09-14-2007 12:28 AM
Empowering IPN Citizens through tools! IronPort’s Top 10 3rd Party Tools are listed below. Reply to this post to share your favorite 3rd party tools.
For IronPort Unsupported Contributed Tools visit the Support Portal.: http://tinyurl.com/3c5l8r
IRONPORT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, WITH RESPECT TO THE PACKAGES, POSTS OR THIRD PARTY TOOLS, INCLUDING WITHOUT LIMITATION ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT, OR ARISING FROM COURSE OF PERFORMANCE, DEALING, USAGE OR TRADE. IRONPORT DOES NOT PROVIDE ANY SUPPORT SERVICES FOR THE PACKAGES, POSTS OR THIRD PARTY TOOLS.
06-13-2009 10:24 PM
We use Nagios (http://www.nagios.org) for monitoring our Ironports.
Nagios support several plugins and has an active community developing plugins to check a variety of systems.
We use the check_ironport plugin to retrieve useful info then the HTTP(s) XML pages and the standard check_snmp plugin for the additional stuff like the hardware status.
With these two we have setup a quite robust monitoring system for our Ironports, including event forwarding to the corporate TE/C monitoring environment.
If anyone wants to have a copy of our Nagios checks, just send me a reply.
Besides this we use syslog-ng http://www.balabit.com/network-security/syslog-ng/opensource-logging-system/ (on our syslog host).
This tool allows us to filter several types of info’s from the Ironport logfiles and store those into separate logfiles. We have for example a logfile that logs all the “commit” actions and the supplied comments, a logfile that displays all the AV actions, a logfile that records all spoofed messages (by logging a custom X-header we add for spoofing) etc.
And the best of all: it supports syslog traffic over TCP (just like Ironport does)
(now we need to find someone who can convert the findevent command to a useful version on our syslog host) :)
Steven
02-24-2010 08:50 AM
steven_geerts wrote:
If anyone wants to have a copy of our Nagios checks, just send me a reply.
Steven
Hi Steven, we're looking into the possiblity of using Nagios to monitor some of our IronPorts. I'd be interested to see what your checking.
Thanks,
Ryan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide