Alerting Best Practice documents

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
ssouthern
Posts: 24
Joined: Thu Oct 25, 2012 7:34 am

Alerting Best Practice documents

Post by ssouthern »

Are there any documents on best practices for alerting? By that I mean a single document that lists what would normally indicate things like accounts locked out, multiple bad password attempts, service failures, changes to Windows security policies, etc. and a threshold for sending the alerts. We, like I'd expect most organizations, have a mix of Windows & Linux systems.
tmcdonald
Posts: 9117
Joined: Mon Sep 23, 2013 8:40 am

Re: Alerting Best Practice documents

Post by tmcdonald »

Nothing that we would have published, mostly because what is best practice for one organization could be completely useless information for another. We can give you the tools to monitor the logs, but we can't tell you what's important in your organization. That's something that only you and your team can decide.
Former Nagios employee
Locked