How to monitor particular kit with Oversight: which sensor to use, where on the device to set up access, which user function and extraction rows read the response, and how to write the rules that turn it into an alarm. Search for a vendor, a product or an error message, or ask a question in your own words.
SMB file: a backup on a Windows share or NAS
An SMB file sensor signs in to a Windows file server or a NAS, connects to a share and asks whether one file exists, and if so how big it is and how old. It is for checking that something landed: last night's backup, a router's config export, a nightly report. Nothing is read from the file.
Signing in, reaching the share and finding the file are separate steps, timed and reported separately. A refused login, a share that has been renamed and a backup that did not run are different problems for different people, and the sensor says which one it is.
Before you start
- An account that can read the share, and nothing more. The probe only ever looks, but the account is the real safeguard. On a NAS, a local user with read-only permission on the one shared folder is ideal.
- An SMB credential holding that account's username and password, and its domain where it is a domain account. Set it in Credentials on the sensor, or on the device, group or site above it to cover several sensors at once. Without one the sensor is not sent to any probe and reads STALE.
- SMB 2 or 3, signing in with NTLMv2. That is what Windows Server and current NAS products accept by default. SMB 1 is not supported. Where a server accepts only Kerberos, mount the share on the probe host and use a file sensor.
- TCP port 445 open from the probe to the server.
Setting it up
| Setting | What to put |
|---|---|
| Target | Leave the target override empty and the sensor asks the device's own address, which is right when the sensor sits on the file server or NAS. |
| Share | The share's name alone, as the server lists it, such as Backups. Not a path, and no slashes. |
| File path | Within the share, with either kind of slash, such as routers/edge1.cfg. A dated file can be named with tokens, filled in on UK time: routers/edge1-{{yesterday}}.cfg. See Dated files below before using {{isodate}}. Left empty, the sensor checks only that the account can sign in and reach the share. |
| Port | Leave empty for 445. |
| Interval | A file that changes once a day does not need checking every minute. 15 minutes to an hour suits a nightly backup. An SMB file sensor is 2 credits a reading. |
| Failures before a probe calls it down | 1 is reasonable on a long interval, since a missing backup is not going to reappear on the next poll. Keep 3 on a short one. |
What it reads
| Slot | Reading |
|---|---|
| SV01 File size | Bytes. |
| SV02 File age | Seconds since the file was last modified, measured against the probe's clock, so a server whose clock is wrong shows a wrong age. |
| SV03 Login time | Milliseconds to negotiate and sign in. A domain controller getting slow shows here. |
| SV04 Lookup time | Milliseconds to reach the share and look the file up. |
| SD01 Modified | The modification time, in UTC. |
| SD02 Kind | file or directory. |
The sensor is OK while the file is found, whatever its age, until rules say otherwise. A file that is there but three weeks old is still found, so for a backup the rules below are what make the sensor worth having.
A nightly backup
- In Rules, add SV02 greater than 93600 gives CRIT. 93600 seconds is 26 hours: a day plus a margin for a backup that runs a little late.
- Add SV01 less than a sensible minimum, such as 1000, gives CRIT. A backup job that ran but wrote an empty or truncated file still updates the age, and only the size catches it.
A file that is missing altogether fills no slot, so these rules do not judge it: it is a failed reading, and the failure threshold turns it into CRIT.
Dated files
Where a device writes a new file each day with the date in its name, the path can follow it with {{isodate}} (today) or {{yesterday}}. Be careful with today. From midnight until the backup runs, today's file does not exist yet, so a sensor looking for it fails every night, and an alarm at ten past midnight soon gets ignored. Look for yesterday's file instead, and a missing one means a backup really did not run.
Where the names cannot be predicted, because they carry a time or a serial number, point the sensor at the folder instead. A folder's modification time changes whenever a file is added to it or removed from it, so the folder's File age is the time since anything last landed there, and the same 26 hour rule works on it. Something deleted from the folder counts too, so this suits a folder that only ever receives.
When it fails
| Error | What it means |
|---|---|
| AUTH | The sign-in was refused: a wrong password, or an account that is disabled, locked out or expired. Or the account signed in but may not use the share, or may not read the file. The message says which. |
| No error class | There is no share of that name, or the file is not there. The message says which. |
| REFUSED | Nothing is listening on port 445, or a firewall rejected the connection. |
| CONNECTTIMEOUT | No connection within the connect timeout: the server is off or unreachable, or a firewall is dropping the traffic. |
| RESPONSETIMEOUT | Connected, but a step did not finish in time. |
| DNS | The hostname could not be looked up on the probe. |