Ad Widget

Collapse

Zabbix alert issues - More false positives

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • cambaselkar
    Junior Member
    • Dec 2013
    • 3

    #1

    Zabbix alert issues - More false positives

    Greetings all,

    We are using Zabbix 2.2 for monitoring our production environment and SMS alerting mechanism for very critical alerts and server down time. I am facing more than issues with our installation. Will try to sum up in brief more important issues

    1. I have created icmpping items and triggers for those items. Action is configured to send SMS to particular user if server NOT IN maintenance, trigger value is PROBLEM and severity is DISASTER. In addition, we have configured the trigger to be DISASTER only if there is no ICMP response for 5 pings.
    Even though, Zabbix receives ICMP response from the host, it still considers this as DISASTER and sends an alert. While mentioning that the status of the host is Up. I do not understand where to look.
  • syndeysider
    Senior Member
    • Oct 2013
    • 115

    #2
    Might help if you post your trigger definition....

    Comment

    • cambaselkar
      Junior Member
      • Dec 2013
      • 3

      #3
      Though there is no particular trigger that is causing this trouble, this is one of those

      {www.<my-domain>.com:icmpping[,5].last(,60)}=0

      This is just a simple icmpping, and nothing much more.

      PS: I understand that I should be using web monitoring capabilities, but I think this is also something I want to keep watch through.

      Comment

      • MaxM
        Member
        • Sep 2011
        • 42

        #4
        Your description of what you want and what you're doing doesn't exactly line up. The item key 'www.<my-domain>.com:icmpping[,5]' will give you a failure if one packet in 5 fails in a ping. The last function written that way should evaluate the last value time shifted as of a minute ago. If you want five consecutive test failures, you should use count (or min/max if the expression can be built correctly). Right now, you're getting an alert for *every* dropped packet, delayed by one minute.

        Comment

        • cambaselkar
          Junior Member
          • Dec 2013
          • 3

          #5
          I am okay if system sends alerts for all the dropped packets. But does it consider the host to be in PROBLEM state if it is Up(1)?
          I have created a template for icmpping which is linked to every host but we get alert for only certain hosts.

          Comment

          Working...