graylog-deploy/rules/rule54_zte_alarm_cleared.json
byrsapty 98359c7ca3 Add pipeline rules for BDCOM EPON/GPON, ZTE, and D-Link from provided log-signature report
Closes the parsing gap the README explicitly called out (no D-Link
parsing, no ZTE ONU alarms) plus adds BDCOM GPON and expands Juniper
coverage (DDoS, PSU/memory/ASIC hardware faults, LACP/BGP/SNMP, config
commit). 58 new rules across 5 vendors, wired into Network Equipment
Parsing's stage 0 ahead of the generic_critical_severity fallback.

Where the same real-world event is reported by multiple vendors
(dying_gasp, onu_offline, optical_low_power, cli_login/cli_logout,
config_saved, interface_link_state, lag_state_change), rules share one
event_type value so dashboards can aggregate across vendors, same
normalization approach as accelppp_interface.

Built directly from the user's CSV signature report, not from real
device log samples - each rule's description says so explicitly. `when`
conditions use plain substring/contains matching on the report's own
pattern text to keep classification robust; regex field extraction is
only added where the source format is unambiguous. Passed offline
checks (JSON validity, every pipeline-referenced rule resolves to a
file, all regex patterns compile). Live compilation against a running
Graylog instance - which caught 2 real bugs during the dashboard/stream
fixes earlier this session - could NOT be completed: the test container
went unreachable mid-session. Re-run install-graylog.sh once it's back
up to confirm these compile before relying on them.
2026-07-29 16:32:18 +03:00

5 lines
1,017 B
JSON

{
"title": "zte_alarm_cleared",
"description": "ZTE: any of the GPON/EPON alarms above (dying gasp, PON LOS, ONU signal-degraded, ONU LAN LOS) clearing/restoring - zte.csv row 7. Merged into one rule since these are all the same 'condition resolved' event, just for different alarm types. Built from the provided report, not yet verified against real device output.",
"source": "rule \"zte_alarm_cleared\"\nwhen\n contains(to_string($message.message), \"GPON\") && (contains(to_string($message.message), \"link olt dgi\") || contains(to_string($message.message), \"link olt losi\")) && contains(to_string($message.message), \"cleared\")\n || (contains(to_string($message.message), \"ONU ANI SD\") && contains(to_string($message.message), \"restore\"))\n || (contains(to_string($message.message), \"ONU Uni lan los\") && contains(to_string($message.message), \"restore\"))\nthen\n set_field(\"vendor\", \"zte\");\n set_field(\"pon_type\", \"gpon\");\n set_field(\"event_type\", \"alarm_cleared\");\nend"
}