Closes the parsing gap the README explicitly called out (no D-Link parsing, no ZTE ONU alarms) plus adds BDCOM GPON and expands Juniper coverage (DDoS, PSU/memory/ASIC hardware faults, LACP/BGP/SNMP, config commit). 58 new rules across 5 vendors, wired into Network Equipment Parsing's stage 0 ahead of the generic_critical_severity fallback. Where the same real-world event is reported by multiple vendors (dying_gasp, onu_offline, optical_low_power, cli_login/cli_logout, config_saved, interface_link_state, lag_state_change), rules share one event_type value so dashboards can aggregate across vendors, same normalization approach as accelppp_interface. Built directly from the user's CSV signature report, not from real device log samples - each rule's description says so explicitly. `when` conditions use plain substring/contains matching on the report's own pattern text to keep classification robust; regex field extraction is only added where the source format is unambiguous. Passed offline checks (JSON validity, every pipeline-referenced rule resolves to a file, all regex patterns compile). Live compilation against a running Graylog instance - which caught 2 real bugs during the dashboard/stream fixes earlier this session - could NOT be completed: the test container went unreachable mid-session. Re-run install-graylog.sh once it's back up to confirm these compile before relying on them.
5 lines
1,017 B
JSON
5 lines
1,017 B
JSON
{
|
|
"title": "zte_alarm_cleared",
|
|
"description": "ZTE: any of the GPON/EPON alarms above (dying gasp, PON LOS, ONU signal-degraded, ONU LAN LOS) clearing/restoring - zte.csv row 7. Merged into one rule since these are all the same 'condition resolved' event, just for different alarm types. Built from the provided report, not yet verified against real device output.",
|
|
"source": "rule \"zte_alarm_cleared\"\nwhen\n contains(to_string($message.message), \"GPON\") && (contains(to_string($message.message), \"link olt dgi\") || contains(to_string($message.message), \"link olt losi\")) && contains(to_string($message.message), \"cleared\")\n || (contains(to_string($message.message), \"ONU ANI SD\") && contains(to_string($message.message), \"restore\"))\n || (contains(to_string($message.message), \"ONU Uni lan los\") && contains(to_string($message.message), \"restore\"))\nthen\n set_field(\"vendor\", \"zte\");\n set_field(\"pon_type\", \"gpon\");\n set_field(\"event_type\", \"alarm_cleared\");\nend"
|
|
}
|