Skip to content

Commit d495dd7

Browse files
chetanchoudhary-sumoJV0812himanshu219
authored
SUMO-252275: Adding monitor's information to OTEL Apps Set3 (#4912)
* SUMO-252275: Adding monitor's information to OTEL Apps Set3 * Update jfrog-artifactory-opentelemetry.md * Update vmware-opentelemetry.md * Update jfrog-artifactory-opentelemetry.md * Update active-directory-json-opentelemetry.md * Update jfrog-artifactory-opentelemetry.md * release note updated * minor fix --------- Co-authored-by: Jagadisha V <129049263+JV0812@users.noreply.github.com> Co-authored-by: Himanshu Pal <hp.iiita@gmail.com>
1 parent 4469329 commit d495dd7

File tree

4 files changed

+71
-18
lines changed

4 files changed

+71
-18
lines changed

blog-service/2024-12-31-apps.md

Lines changed: 2 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -26,22 +26,8 @@ We’re excited to announce the release of new Azure Service Bus, Azure API Mana
2626

2727
### Enhancements
2828

29-
- We're excited to announce the release of the enhancements listed below for the Sumo Logic apps:
30-
- **Cassandra - OpenTelemetry**. Added 9 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/cassandra-opentelemetry/#cassandra-alerts).
31-
- **Couchbase - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/couchbase-opentelemetry/#couchbase-alerts).
32-
- **HAProxy - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/haproxy-opentelemetry/#haproxy-alerts).
33-
- **IIS - OpenTelemetry**. Added 10 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/iis-10).
34-
- **Linux - OpenTelemetry**. Added 7 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/microsoft-azure/opentelemetry/sql-server-linux-opentelemetry/#sql-server-linux-alerts).
35-
- **MariaDB - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/mariadb-opentelemetry/#mariadb-alerts).
36-
- **Memcached - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/memcached-opentelemetry/#memcached-alerts).
37-
- **MongoDB - OpenTelemetry**. Added 12 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/mongodb-opentelemetry/#mongodb-alerts).
38-
- **Oracle - OpenTelemetry**. Added 12 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/oracle-opentelemetry/#oracle-alerts).
39-
- **RabbitMQ - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/containers-orchestration/opentelemetry/rabbitmq-opentelemetry/#rabbitmq-alerts).
40-
- **Redis - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/redis-opentelemetry/#redis-alerts).
41-
- **Squid Proxy - OpenTelemetry**. Added 4 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/squid-proxy-opentelemetry/#squidproxy-alerts).
42-
- **Varnish - OpenTelemetry**. Added 3 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/varnish-opentelemetry/#varnish-alerts).
43-
44-
- **Block Blob**. Updated the Block Blob collection to support collection for Network Flow logs. The Network Security Group (NSG) flow logs will be removed on 30 September 2027. **From 30 June 2025, you will no longer be able to generate new NSG flow logs as part of this retirement**. For more details, refer to the Azure [documentation](https://learn.microsoft.com/en-us/azure/network-watcher/flow-logs-read?tabs=nsg).
29+
- **Added Monitors**. We have added new pre-configured monitors to the [Cassandra - OpenTelemetry](/docs/integrations/databases/opentelemetry/cassandra-opentelemetry/#cassandra-alerts), [Couchbase - OpenTelemetry](/docs/integrations/databases/opentelemetry/couchbase-opentelemetry/#couchbase-alerts), [HAProxy - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/haproxy-opentelemetry/#haproxy-alerts), [IIS - OpenTelemetry](/docs/integrations/web-servers/iis-10), [Linux - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/sql-server-linux-opentelemetry/#sql-server-linux-alerts), [MariaDB - OpenTelemetry](/docs/integrations/databases/opentelemetry/mariadb-opentelemetry/#mariadb-alerts), [Memcached - OpenTelemetry](/docs/integrations/databases/opentelemetry/memcached-opentelemetry/#memcached-alerts), [MongoDB - OpenTelemetry](/docs/integrations/databases/opentelemetry/mongodb-opentelemetry/#mongodb-alerts), [Oracle - OpenTelemetry](/docs/integrations/databases/opentelemetry/oracle-opentelemetry/#oracle-alerts), [RabbitMQ - OpenTelemetry](/docs/integrations/containers-orchestration/opentelemetry/rabbitmq-opentelemetry/#rabbitmq-alerts), [Redis - OpenTelemetry](/docs/integrations/databases/opentelemetry/redis-opentelemetry/#redis-alerts), [Squid Proxy - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/squid-proxy-opentelemetry/#squidproxy-alerts), [Varnish - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/varnish-opentelemetry/#varnish-alerts), [JFrog Artifactory - OpenTelemetry](/docs/integrations/app-development/opentelemetry/jfrog-artifactory-opentelemetry), [VMWare - OpenTelemetry](/docs/integrations/containers-orchestration/opentelemetry/vmware-opentelemetry), and [Active Directory JSON - OpenTelemetry](/docs/integrations/microsoft-azure/opentelemetry/active-directory-json-opentelemetry) apps.
30+
- **Azure Blob Storage (block blobs) Collection**. Updated the Block Blob collection to support collection for Network Flow logs. The Network Security Group (NSG) flow logs will be removed on 30 September 2027. **From 30 June 2025, you will no longer be able to generate new NSG flow logs as part of this retirement**. For more details, refer to the Azure [documentation](https://learn.microsoft.com/en-us/azure/network-watcher/flow-logs-read?tabs=nsg).
4531
- The apps listed below have been updated, and as part of the app installation flow, you can now create Cloud-to-Cloud sources:
4632
- [1Password](/docs/integrations/saas-cloud/1password/#collection-configuration-and-app-installation)
4733
- [Abnormal Security](/docs/integrations/saas-cloud/abnormal-security/#collection-configuration-and-app-installation)

docs/integrations/app-development/opentelemetry/jfrog-artifactory-opentelemetry.md

Lines changed: 23 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,11 +15,15 @@ The Sumo Logic app for Artifactory provides insight into your [JFrog Artifactory
1515

1616
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/Artifactory-OpenTelemetry/Artifactory-Schematics.png' alt="Artifactory-Schematics" />
1717

18+
:::info
19+
This app includes [built-in monitors](#jfrog-artifactory-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-jfrog-artifactory-app).
20+
:::
21+
1822
## Fields creation in Sumo Logic for Artifactory
1923

2024
Following are the Tags which will be created as part of Artifactory app install if not already present.
2125

22-
* `sumo.datasource`. Has fixed value of **artifactory**
26+
* `sumo.datasource`. Has fixed value of **artifactory**.
2327

2428
## Prerequisites
2529

@@ -244,3 +248,21 @@ import JfrogReq from '../../../reuse/apps/jfrog/artifactory-request-access.md';
244248
import JfrogTr from '../../../reuse/apps/jfrog/artifactory-traffic.md';
245249

246250
<JfrogTr/>
251+
252+
## Create monitors for JFrog Artifactory app
253+
254+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
255+
256+
<CreateMonitors/>
257+
258+
### JFrog Artifactory alerts
259+
260+
| Name | Description | Alert Condition | Recover Condition |
261+
|:--|:--|:--|:--|
262+
| `Artifactory - Excessive Denied Login Attempts` | This alert is triggered when there are multiple denied login attempts from the same IP or user. | Count `>` 5 | Count `<=` 5 |
263+
| `Artifactory - High 4xx Status Codes` | This alert is triggered when there's a high number of HTTP 4xx error responses. | Count `>` 10 | Count `<=` 10 |
264+
| `Artifactory - High 5xx Status Codes` | This alert is triggered when there's a high number of HTTP 5xx error responses. | Count `>` 10 | Count `<=` 10 |
265+
| `Artifactory - High Denied Deploys to Cached Repos` | This alert is triggered when there's a high number of denied deploy attempts to cached repositories. | Count `>` 5 | Count `<=` 5 |
266+
| `Artifactory - High Denied Deploys to Non-Cached Repos` | This alert is triggered when there's a spike in denied deploy attempts to non-cached repositories. | Count `>` 5 | Count `<=` 5 |
267+
| `Artifactory - High Denied Downloads` | This alert is triggered when there's a high number of denied download attempts. | Count `>` 5 | Count `<=` 5 |
268+
| `Artifactory - Slow HTTP Response Times` | This alert is triggered when Artifactory response times are high. | Count `>` 5 | Count `<=` 5 |

docs/integrations/containers-orchestration/opentelemetry/vmware-opentelemetry.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,12 @@ See the [vSphere product page](https://www.vmware.com/products/vsphere.html) for
2121

2222
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/VMWare-OpenTelemetry/VMWare-Schematics.png' alt="Schematics" />
2323

24+
:::info
25+
This app includes [built-in monitors](#vmware-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-vmware-app).
26+
:::
27+
2428
## Prerequisites
29+
2530
VMWare metrics are collected through the [vCenter Receiver](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/vcenterreceiver) of OpenTelemetry.
2631

2732
This receiver has been built to support ESXi and vCenter versions:
@@ -276,3 +281,22 @@ The **VMWare - VM Details** dashboard provides a detailed analysis of VM metrics
276281
- **Top 25 VMs Network Packet Rate**. Top 25 VMs Network transmitted/received packet rate.
277282
- **Top 25 VMs Network Packet Drop Rate**. Top 25 VMs Network transmitted/received packet drop rate.
278283
- **Top 25 VMs Memory Swapped**. Top 25 VMs Memory swapped.
284+
285+
## Create monitors for VMWare app
286+
287+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
288+
289+
<CreateMonitors/>
290+
291+
### VMWare alerts
292+
293+
| Name | Description | Alert Condition | Recover Condition |
294+
|:--|:--|:--|:--|
295+
| `VMware - Datastore High Utilization` | This alert is triggered when datastore usage is approaching capacity. | Count `>=` 90 | Count `<` 90 |
296+
| `VMware - High Virtual Disk Read Latency` | This alert gets triggered on high virtual datastore read latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
297+
| `VMware - High Virtual Disk Write Latency` | This alert gets triggered on high virtual datastore write latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
298+
| `VMware - Host CPU High Utilization` | This alert is triggered when host CPU utilization is consistently high, which may impact VM performance. | Count `>=` 90 | Count `<` 90 |
299+
| `VMware - Host Memory Utilization` | This alert is triggered when host memory utilization is consistently high. | Count `>=` 95 | Count `<` 95 |
300+
| `VMware - VM CPU Ready Time High` | This alert gets triggered when VMs are waiting too long for CPU resources, indicating CPU contention. | Count `>=` 10 | Count `<` 10 |
301+
| `VMware - VM Memory Balloon Pressure` | This alert gets triggered when VMs are experiencing significant memory ballooning. | Count `>=` 1024 | Count `<` 1024 |
302+

docs/integrations/microsoft-azure/opentelemetry/active-directory-json-opentelemetry.md

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,15 @@ We recommend using the Active Directory JSON app in combination with the Windows
1717

1818
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/Active-Directory-OpenTelemetry/Active-Directory-Schematics.png' alt="Schematics" />
1919

20+
:::info
21+
This app includes [built-in monitors](#active-directory-alerts). For details on creating custom monitors, refer to the [Create monitors for Active Directory app](#create-monitors-for-active-directory-app).
22+
:::
23+
2024
## Fields creation in Sumo Logic for Active Directory
2125

2226
Following are the [fields](/docs/manage/fields/) which will be created as part of Active Directory App install if not already present.
2327

24-
**`sumo.datasource`** - Has fixed value of **activeDirectory**
28+
**`sumo.datasource`** - Has fixed value of **activeDirectory**.
2529

2630
### Event logs used by Active Directory app
2731

@@ -180,3 +184,20 @@ The **Active Directory Service Activity** dashboard provides insights into overa
180184
The **Active Directory Service Failures** dashboard provides an at-a-glance view of success, failures, and audit failures overtime.
181185

182186
<img src='https://sumologic-app-data-v2.s3.amazonaws.com/dashboards/Active-Directory-OpenTelemetry/Active-Directory-Service-Failures.png' alt="Service Failures" />
187+
188+
## Create monitors for Active Directory app
189+
190+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
191+
192+
<CreateMonitors/>
193+
194+
### Active Directory alerts
195+
196+
| Name | Description | Alert Condition | Recover Condition |
197+
|:--|:--|:--|:--|
198+
| `Active Directory - Account Lockouts Spike` | This alert is triggered when there are multiple account lockouts in a short time period, indicating potential brute force attempts. | Count `>=` 5 | Count `<` 5 |
199+
| `Active Directory - Directory Service Failures` | This alert is triggered when there are critical Directory Service failures that could impact AD functionality. | Count `>=` 3 | Count `<` 3 |
200+
| `Active Directory - Mass User Account Deletions` | This alert triggers when multiple user accounts are deleted in a short time period, which could indicate malicious activity. | Count `>` 5 | Count `<=` 5 |
201+
| `Active Directory - NTLM Authentication Failures` | This alert is triggered when there are multiple NTLM authentication failures, which could indicate credential theft attempts. | Count `>=` 5 | Count `<` 5 |
202+
| `Active Directory - Replication Failures` | This alert triggers when AD replication failures occur, which can impact directory synchronization. | Count `>` 0 | Count `<=` 0 |
203+
| `Active Directory - Schema Modifications` | This alert is triggered when changes are made to the AD schema, which are rare and potentially high-impact changes. | Count `>` 0 | Count `<=` 0 |

0 commit comments

Comments
 (0)