Analyzed a real 1GB accel-ppp log (2026-07-23): only 2,819 of its lines were error:/warn:, and one pattern - "can't determine router address" - repeated 2,746 times over ~4 hours for two specific subscriber interfaces before self-resolving, completely unalerted since no alert covered it. - New pipeline rules for 3 previously-unclassified real message types (radius:dm_coa session not found, mac change detected, dhcpv4 short packet) plus a text-based fallback pair (accelppp_unclassified_error/ warn) for anything not yet specifically classified - needed because Vector-shipped accel-ppp lines have no real syslog PRI header, so the numeric-severity generic_critical_severity rule never fires for this source. - New alert7: group by gl2_remote_ip + event_type, fires on >5 occurrences in 5 minutes - low enough to have caught the real incident within its first cycle, high enough to tolerate a single transient warning. - vector-accel-ppp-setup.md gained a "keep only error/warn" filter option (Step 2b), explicitly documented as a deliberate tradeoff: it also drops RADIUS accounting, so the Servers & Sessions dashboard and session correlation go empty for any server that applies it. Both the with-filter and without-filter full configs are included so the choice is per-server, not global. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
5 lines
579 B
JSON
5 lines
579 B
JSON
{
|
|
"title": "accelppp_radius_coa_session_not_found",
|
|
"description": "accel-ppp: RADIUS CoA/Disconnect-Message arrived for a session that no longer exists - found live in a real 1GB accel-ppp log sample (2026-07-23), format: 'warn: radius:dm_coa: session not found'",
|
|
"source": "rule \"accelppp_radius_coa_session_not_found\"\nwhen\n contains(to_string($message.message), \"radius:dm_coa: session not found\")\nthen\n set_field(\"vendor\", \"accel-ppp\");\n set_field(\"event_type\", \"radius_coa_session_not_found\");\n set_field(\"severity_tag\", \"warning\");\nend"
|
|
}
|