5.1.1.1 Employ technology watches or other technology monitoring notification systems

From aptrust
Jump to: navigation, search


5.1.1.1 Employ technology watches or other technology monitoring notification systems
Status Ready for review
Compliance Rating Fully compliant
Responsible

Requirement: The repository shall employ technology watches or other technology monitoring notification systems.

Servers and services are monitored using the community supported open source software Icinga2. When a server or service fails, is non-responsive or exhausts available resources Icinga2 notifies the operations team per email and Slack notification (depending on the severity of the failure) in order ensure a quick resolution. Icinga2 tracks performance and resource data over time so spikes can be reviewed and analyzed if issues have occurred.

Application and service log files are analyzed using the open-source tool Logwatch (https://sourceforge.net/projects/logwatch/files/). The tool parses and analyzes log files for certain patterns and sends email reports on malicious or irregular activity. This reactive strategy allows to identify gaps in the systems configuration and mitigate eventual issues.

See Monitoring for more details.