LINUXOR.SK ... open source notes ...

Balabit - Alerting and monitoring (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring

noteThe design files this page under "Management"; in the web interface it is a page of its own under Basic Settings. The three load-average thresholds are 0 as recorded; the design does not say what a zero does there.

The thresholds of the appliance's health monitoring and, for every alert the appliance knows, whether it is sent as e-mail, as an SNMP trap, or not at all. As built, alerts went out by e-mail only, to the distribution group scb_mail_group; no alert was sent as an SNMP trap.

ItemValue
WhereSCB web interface, Basic Settings > Alerting & Monitoring
Clusterdc1-s-xblb001, site 1
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.2.19 "Management – Alerting & Monitoring", three tables
RecipientsSet on the Management page: Management and date and time (site 1)

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.19

Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / Value = 80 (%)
Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / Email = Yes
Basic Settings > Alerting & Monitoring > Health monitoring > Disk utilization maximum (xcbDiskFull) / SNMP = No
Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / Value = 70 (%)
Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / Email = Yes
Basic Settings > Alerting & Monitoring > Health monitoring > Swap utilization maximum (xcbSwapFull) / SNMP = No
Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 1 min)
Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 5 min)
Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Value = 0 (maximum load for 15 min)
Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / Email = Yes
Basic Settings > Alerting & Monitoring > Health monitoring > Load average (Number of CPU cores: 24) (xcbLoadAvgHigh) / SNMP = No

Basic Settings > Alerting & Monitoring > System related traps > Login failed (xcbLoginFailure) / Email = No
Basic Settings > Alerting & Monitoring > System related traps > Login failed (xcbLoginFailure) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Successful login (xcbLogin) / Email = No
Basic Settings > Alerting & Monitoring > System related traps > Successful login (xcbLogin) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Logout from the management interface (xcbLogout) / Email = No
Basic Settings > Alerting & Monitoring > System related traps > Logout from the management interface (xcbLogout) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Configuration changed (xcbConfigChange) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Configuration changed (xcbConfigChange) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > General alert (xcbAlert) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > General alert (xcbAlert) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > General error (xcbError) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > General error (xcbError) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Data and configuration backup failed (xcbBackupFailed) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Data and configuration backup failed (xcbBackupFailed) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Data archiving failed (xcbArchiveFailed) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Data archiving failed (xcbArchiveFailed) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Database error occurred (xcbDBError) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Database error occurred (xcbDBError) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > License limit reached (xcbLimitReached) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > License limit reached (xcbLimitReached) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > HA node state changed (xcbHaNodeChanged) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > HA node state changed (xcbHaNodeChanged) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Timestamping error occurred (xcbTimestampError) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Timestamping error occurred (xcbTimestampError) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Time sync lost (xcbTimeSyncLost) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Time sync lost (xcbTimeSyncLost) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Raid status changed (xcbRaidStatus) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Raid status changed (xcbRaidStatus) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Hardware error occurred (xcbHWError) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Hardware error occurred (xcbHWError) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Firmware is tainted (xcbFirmwareTainted) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Firmware is tainted (xcbFirmwareTainted) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > Too many login attempts (xcbBruteforceAttempt) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > Too many login attempts (xcbBruteforceAttempt) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > License expires soon (xcbLicenseAlmostExpired) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > License expires soon (xcbLicenseAlmostExpired) / SNMP = No
Basic Settings > Alerting & Monitoring > System related traps > A system service failed (xcbInitSystemUnitFailed) / Email = Yes
Basic Settings > Alerting & Monitoring > System related traps > A system service failed (xcbInitSystemUnitFailed) / SNMP = No

Basic Settings > Alerting & Monitoring > Traffic related traps > Channel opening denied (scbChannelDenied) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Channel opening denied (scbChannelDenied) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection denied (scbConnectionDenied) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection denied (scbConnectionDenied) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated (scbAuthSuccess) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated (scbAuthSuccess) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed (scbAuthFailure) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed (scbAuthFailure) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > SSH host key mismatch (scbSshHostKeyMismatch) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > SSH host key mismatch (scbSshHostKeyMismatch) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > New SSH host key learned (scbSshHostKeyLearned) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > New SSH host key learned (scbSshHostKeyLearned) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection timed out (scbConnectionTimedout) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection timed out (scbConnectionTimedout) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Protocol violation (scbProtocolViolation) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Protocol violation (scbProtocolViolation) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection to the server failed (scbConnectionFailed) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Connection to the server failed (scbConnectionFailed) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated on the gateway (scbGWAuthSuccess) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User successfully authenticated on the gateway (scbGWAuthSuccess) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed on the gateway (scbGWAuthFailure) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User authentication failed on the gateway (scbGWAuthFailure) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User mapping failed on the gateway (scbUserMappingFailure) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > User mapping failed on the gateway (scbUserMappingFailure) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Decryption of a credential failed (scbCredStoreDecryptError) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Decryption of a credential failed (scbCredStoreDecryptError) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > The requested credential store is closed (scbCredStoreClosed) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > The requested credential store is closed (scbCredStoreClosed) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Failed to unlock credential store (scbCredStoreUnlockFailure) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Failed to unlock credential store (scbCredStoreUnlockFailure) / SNMP = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Real-time audit event detected (scbRealTimeAlert) / Email = No
Basic Settings > Alerting & Monitoring > Traffic related traps > Real-time audit event detected (scbRealTimeAlert) / SNMP = No

The page path carries the description of each alert and, in brackets, its name as the design gives it.

GroupWhat is switched on
Health monitoringDisk above 80 % and swap above 70 % send e-mail. The disk threshold is the same 80 % at which the Management page starts to disconnect clients, so the warning and the cut-off come together
System related, 19 alerts16 by e-mail; only failed login, successful login and logout of the web interface are off. On are among others configuration change, backup and archive failures, HA node state change, timestamping error, lost time synchronisation, RAID status, tainted firmware, too many login attempts, licence limit and a failed system service
Traffic related, 16 alertsAll off: denied channels and connections, user authentication on the server or on the gateway, SSH host keys learned or mismatched, timeouts, protocol violations, credential store events and real-time audit events produce no alert
SNMP columnNo throughout. Sensu queried the appliance over SNMPv3 (see Local services (site 1)); nothing was pushed as a trap

The analysis asked for "real-time alerting" on RDP sessions, not blocking but alerting, with an SNMP trap as the preference at the time. In the as-built table the real-time audit event is off for both e-mail and SNMP, and no content policy that would raise one was linked to the RDP channels; see Connection and channel policies.

The exported config.xml of the site 2 cluster (5.0.6, 2018-09-17, element <alert_monitor>) lists the alerts by OID instead of by name. It has the same health thresholds (disk 80, swap 70, the three loads 0), the same 16 traffic alerts all off, and 23 system alerts of which 19 send e-mail: four more than the design's table, presumably alerts that 5.0.6 has and 5.0.3 did not. The material has no table of names for those OIDs, so which four they are I cannot say. Not one alert in site 2 sends a trap either.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
xcbFirmwareTaintedGone; replaced by xcbFirmwareError with the states "Corrupted" and "Tainted"
xcbInitSystemUnitFailed, xcbHaNodeChanged, xcbTimeSyncLost, xcbRaidStatus, xcbHWError, xcbBackupFailed, xcbArchiveFailed, xcbTimestampError, xcbBruteforceAttempt, scbAuthFailureStill in the 9.0 list of traps; xcbRandomGeneratorError is new
xcbLimitReached, xcbLicenseAlmostExpiredStill listed, although 9.0 has dropped licensing
SNMP traps not usedSNMPv3 still offers only MD5 or SHA1 authentication and DES or AES privacy

An e-mail filter or a Sensu check that matched xcbFirmwareTainted would no longer fire after an upgrade; the alerts listed in the table above kept their names, and the others were not checked.

← solutionz