Thursday, August 21, 2014

How to Setup Nagios & NREP in RHEL/CentOS - 6 Steps

Nagios is a powerful Open Source Monitoring tool that provides you with instant awareness of your organization's mission-critical IT infrastructure. Nagios allows you to detect and repair problems and mitigate future issues before they affect end-users and customers.

 We can monitor remote host and their services (HTTP, MYSQL, Disk Space etc) remotely. Its show’s warnings and alerts if something went wrong in remote servers, which will help us to detect the problem in server and find a solution for the issue which helps us to reduce the downtime of server.



Nagios will be installed in a server where we will monitor all our client machines and in client side we will install Nagios NRPE (Nagios Remote Plugin Executor) which will communicate with the Nagios server and send client machine status.

Step 1: Install Required Packages and Dependencies in Nagios Server

We need to install Apache, Php and supporting libraries file such as gcc, glibc, glibc-common, and GD libraries.


[root@linuxstorages ~]#yum install gd gd-devel gcc glibc glibc-common -y

To install nagios through yum we need to add EPEL repository in yum.

[root@linuxstorages ~]# wget http://dl.fedoraproject.org/pub/epel/6/i386/epel-release-6-8.noarch.rpm

[root@linuxstorages ~]#rpm -ivh epel-release-6-8.noarch.rpm

Now install nagios via yum 

[root@linuxstorages ~]#yum install nagios* -y

Step 2 : Configure Nagios Server

Add the admin mail address in the nagios contact file to receive alerts from nagios server.

[root@linuxstorages ~] vi /etc/nagios/objects/contacts.cfg
#
# CONTACTS
#
###############################################################################
###############################################################################
# Just one contact defined by default - the Nagios admin (that's you)
# This contact definition inherits a lot of default values from the 'generic-contact'
# template which is defined elsewhere.

#define contact{
#        contact_name                    nagiosadmin             ; Short name of user
#        use                                    generic-contact         ; Inherit default values #from generic-contact template (defined above)
#        alias                                  Nagios Admin            ; Full name of user
#        email                                 nagios@localhost        ; <<***** CHANGE THIS TO #YOUR EMAIL ADDRESS ******
#        }
define contact{
        contact_name                    pravin_contact             ; Short name of user
        use                                    generic-contact         ; Inherit default values from generic-contact template (defined above)
        alias                                  Nagios Admin            ; Full name of user
        email                                 pravin@linuxstorages.com   ; <<***** CHANGE THIS TO YOUR EMAIL ADDRESS ******
        }
:wq(save file)

To allow Nagios server admin link from particular ip address (192.168.1.54).


  [root@linuxstorages ~]# vi /etc/httpd/conf.d/nagios.conf

## Comment Lines 15 & 16 ##

#   Order allow,deny

#   Allow from all

 ## Uncomment and Change lines 17,18 & 19 as shown below ##

Order deny,allow

Deny from all

Allow from 127.0.0.1 192.168.1.54

:wq (save)

Now we can access Nagios admin link only from localhost and 192.168.1.54. 

Step 3 : Create User and password for Nagios Admin.


  [root@linuxstorages ~]#  htpasswd /etc/nagios/passwd nagiosadmin

New password:

Re-type new password:

Updating password for user nagiosadmin

Step 4 : Start Apache and Nagios service and make chkconfig(Service Start automatically on every boot). 

  [root@linuxstorages ~]# /etc/init.d/nagios start
 Starting nagios: done.

  [root@linuxstorages ~]#/etc/init.d/httpd start

 Starting httpd:                                            [  OK  ]

   [root@linuxstorages ~]#chkconfig nagios on
        

  [root@linuxstorages ~]#chkconfig httpd on 

Now access the Nagios admin link and enter user & password which created before.

Link : http://localhost/nagios 




Step 5 : Installing NRPE on Nagios Remote Host server’s 

NRPE  Nagios Remote Plugin Executor which allows you to remotely execute Nagios plugins on other Linux/Unix machines. This allows you to monitor remote machine metrics (disk usage, CPU load, etc.). NRPE can also communicate with some of the Windows agent addons, so you can execute scripts and check metrics on remote Windows machines as well.

[root@linuxstorages ~]# yum install nagios-plugins-all nrpe openssl

Configure nrpe configuration in remote host by adding Nagios server ipaddress.

 
[root@linuxstorages ~]# vi /etc/nagios/nrpe.cfg

[...]

## Line 81 - Add the Nagios server IP  and check_nrpe commands ##

allowed_hosts=127.0.0.1,192.168.1.54

##Line 210 ##

command[check_users]=/usr/lib64/nagios/plugins/check_users -w 5 -c 10

command[check_load]=/usr/lib64/nagios/plugins/check_load -w 15,10,5 -c 30,25,20

command[check_hda1]=/usr/lib64/nagios/plugins/check_disk -w 20% -c 10% -p /dev/hda1

command[check_zombie_procs]=/usr/lib64/nagios/plugins/check_procs -w 5 -c 10 -s Z

command[check_total_procs]=/usr/lib64/nagios/plugins/check_procs -w 150 -c 200

command[check_swap]=/usr/lib64/nagios/plugins/check_swap -w 20 -c 10

[...]

:wq (save)


Restart the nrpe service in remote host.

[root@linuxstorages ~]# service nrpe restart

[root@linuxstorages ~]# chkconfig nrpe on

Step 6 : Now switch back to Nagios server and edit below configuration file.


By default NRPE command wont be available in commands.cfg, to execute the in check_nrpe command in configuration file we need to add it in commands.cfg

[root@linuxstorages ~]# vi /etc/nagios/objects/commands.cfg

# add at the bottom

define command{

command_name   check_nrpe

command_line    $USER1$/check_nrpe -H $HOSTADDRESS$ -c $ARG1$

}

:wq (save)


Now Change configuration in nagios.cfg

    [root@linuxstorages ~]# vi /etc/nagios/nagios.cfg

    and uncomment the following lines.

    ## Line 52 - Uncomment ##

    cfg_dir=/etc/nagios/servers

    :wq (save)


Create a directory called “servers” under “/etc/nagios/”.

[root@linuxstorages ~]# mkdir –p /etc/nagios/servers

Now create a configuration files for remote host server's in /etc/nagios/servers path.

[root@linuxstorages ~]#cd /etc/nagios/servers

    [root@linuxstorages ~]#vi client-server-1.cfg

     Check nrpe configuration file in remote client machine so that we can use same command

     in this file too.

               define host {
          
            use                                 linux-server
          
            host_name                        client-server1
          
            alias                            client-server1
          
            address                         192.168.1.101
    
     max_check_attempts              5
    
     check_period                    24x7
    
     notification_interval           30
    
     notification_period             24x7
    
     }
    

        define service {

                use                                   generic-service

                host_name                        client-server1

                service_description              PING

                check_command               check_ping!100.0,20%!500.0,60%

                }

        define service {

                use                                   generic-service

                host_name                        client-server1

                service_description             SSH

                check_command               check_ssh

                notifications_enabled            0

                }

        define service {

                use                                  generic-service

                host_name                        client-server1

                service_description           CPU Load

                check_command              check_nrpe!check_load

                }

        define service {

                use                                  generic-service

                host_name                        client-server1

                service_description          Login Users

                check_command               check_nrpe!check_users

                }

        define service {

                use                                  generic-service

                host_name                      client-server1

                service_description          Disk Usage

                check_command              check_nrpe!check_hda1

                }

        define service {

                use                                  generic-service

                host_name                       client-server1

                service_description           Total Process

                check_command              check_nrpe!check_total_procs

                }

        define service {

                use                                  generic-service

                host_name                        client-server1

                service_description           Swap Usage

                check_command             check_nrpe!check_swap

                }


same configuration should to be done for all remote host client machines.

Restart the Nagios server, after all configuration's done in both client and server side.

[root@linuxstorages ~]#/etc/init.d/nagios restart

Running configuration check...done.
Stopping nagios: done.
Starting nagios: done.

Now access the Nagios Monitoring Tool in Web Interface by using Nagios admin link and make sure services for remote host.


Nagios Host View



Nagios Service View

Tuesday, August 19, 2014

Three Special Permission in Linux - SUID, SGID & Sticky Bit.

Three special permission in linux are SUID, SGID and Sticky Bit which is use to control the linux user in advance.



What is SUID?

The common explanation given for SUID is, it is an advance file permission SUID allows an user to execute a script as if the owner of the script is executing it.

Example for SUID

root@linuxstorages:~#ls -l /usr/bin/passwd
-rwsr-xr-x 1 root root 22984 Jan  2006 /usr/bin/passwd

SUID bit is set on an executable. It runs with the permission of its owner.

Command :

root@linuxstorages:~#chmod u+s  < file name >

                                  or

root@linuxstorages:~#chmod 4755  < file name >


What is SGID?

If the set gid bit on directory entry is set, file in that directory will have the group ownership as the directory, instead of than the group of the user that created the file.

Command :

root@linuxstorages:~#chmod g+s  < file name >

                                 or

root@linuxstorages:~#chmod 2755  <file name >


What is Sticky Bit?

Before set the sticky bit permission for folder, the irrespective of the users has rights to delete the folder. If the sticky bit permission set for the folder, respective of the user has rights to delete the folder.

Example for Sticky Bit

root@linuxstorages:~#ls -ld /tmp
drwxrwxrwt 32 root root 36864 Mar 27 12:38 /tmp

Command :

root@linuxstorages:~#chmod o+t  < Dir Name >

                                   or

root@linuxstorages:~#chmod 1777 < Dir Name >

Tuesday, August 12, 2014

File Permissions in Linux - Umask,Chmod,Chown.



File permissions

Linux uses the same permissions scheme as Unix. Each file and directory on your system is assigned access rights for the owner of the file, the members of a group of related users, and everybody else. Rights can be assigned to read a file, to write a file, and to execute a file.
Permissions on Unix systems are managed in three distinct scopes or classes. These scopes are known as user(U), group(G), and others(O).


Values for Read, Write and Execute.
Read        - 4
Write       - 2
Execute   - 1

  • The read permission grants the ability to read a file. When set for a directory, this permission grants the ability to read the names of files in the directory, but not to find out any further information about them such as contents, file type, size, ownership, permissions.
  • The write permission grants the ability to modify a file. When set for a directory, this permission grants the ability to modify entries in the directory. This includes creating files, deleting files, and renaming files.
  • The execute permission grants the ability to execute a file. This permission must be set for executable programs, including shell scripts, in order to allow the operating system to run them. When set for a directory, this permission grants the ability to access file contents and meta-information if its name is known, but not list files inside the directory, unless read is set also.
           
Symbolic Way
Numeric Way
Permission
User (U)
Group(G)
Others(O)
---                 ---                   ---
000
No Permission
--x                --x                  --x
111
Execute
-w-               -w-                 -w-
222
Write
-wx               -wx                -wx
333
Write & Execute
r--                 r--                   r--
444
Read
r-x                r-x                  r-x
555
Read & Execute
rw-               rw-                 rw-
666
Read & Write
rwx              rwx                rwx
777
Read & Write & Execute






To see the permission settings for a file, we can use the ls command as follows:

root@linuxstorages:~# ls A1.html
-rw-r--r--   1 root root  353 Aug 25 18:13 A1.html

Here file A1.html has the permission 644. Users have read & write, group and others have only read permission.

CHMOD 

Chmod command is used to set permission for the files and folders.

Eg: Numeric way of assigning permission to a file.

root@linuxstorages:~# chmod 640 ab.txt  

root@linuxstorages:~# chmod 666 ac.txt

root@linuxstorages:~# chmod 755 ad.txt

Eg: Symbolic way of assigning permission to a file.

root@linuxstorages:~#chmod  ugo+x  ab.txt

Adding execution permission to all user, group and others.

root@linuxstorages:~# chmod u=w,g=wx,o=x dd.txt

user – write, group – write and execute, others – execute.

root@linuxstorages:~# chmod u-wx,g-x,o-rw ac.txt

Removing write and execute from user, execute from group , read and write from others.

What is UMASK ?

The user file creation mode mask [umask] is used to determine the file permission for Normal and Root user.

Default value for Folder  777

Default value for File      666

For Root user Umask value is 022

Type
Permission
Umask
Subtract
Folder
Permission
Folder
777
022
777-022
755
rwxr-xr-x
File
666
022
666-022
644
rw-r--r--

For Normal user Umask value is 002

Type
Permission
Umask
Subtract
Folder
Permission
Folder
777
002
777-002
775
rwxrwxr-x
File
666
002
666-002
664
rw-rw-r--

To understand the value of default UMASK value for Root and Normal user.


root@linuxstorages:~# vi /etc/bashrc


CHOWN


Changing the user ownership of a file or a directory.

root@linuxstorages:~# chown <User Name> <File Name>

root@linuxstorages:~#chown storage sample.txt

-R option is used for recursive mainly for directories and have sub-directories.

root@linuxstorages:~#chown –R storages /home/backup

Permission will reflect to all it sub-directories in backup folder.


CHGRP

To change a group for a file or a folder.


root@linuxstorages:~# chgrp storages abc.txt

root@linuxstorages:~# chgrp storages /data

will change only to data folder.

root@linuxstorages:~#chgrp –R storages /data

will change all its sub directories in data folder.


 

© 2014 Linux Storages | Updated . All rights resevered. Designed by Templateism