You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: blog-service/2024-12-31-apps.md
+2-16Lines changed: 2 additions & 16 deletions
Original file line number
Diff line number
Diff line change
@@ -26,22 +26,8 @@ We’re excited to announce the release of new Azure Service Bus, Azure API Mana
26
26
27
27
### Enhancements
28
28
29
-
- We're excited to announce the release of the enhancements listed below for the Sumo Logic apps:
30
-
-**Cassandra - OpenTelemetry**. Added 9 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/cassandra-opentelemetry/#cassandra-alerts).
31
-
-**Couchbase - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/couchbase-opentelemetry/#couchbase-alerts).
32
-
-**HAProxy - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/haproxy-opentelemetry/#haproxy-alerts).
33
-
-**IIS - OpenTelemetry**. Added 10 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/iis-10).
34
-
-**Linux - OpenTelemetry**. Added 7 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/microsoft-azure/opentelemetry/sql-server-linux-opentelemetry/#sql-server-linux-alerts).
35
-
-**MariaDB - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/mariadb-opentelemetry/#mariadb-alerts).
36
-
-**Memcached - OpenTelemetry**. Added 5 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/memcached-opentelemetry/#memcached-alerts).
37
-
-**MongoDB - OpenTelemetry**. Added 12 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/mongodb-opentelemetry/#mongodb-alerts).
38
-
-**Oracle - OpenTelemetry**. Added 12 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/oracle-opentelemetry/#oracle-alerts).
39
-
-**RabbitMQ - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/containers-orchestration/opentelemetry/rabbitmq-opentelemetry/#rabbitmq-alerts).
40
-
-**Redis - OpenTelemetry**. Added 6 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/databases/opentelemetry/redis-opentelemetry/#redis-alerts).
41
-
-**Squid Proxy - OpenTelemetry**. Added 4 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/squid-proxy-opentelemetry/#squidproxy-alerts).
42
-
-**Varnish - OpenTelemetry**. Added 3 new monitors that will be triggered for different pre-defined conditions. [Learn more](/docs/integrations/web-servers/opentelemetry/varnish-opentelemetry/#varnish-alerts).
43
-
44
-
-**Block Blob**. Updated the Block Blob collection to support collection for Network Flow logs. The Network Security Group (NSG) flow logs will be removed on 30 September 2027. **From 30 June 2025, you will no longer be able to generate new NSG flow logs as part of this retirement**. For more details, refer to the Azure [documentation](https://learn.microsoft.com/en-us/azure/network-watcher/flow-logs-read?tabs=nsg).
-**Azure Blob Storage (block blobs) Collection**. Updated the Block Blob collection to support collection for Network Flow logs. The Network Security Group (NSG) flow logs will be removed on 30 September 2027. **From 30 June 2025, you will no longer be able to generate new NSG flow logs as part of this retirement**. For more details, refer to the Azure [documentation](https://learn.microsoft.com/en-us/azure/network-watcher/flow-logs-read?tabs=nsg).
45
31
- The apps listed below have been updated, and as part of the app installation flow, you can now create Cloud-to-Cloud sources:
This app includes [built-in monitors](#jfrog-artifactory-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-jfrog-artifactory-app).
20
+
:::
21
+
18
22
## Fields creation in Sumo Logic for Artifactory
19
23
20
24
Following are the Tags which will be created as part of Artifactory app install if not already present.
21
25
22
-
*`sumo.datasource`. Has fixed value of **artifactory**
26
+
*`sumo.datasource`. Has fixed value of **artifactory**.
23
27
24
28
## Prerequisites
25
29
@@ -244,3 +248,21 @@ import JfrogReq from '../../../reuse/apps/jfrog/artifactory-request-access.md';
244
248
import JfrogTr from '../../../reuse/apps/jfrog/artifactory-traffic.md';
245
249
246
250
<JfrogTr/>
251
+
252
+
## Create monitors for JFrog Artifactory app
253
+
254
+
import CreateMonitors from '../../../reuse/apps/create-monitors.md';
|`Artifactory - Excessive Denied Login Attempts`| This alert is triggered when there are multiple denied login attempts from the same IP or user. | Count `>` 5 | Count `<=` 5 |
263
+
|`Artifactory - High 4xx Status Codes`| This alert is triggered when there's a high number of HTTP 4xx error responses. | Count `>` 10 | Count `<=` 10 |
264
+
|`Artifactory - High 5xx Status Codes`| This alert is triggered when there's a high number of HTTP 5xx error responses. | Count `>` 10 | Count `<=` 10 |
265
+
|`Artifactory - High Denied Deploys to Cached Repos`| This alert is triggered when there's a high number of denied deploy attempts to cached repositories. | Count `>` 5 | Count `<=` 5 |
266
+
|`Artifactory - High Denied Deploys to Non-Cached Repos`| This alert is triggered when there's a spike in denied deploy attempts to non-cached repositories. | Count `>` 5 | Count `<=` 5 |
267
+
|`Artifactory - High Denied Downloads`| This alert is triggered when there's a high number of denied download attempts. | Count `>` 5 | Count `<=` 5 |
268
+
|`Artifactory - Slow HTTP Response Times`| This alert is triggered when Artifactory response times are high. | Count `>` 5 | Count `<=` 5 |
This app includes [built-in monitors](#vmware-alerts). For details on creating custom monitors, refer to the [Create monitors for JFrog Artifactory app](#create-monitors-for-vmware-app).
26
+
:::
27
+
24
28
## Prerequisites
29
+
25
30
VMWare metrics are collected through the [vCenter Receiver](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/vcenterreceiver) of OpenTelemetry.
26
31
27
32
This receiver has been built to support ESXi and vCenter versions:
@@ -276,3 +281,22 @@ The **VMWare - VM Details** dashboard provides a detailed analysis of VM metrics
|`VMware - Datastore High Utilization`| This alert is triggered when datastore usage is approaching capacity. | Count `>=` 90 | Count `<` 90 |
296
+
|`VMware - High Virtual Disk Read Latency`| This alert gets triggered on high virtual datastore read latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
297
+
|`VMware - High Virtual Disk Write Latency`| This alert gets triggered on high virtual datastore write latency indicating storage performance issues. | Count `>=` 20 | Count `<` 20 |
298
+
|`VMware - Host CPU High Utilization`| This alert is triggered when host CPU utilization is consistently high, which may impact VM performance. | Count `>=` 90 | Count `<` 90 |
299
+
|`VMware - Host Memory Utilization`| This alert is triggered when host memory utilization is consistently high. | Count `>=` 95 | Count `<` 95 |
300
+
|`VMware - VM CPU Ready Time High`| This alert gets triggered when VMs are waiting too long for CPU resources, indicating CPU contention. | Count `>=` 10 | Count `<` 10 |
301
+
|`VMware - VM Memory Balloon Pressure`| This alert gets triggered when VMs are experiencing significant memory ballooning. | Count `>=` 1024 | Count `<` 1024 |
This app includes [built-in monitors](#active-directory-alerts). For details on creating custom monitors, refer to the [Create monitors for Active Directory app](#create-monitors-for-active-directory-app).
22
+
:::
23
+
20
24
## Fields creation in Sumo Logic for Active Directory
21
25
22
26
Following are the [fields](/docs/manage/fields/) which will be created as part of Active Directory App install if not already present.
23
27
24
-
**`sumo.datasource`** - Has fixed value of **activeDirectory**
28
+
**`sumo.datasource`** - Has fixed value of **activeDirectory**.
25
29
26
30
### Event logs used by Active Directory app
27
31
@@ -180,3 +184,20 @@ The **Active Directory Service Activity** dashboard provides insights into overa
180
184
The **Active Directory Service Failures** dashboard provides an at-a-glance view of success, failures, and audit failures overtime.
|`Active Directory - Account Lockouts Spike`| This alert is triggered when there are multiple account lockouts in a short time period, indicating potential brute force attempts. | Count `>=` 5 | Count `<` 5 |
199
+
|`Active Directory - Directory Service Failures`| This alert is triggered when there are critical Directory Service failures that could impact AD functionality. | Count `>=` 3 | Count `<` 3 |
200
+
|`Active Directory - Mass User Account Deletions`| This alert triggers when multiple user accounts are deleted in a short time period, which could indicate malicious activity. | Count `>` 5 | Count `<=` 5 |
201
+
|`Active Directory - NTLM Authentication Failures`| This alert is triggered when there are multiple NTLM authentication failures, which could indicate credential theft attempts. | Count `>=` 5 | Count `<` 5 |
202
+
|`Active Directory - Replication Failures`| This alert triggers when AD replication failures occur, which can impact directory synchronization. | Count `>` 0 | Count `<=` 0 |
203
+
|`Active Directory - Schema Modifications`| This alert is triggered when changes are made to the AD schema, which are rare and potentially high-impact changes. | Count `>` 0 | Count `<=` 0 |
0 commit comments