2 # make sure we can collect web log data
4 template: last_collected_secs
5 on: web_log.response_codes
7 calc: $now - $last_collected_t
10 warn: $this > (($status >= $WARNING) ? ($update_every) : ( 5 * $update_every))
11 crit: $this > (($status == $CRITICAL) ? ($update_every) : (60 * $update_every))
12 delay: down 5m multiplier 1.5 max 1h
13 info: number of seconds since the last successful data collection
16 # -----------------------------------------------------------------------------
17 # high level response code alarms
20 on: web_log.response_codes
22 lookup: sum -1m unaligned
23 calc: ($this == 0)?(1):($this)
26 info: the sum of all HTTP requests over the last minute
29 on: web_log.response_codes
31 lookup: sum -1m unaligned of 2xx
32 calc: ($this == 0)?(1):($this)
35 info: the sum of successful HTTP requests over the last minute
37 template: 1m_successful
38 on: web_log.response_codes
40 calc: $1m_2xx * 100 / $1m_requests
43 warn: ($1m_requests > 30) ? ($this < (($status >= $WARNING ) ? ( 98 ) : ( 95 )) ) : ( 0 )
44 crit: ($1m_requests > 30) ? ($this < (($status == $CRITICAL) ? ( 95 ) : ( 90 )) ) : ( 0 )
45 delay: down 15m multiplier 1.5 max 1h
46 info: the ratio of HTTP redirects (3xx) vs the successful requests, \
50 template: 1m_redirects
51 on: web_log.detailed_response_codes
53 lookup: sum -1m unaligned of 301,303,307,308
54 calc: $this * 100 / ( $1m_2xx + $this )
57 warn: ($1m_requests > 30) ? ($this > (($status >= $WARNING ) ? ( 1 ) : ( 2 )) ) : ( 0 )
58 crit: ($1m_requests > 30) ? ($this > (($status == $CRITICAL) ? ( 2 ) : ( 5 )) ) : ( 0 )
59 delay: down 15m multiplier 1.5 max 1h
60 info: the ratio of HTTP redirects (301, 303, 307, 308) vs the successful requests, \
64 template: 1m_bad_requests
65 on: web_log.response_codes
67 lookup: sum -1m unaligned of 4xx
68 calc: $this * 100 / ( $1m_2xx + $this )
71 warn: ($1m_requests > 30) ? ($this > (($status >= $WARNING) ? ( 1 ) : ( 5 )) ) : ( 0 )
72 crit: ($1m_requests > 30) ? ($this > (($status == $CRITICAL) ? ( 5 ) : ( 10 )) ) : ( 0 )
73 delay: down 15m multiplier 1.5 max 1h
74 info: the ratio of HTTP bad requests (4xx) vs the successful requests, \
78 template: 1m_internal_errors
79 on: web_log.response_codes
81 lookup: sum -1m unaligned of 5xx
82 calc: $this * 100 / ( $1m_2xx + $this )
85 warn: ($1m_requests > 30) ? ($this > (($status >= $WARNING) ? ( 1 ) : ( 2 )) ) : ( 0 )
86 crit: ($1m_requests > 30) ? ($this > (($status == $CRITICAL) ? ( 2 ) : ( 5 )) ) : ( 0 )
87 delay: down 15m multiplier 1.5 max 1h
88 info: the ratio of HTTP internal server errors (5xx) vs the successful \
89 requests, over the last minute
92 # -----------------------------------------------------------------------------
95 template: 10m_response_time
96 on: web_log.response_time
98 lookup: average -10m unaligned of avg
101 info: the average time to respond to HTTP requests, over the last 10 minutes
104 on: web_log.response_time
106 lookup: average -1m unaligned of avg
111 warn: ($1m_requests > 30) ? ($this > $green && $this > ($10m_response_time * 2) ) : ( 0 )
112 crit: ($1m_requests > 30) ? ($this > $red && $this > ($10m_response_time * 4) ) : ( 0 )
113 delay: down 15m multiplier 1.5 max 1h
114 info: the average time to respond to HTTP requests, over the last 1 minute
117 # -----------------------------------------------------------------------------
118 # web too many or too few requests
120 template: 5m_2xx_last
121 on: web_log.response_codes
123 lookup: average -5m at -5m unaligned of 2xx
126 info: average successful HTTP requests over the last 5 minutes
129 on: web_log.response_codes
131 lookup: average -5m unaligned of 2xx
134 info: average successful HTTP requests over the last 5 minutes
136 template: 5m_requests_ratio
137 on: web_log.response_codes
139 calc: ($5m_2xx_last > 0)?($5m_2xx_now * 100 / $5m_2xx_last):(100)
142 warn: ($1m_requests > 30) ? (($5m_2xx_last > 30) ? ($this > 200 OR $this < 50) : (0) ) : ( 0 )
143 crit: ($1m_requests > 30) ? (($5m_2xx_last > 30) ? ($this > 400 OR $this < 25) : (0) ) : ( 0 )
144 delay: down 15m multiplier 1.5 max 1h
145 options: no-clear-notification
146 info: the percentage of web requests over the last 5 minutes, \
147 compared with the previous 15 minutes