four more than the design's table, presumably alerts that 5.0.6 has and 5.0.3 did not. The material has no table of names for those OIDs, so which four they are I cannot say. Not one alert in site 2 sends a trap either.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
xcbFirmwareTainted | Gone; replaced by xcbFirmwareError with the states "Corrupted" and "Tainted" |
xcbInitSystemUnitFailed, xcbHaNodeChanged, xcbTimeSyncLost, xcbRaidStatus, xcbHWError, xcbBackupFailed, xcbArchiveFailed, xcbTimestampError, xcbBruteforceAttempt, scbAuthFailure | Still in the 9.0 list of traps; xcbRandomGeneratorError is new |
xcbLimitReached, xcbLicenseAlmostExpired | Still listed, although 9.0 has dropped licensing |
| SNMP traps not used | SNMPv3 still offers only MD5 or SHA1 authentication and DES or AES privacy |
An e-mail filter or a Sensu check that matched xcbFirmwareTainted would no longer fire after an upgrade; the alerts listed in the table above kept their names, and the others were not checked.