SIEM, Vulnerability Scanning, Server Monitoring and Compliance Training for IT Professionals
Table of Contents

SSH Monitor Template

The SSH Monitor Template enables you to check the availability of an SSH server, run SSH shell scripts, parse results and trigger actions. This template is typically used by systems administrators to tar Linux Audit Log files and monitor resources such as monitor CPU, disk space and memory on Linux servers.

Important
SSH server connection parameters as set via the Host Properties | SFTP Tab.
For more information see: SFTP Properties

How to configure the SSH Moniotr Template:

  • From the Menu Bar, select File | New. The Create New Object View displays.
  • From the Create New Object View, expand Templates | Network and Application Monitors then select SSH Monitor. The New Template Properties View displays.
  • The Template Properties view contains 3 tabs.

The Options Tab

  • Use the Host drop-down to select the server you would like to monitor.
Note
Once selected, the server is automatically assigned to this template.
  • Use the Terminal name text box to specify the terminal name (e.g. xterm or VT100).
  • Use the Columns text box to specify the terminal width in columns.
  • Use the Rows text box to specify the terminal height in rows.
  • Use the Width text box to specify the terminal width in pixels.
  • Use the Height text box to specify the terminal height in pixels.
  • Use the Buffer size text box to specify the buffer size.
  • Use the Timeout text box to specify the time to wait for the command-prompt.
  • Use the Commands controls to specify each command to execute.
    • Use the Command text box to specify the command to execute (e.g. tar -cvf AuditLogs.tar /etc/security/audit_event).
    • Use the Response text box to specify the answer to a command's question (e.g. your password).
Note
Response values are encrypted using FIPS compliant AES encryption.
    • Use the Timeout text box to specify the time to wait for the command-prompt after each command and response.
    • Use the Up Up Button and Down Drop-Down Button buttons to change the order of commands.
    • Use the Execute Refresh Button button to run the commands and view the results.
  • Use the Is tabular check box to parse tabular results.

    Tabular Results

    Use the Column definitions control to automatically define the results schema.

    • Click the Load Columns button to run the script then automatically generate the column definitions.
    • Use the Key text box to specify a unique key to be used by filters.
    • Use the Name text box to specify the column header's display string.
    • Use the Data Type drop-down to select the data type to assign to the column.

    Other Results

    Use the Column definitions control to manually define the results schema.

    • Click the Add Add Button button. A new empty column definition is created at the bottom of the list.
    • Use the Key text box to specify a unique key to be used by filters.
    • Use the Name text box to specify the column header's display string.
    • Use the Data Type drop-down to select the data type to assign to the column.
    • From the RegEx column, click the Down Display regular expressionsbutton to display the Regular expressions control.
    • From the Regular expressions control, click the Add Add regular expression. A new Regular expression is added to the bottom of the list.
    • Use the Value text box to specify the regular expression that defines a key value pair.
Important
To successfully validate, a regular expression variable must be defined that matches the key. For example, if the key is TARGET_ACCOUNT_NAME, there must be a corresponding variable ?<TARGET_ACCOUNT_NAME>The regular expression is validated against the current column key after you tab out of the text box or move focus to another control.
    • Use the Up Move up button and Down Move down button buttons to change the regular expression order of execution.
Sample Regular Expression Definition Properties View
Sample Regular Expression Definition Properties View
  • Sort By:

    • Use the Select from list drop-down to select an alternate column to sort by when the values in the prior column are identical. You can sort by as many columns as necessary to get the desired results.
    • Use the Sort Order column drop-downs to assign the sort directions.
    • Use the Up Move up button and Down Move down button buttons found on the right side of the table control to change the order of sorting.
    • To delete an item, either select a single line item or use the shift and/or ctrl keys to multi-select, then either press the Delete key or press the Delete Delete button button.
    • To clear all listed items, press the Clear Clear button button.
Sample Sort by Properties View
Sample Sort by Properties View
  • Group By:

    • Use the Select from list drop-down to select each column to group by.
Note
When reports are emailed or saved to a file, a table is generated for each unique set of Group By columns.
    • Use the Sort Order column drop-downs to assign the sort directions.
    • Use the Sort By Count column checkbox to sort the groups by the count of rows rather than the names.
    • Use the Up Move up button and Down Move down button buttons found on the right side of the table control to change the order of grouping.
    • To delete an item, either select a single line item or use the shift and/or ctrl keys multi-select, then either press the Delete key or press the Delete Delete button button.
    • To clear all listed items, press the Clear Clear button button.
Group By Control
Group by properties
    • Use the Warning and Critical Trigger controls to apply trigger criteria.
    • Click the Test button to verify the template is configured property and the monitor executes as expected.
    • Finally, select the General Tab, then click the click the Auto-Generate Name Auto-Generate Name Button button to auto-generate a name based on the configured settings.

Related Topics

Network and Application Monitor Templates