I didn't see this posted so trying again
-----Original Message----- From: shea, greg Sent: Thursday, November 04, 2010 12:21 PM To: 'xymon at xymon.com' Cc: shea, greg Subject: Problem with false procs Update
RESOLVED, skip to bottom for resolution or read on
Hi all,
As reported earlier, http://www.xymon.com/archive/2010/04/msg00058.html I've been having a problem with false procs showing up on other pages and causing alerts to go out that aren't for that host. Strange trying to explain it but for my dev box hobbitdev, I'm only interested in hobbitd_channel and heartbeat as seen from the snippet of my hobbit-clients.cfg file For certain ESX servers I'm looking for the specific procs listed below in the ESX VI Servers section. What's happening is, the procs from the ESX VI Servers page is merging with the procs from the HOST hobbitdev
From hobbitdev procs web page: hobbitdev - procs Thu Nov 04 10:08:10 EDT 2010
Thu Nov 4 10:08:04 EDT 2010 - Processes NOT ok G hobbitd_channel (found 6, req. 1 or more) Y heartbeat (found 0, req. between 1 and 1) G /usr/sbin/sshd (found 1, req. 1 or more) R /opt/vmware/vpxa/vpx/vpxa (found 0, req. 1 or more) R /usr/lib/vmware/hostd/vmware-hostd (found 0, req. 1 or more) G /usr/sbin/snmpd (found 1, req. 1 or more) G cron (found 1, req. 1 or more) G sshd (found 5, req. 1 or more) ... ...
From hobbit-clients.cfg: HOST=hobbitdev LOAD 40.0 50.0 PROC hobbitd_channel PROC heartbeat 1 1 yellow GROUP=HHEARTBEAT FILE /apps/hobbit/server/etc/bb-hosts yellow MTIME>600 TRACK FILE /apps/hobbit/server/etc/hobbit-alerts.cfg yellow MTIME>600 TRACK FILE /apps/hobbit/server/etc/hobbit-clients.cfg yellow MTIME>600 TRACK PORT LOCAL=0.0.0.0:1984 TEXT=HobbitD
############################################################ ..SNIP..
ESX VI Servers
PAGE=ESXVI LOAD 5.0 8.0 PROC /usr/sbin/sshd 1 -1 PROC /opt/vmware/vpxa/vpx/vpxa 1 -1 PROC /usr/lib/vmware/hostd/vmware-hostd 1 -1 PROC /usr/sbin/snmpd 1 -1
############################################################ ..SNIP..
DEFAULT # These are the built-in defaults. #UP 1h UP 30m LOAD 8.0 10.0 DISK "%^/mnt.*|^/cdrom.*" 102 102 DISK * 90 95 MEMPHYS 101 102 MEMSWAP 85 95 MEMACT 90 95 LOG /var/log/messages "%(?-i)NOTICE" LOG /var/log/messages "%(?-i)WARNING" COLOR=yellow LOG /var/adm/messages "%(?-i)NOTICE" "IGNORE=%(file system full|disabled dmpnode|di\ sabled path|enabled dmpnode|enabled path|vx_nospace|vxdmp|dmp_tur_temp_pgr|pure-ftpd|rdftp|\ downloaded|uploaded|Deleted|acl_server|unrecognized ioctl|Unknown:|exited without|uid 29108\ |unregistered|pcn: possible RX|nfssrv)"
RESOLUTION In hobbit-clients.cfg there's an entry for ESX VI Servers, well this doesn't exist. I'm not watching those ESX servers from my dev box and there is no entry in bb-hosts for this as well. I've removed the PAGE=ESXVI entry from hobbit-clients.cfg and the "phantom" processes are now gone. Sorry for being long winded here, just wanted to post so no one else runs into this bone-headed mistake.
Regards Gregory R Shea EMC Corporation