The R&S CHM software monitors status information from various system components
that are connected to the network. The web-based user interface visualizes system
state parameters, and lets you monitor and troubleshoot connected and configured
Rohde & Schwarz instruments, hosts and SNMP devices.
Target audience
The manual familiarizes you with the functions and operation of R&S CHM. In addition,
it provides you with the information about configuration of monitoring services.
The contents are therefore intended for operators and administrators of R&S CHM.
●
Operators: Monitor configured hosts and services with restricted permissions.
●
Administrators: Monitor configured hosts and services with extended permissions.
●
System administrators:
Install and configure R&S CHM on the R&S CHM host.
These tasks require root user access. System administrators require elevated privileges to complete their tasks. It is assumed that system administrators already
have comprehensive knowledge of system setup and configuration.
R&SCHM system status monitoring provides the following high-level features:
●
Run on a security-enhanced Linux distribution (SELinux)
●
Run on a hardened operating system according to DISA STIGs. For information,
see https://public.cyber.mil/stigs/.
●
Run unattended for a long period of time
●
Continuously monitor the status of hosts and services, e.g. used disk space
●
Allow configuration of device-specific monitoring services
●
Reduce down-time of system components
●
Troubleshooting of problems
●
Encrypted communication between R&SCHM and monitored hosts
●
Secure password handling
1.2Documentation overview
This section provides an overview of the R&S CHM user documentation.
5Manual 1179.3521.02 ─ 04
Page 6
R&S®CHM
Welcome to R&S CHM
Documentation overview
1.2.1Manual
The manual is part of the R&S CHM user documentation. It is provided as PDF and as
help on the R&S CHM web GUI.
The manual introduces to the software and describes how to set up and start working
with the product. Also, it provides a comprehensive description of the R&S CHM functions and how you set up and configure R&S CHM.
The manual is available for download or for immediate display on the internet.
To show the help on the R&S CHM web GUI
► On the left navigation area of the R&S CHM web GUI, select "System" > "Manual".
The help opens in the R&S CHM web GUI.
1.2.2Brochure
The brochure provides an overview of the software and deals with the specific characteristics.
See www.rohde-schwarz.com/brochure-datasheet/chm
1.2.3Release notes and open source acknowledgment (OSA)
The release notes list new features, improvements and known limitations of the current
software version.
The open-source acknowledgment document provides verbatim license texts of the
used open-source software.
6Manual 1179.3521.02 ─ 04
Page 7
R&S®CHM
Introduction
2Introduction
The R&S CHM system status monitoring software provides an integrated, system-wide
solution to collect status information continuously in a local area network (LAN). The
software continuously performs checks for monitored hosts and services and evaluates
the results. If R&S CHM detects an error condition, it creates an alert. The following
figure provides an overview of a monitored system.
4
5
3
1
Figure 2-1: R&S CHM - status monitoring overview
1 = Computer with web-based user interface
2 = Network component (router, switch)
3 = Server hardware
4 = Rohde & Schwarz device
5 = Server hardware with error condition
6 = Uninterruptible power supply with error condition
7 = R&S CHM host that runs the status monitoring software
6
7
2
The R&S CHM software runs on a Linux server (7) and the web-based user interface
runs on a standard computer (1).
7Manual 1179.3521.02 ─ 04
Page 8
R&S®CHM
Introduction
R&SCHM can fetch data from all connected and configured system components (1 to
7). Therefore, the operational state of the system is always under control. The down-
time periods, due to maintenance operations or hardware failures, are reduced to a
minimum.
Lifetime of monitoring data
All monitoring data is retained for 90 days. Older data is purged from the database.
To monitor status information, system operators and administrators use the browserbased graphical user interface, in the following named as "web GUI".
132
Figure 2-2: Web GUI for status monitoring
1 = Main filter categories
2 = Additional filter categories
3 = Main area for problem monitoring
For configuration of R&S CHM from any client in the LAN, system administrators can
use an SSH client, such as PuTTY.
How to continue?
The next steps depend on your role as mentioned under "Target audience"on page 5.
●
Monitor system status information on the web GUI (operators)
Continue with Chapter 3, "Monitoring the system status", on page 9.
●
Install and configure R&SCHM (administrators, integrators)
These tasks address system administrators and software integrators:
–Chapter 4.1, "Installing R&S CHM", on page 18
–Chapter 4.3, "Configuring status monitoring", on page 26
8Manual 1179.3521.02 ─ 04
Page 9
R&S®CHM
Monitoring the system status
Starting the R&S CHM web GUI
3Monitoring the system status
Here, you can find the information for accessing the web GUI where you carry out all
status monitoring tasks. The web GUI provides numerous filters that you can use to
monitor your system efficiently.
The web GUI only shows the hosts and services that your system administrator has
configured for monitoring. For information about service configuration, see Chapter 4.4,
"Configuring services", on page 47.
●Starting the R&S CHM web GUI............................................................................... 9
●Obtaining a status overview....................................................................................10
●Focusing on specific components........................................................................... 11
●Displaying status details..........................................................................................13
●Verifying status history............................................................................................13
●Customizing the web GUI....................................................................................... 15
3.1Starting the R&S CHM web GUI
You can access R&S CHM web GUI using a standard web browser on any computer
that is connected to the LAN. We recommend using a current version of Microsoft
Edge or Google Chrome.
To start the GUI
1. Open your web browser.
2. In the address bar, type the IP address of the R&S CHM host, e.g. 10.100.120.12.
The browser displays a registration page.
3. Enter your credentials. This step depends on the configured user authentication
method.
●With configured LDAP user authentication, log in with your network creden-
tials or ask your system administrator for details.
Figure 3-1: Web GUI - LDAP sign-in page
9Manual 1179.3521.02 ─ 04
Page 10
R&S®CHM
Monitoring the system status
Obtaining a status overview
See also: Chapter 4.3.4, "Configuring R&S CHM web users", on page 37
●For configured local user authorization, use one of the preconfigured local
Change the password after initial login. Use a unique and strong password that
complies with the security policies in your company.
The browser displays the "Dashboard" view.
Continue with Chapter 3.2, "Obtaining a status overview", on page 10.
3.2Obtaining a status overview
For obtaining an overview of the current status of all configured hosts and services,
you can start from the "Dashboard" view. This view provides specific filters that you
can use to focus only on relevant status information, e.g. critical problems.
A host is a configured SNMP device or an agent, i.e. a Windows or Linux host. A service is a monitored element of a host.
10Manual 1179.3521.02 ─ 04
Page 11
R&S®CHM
Monitoring the system status
Focusing on specific components
Figure 3-3: Dashboard view
Problem severity
Four status levels indicate the severity of detected service problems:
●
OK (green): The service is up and running; R&S CHM does not detect a prob-
lem.
●
UNKNOWN (purple): R&S CHM cannot detect the status of the service, e.g. due
to LAN interruptions. Check for connection or configuration problems.
●
WARNING (orange): The service is running, but exceeds the configured thresh-
old. Check for problem details and report them to your administrator.
●
CRITICAL (red): The service exceeds the critical threshold and thus has severe
problems. Immediately check for problem details and report them to your administrator.
Two status levels indicate the severity of detected host problems:
●
OK (green): The host is up and running; R&SCHM does not detect a problem.
●
CRITICAL (red): The host is down. Immediately check for problem details and
report them to your administrator.
3.3Focusing on specific components
For accessing the current state of specific system components, you can start from the
"Overview" view. This view provides specific filters that you can use to display only relevant resources or groups of resources.
11Manual 1179.3521.02 ─ 04
Page 12
R&S®CHM
Monitoring the system status
Focusing on specific components
Figure 3-4: Overview view
For example, select the "Hostgroups" to check the state of configured groups of host
from a specific location.
Figure 3-5: Host groups and their states
12Manual 1179.3521.02 ─ 04
Page 13
R&S®CHM
Monitoring the system status
Verifying status history
3.4Displaying status details
For displaying status details of a defective resource, you follow the links of this
resource. There are different detail levels that you can access.
1
Figure 3-6: Navigating on the web GUI
1= Show detailed information for selected service on related host.
2, 3 = Show detailed information for selected host.
Use the "Back" function of the web browser to return to the previous page.
3.5Verifying status history
For obtaining an overview of the system status over time, select the "History" view.
3
2
13Manual 1179.3521.02 ─ 04
Page 14
R&S®CHM
Monitoring the system status
Verifying status history
Figure 3-7: History of alerts
For example, you can display the alerts from the past in a grid of months and days and
thus you can identify problem accumulations by time.
Figure 3-8: Event grid - summary history of alerts
14Manual 1179.3521.02 ─ 04
Page 15
R&S®CHM
Monitoring the system status
Customizing the web GUI
3.6Customizing the web GUI
You can customize the following settings of the web GUI to suit your needs.
3.6.1Changing the theme
The default theme is light, which is suitable in bright surroundings. The dark theme
uses a black background and light labeling and is suitable in darkish surroundings.
To apply the dark theme
Starting situation: "Operator" > "My Account"
1. On the left menu, select "My Account".
The "Preferences" view opens.
2. On the "My Account" tab, set the "Theme" to "rs-company-theme/dark".
3. Save the settings to take the changes effect. You can apply the setting for the current session or make the setting permanent until you change it again.
The theme changes to dark.
3.6.2Managing user-defined navigation items
You can create additional, user-defined navigation items on the web GUI. These items
can help you focus on specific hosts or services if necessary.
To create a navigation item
Use this procedure to prepare navigation item that you can use to assign specific navigation items to. You can create menu items or items that are shown on the tabs of a
menu item, e.g. on the "Host" tab.
Prerequisite: If you want to create a host or service action, you need the link to this
host or service. You can copy the link from already existing hosts or services before
you continue. Right-click the host or service, and then select "Copy link address".
Starting situation: "Operator" menu > "My Account" dashboard
15Manual 1179.3521.02 ─ 04
Page 16
R&S®CHM
Monitoring the system status
Customizing the web GUI
A
B
C
D
E
FG
Figure 3-9: Creating and configuring a navigation item
1. On the "Navigation" tab, select "Create a New Navigation Item" (A).
2. Provide the necessary information for the navigation item.
●"Name" (mandatory) (B): Specify the name of the menu item.
●"Type" (mandatory) (C): Select "Menu Entry" to add the navigation item to the
main menu.
"Host Action" and "Service Action" assigns a navigation item to one of the predefined "Host" or "Services" dashboards.
●"Parent" (optional) (D): Select "None" to make this entry a main menu entry.
You can also select from already existing user-defined menu items.
●"Url": The link to a host or service. If you specify a main menu entry, an "Url" is
not necessary. But if you want to add a host or service, you need a link here.
The new navigation item is successfully created, see example "My Menu Entry" (F,
G).
To create dashlets
A dashlet represents an area on a dashboard. Dashlets are assigned to predefined or
user-defined dashboards. The web GUI already shows predefined dashlets, e.g. the
"Service Problems" dashlet on the "Dashboard" view > "Current incidents" dashboard.
You can add more user-defined dashlets to suit your needs. In this procedure, we create a dashboard with dashlet on the "Dashboard" view.
Starting situation: "Dashboard" view
1. Select the down arrow (A) next to already available dashboards.
16Manual 1179.3521.02 ─ 04
Page 17
R&S®CHM
Monitoring the system status
Customizing the web GUI
A
B
Figure 3-10: Adding a dashlet
2. From the list, select "Add Dashlet".
3. On the "New Dashlet" tab, specify the following:
C
D
Figure 3-11: Configuring a dashlet
●"Url" (
C): The link to a host or service.
●"Dashlet Title" (mandatory) (D): Enter the name of the dashlet.
●"New dashboard" (optional) (E, F): If selected, adds the dashlet to a new dash-
board. Enter the name fo the dashboard.
You have added a user-defined dashboard and a user-defined dashlet.
E
F
G
H
Figure 3-12: User-defined dashboard and dashlet on the web GUI
G = Dashboard
H = Dashlet
17Manual 1179.3521.02 ─ 04
Page 18
R&S®CHM
4System administration
The tasks within the following chapters are typically in responsibility of system administrators.
4.1Installing R&S CHM
Software installation is divided into these main parts:
●
R&SCHM host installation
The R&S CHM host software runs on CentOS. Use the Rohde & Schwarz life-cycle
software manager (LCSM) for installation. If LCSM is not available, follow the
description in Chapter 4.1.1, "Installing the R&S CHM host without LSCM",
on page 19.
●
R&SCHM agent installation
The agent software runs on monitored Windows- and CentOS Linux-based computers.
–"To install Windows agents"on page 20
–"To install CentOS Linux agents"on page 21
System administration
Installing R&S CHM
Before you start installation, review the minimum hardware and software requirements
for the R&S CHM host and the agents.
Hardware and software requirements
You can install the R&S CHM host software on a server or a virtual machine (VM).
Ensure that the R&S CHM host meets the minimum requirements listed in the following
table. Keep in mind that the requirements increase with an increasing number of monitored system components and services.
Table 4-1: Requirements for R&S
ComponentMinimum requirements
CPU2 cores with 2 GHz
HDD50 GByte
RAM2 GByte
LAN adapter1 Gbit/s, RJ-45 connector
Operating systemCentOS Linux v7 (2009) distribution
Table 4-2: Requirements for Windows agents
ComponentMinimum requirements
CHM hosts and CentOS Linux agents
Optional with hardening according to DISA standard
CPU2 cores with 2 GHz
HDD50 GByte
18Manual 1179.3521.02 ─ 04
Page 19
R&S®CHM
System administration
ComponentMinimum requirements
RAM2 GByte
Operating systemWindows 10 build 1809 and later
●Installing the R&S CHM host without LSCM........................................................... 19
The R&S CHM host runs on CentOS. If you do not have a host running this operation
system, we recommend downloading the CentOS minimal version from the internet.
To install CentOS Linux
For comprehensive installation instructions, visit https://docs.centos.org/en-US/centos/
install-guide/. In the following procedure, only the main steps are provided.
1. Visit the CentOS homepage at https://www.centos.org/download/.
Installing R&S
CHM
2. Download an ISO image of the CentOS Linux v7 (2009) that suits the hardware
architecture of your host, for example x86_64 for an Intel 64-bit server.
3. Prepare the installation source.
You can select from various options:
●If you need a bootable physical media, prepare a DVD or a USB flash drive.
●If you install CentOS in a virtual machine, configure the virtual machine with at
least the minimum requirements listed in Table 4-1. You can directly select the
ISO image as startup disk on your HDD.
●If needed, you also can save the ISO image from a location on the network and
boot it using NFS, FTP HTTP or HTTPS access methods.
4. Boot the installation media or ISO image.
5. Select "Install " in the boot menu and press [Enter].
Anaconda, the CentOS installer starts.
6. Follow the instructions on the screen.
All installation options are properly configured, such as language, region, keyboard
layout, date and time.
7. On the "INSTALLATION SUMMARY" screen, select "Begin Installation".
Installation of CentOS starts.
CentOS is installed on the host and ready for operation.
19Manual 1179.3521.02 ─ 04
Page 20
R&S®CHM
System administration
Installing R&S
To install the R&S CHM host software
1. Ask your Rohde & Schwarz sales representative or application engineer for providing the R&S CHM host software package.
2. Copy the chm-<version>.tar.gz archive to the R&S CHM host > /root/. For
example, you can use WinSCP for this task.
3. Log in to the R&S CHM server, e.g. using SSH.
4. Change to the directory where the chm-<version>.tar.gz file resides.
5. Unpack the archive.
# tar xfvz chm-*.tar.gz
6. Execute the install script.
# ./install-chm-server
Installation takes a while. Wait until the Completed message is shown.
The R&S CHM host is up and running.
Continue with Chapter 4.3.2, "Changing the configuration", on page 28.
CHM
4.1.2Installing R&S CHM agents
The agent is a program that runs remotely on a Windows or Linux computer. It helps
provide information to the R&S CHM host. Contained PowerShell modules are signed
on Windows and the Rohde & Schwarz certificate is installed.
Obtaining installers
Ask your Rohde & Schwarz sales representative or application engineer for providing
the software package for R&S CHM Windows and CentOS Linux agents.
To install Windows agents
R&S CHM supports the AllSigned execution policy.
1. Copy the CHM_Windows_Agent_<version>.exe installer to the Windows agent.
2. Run the CHM_Windows_Agent_<version>.exe installer.
3. If you install a Windows agent for gRPC-based R&S RAMON monitoring:
a) Copy the chmrd.msi to the Windows agent.
b) Run the chmrd.msi installer.
The Windows agent is installed successfully.
See also:
●Chapter 4.2, "Deploying certificates on R&S CHM agents", on page 21
●Chapter 4.3.6, "Configuring R&S RAMON for monitoring", on page 42
20Manual 1179.3521.02 ─ 04
Page 21
R&S®CHM
System administration
To install CentOS Linux agents
1. Copy the tar.gz installer archive to the CentOS Linux agent.
2. Execute # tar xfvz xxx.tar.gz.
3. Execute # ./install-chm-agent
The CentOS Linux agent is installed successfully.
4.1.3Firewall rules
The firewall rules are included in the software installer and thus set automatically. The
following table informs about necessary connections.
Table 4-3: Firewall rules
ConnectionPortProtocolUse case
CHM host → SNMP monitored
device
Maintenance PC → CHM nodeport 22SSHOptional SSH connection
Deploying certificates on R&S
port 161SNMPCollect monitoring information
CHM agents
PC → CHM nodeport 80HTTPViewing R&S CHM website in
web browser (redirection to
HTTPS)
PC → CHM nodeport 443HTTPSViewing R&S CHM website in
web browser (encrypted connection)
CHM node → VMWare ESXi/
vCenter
Monitored item Windows/Linux
→ CHM node
Monitored item Windows/Linux
←→ CHM node
port 443HTTPSMonitoring of VMWare ESXi/
vCenter status
port 5665IcingaEncrypted communication of Ici-
nga (monitoring information)
port 18005GrpcEncrypted communication of
R&S CHM (monitoring and control information)
4.2Deploying certificates on R&S CHM agents
Certificates protect the connections between the R&S CHM host and the R&S CHM
agents. Without certificates, R&S CHM cannot monitor the system state of connected
R&S CHM agents.
The following figure serves as example system configuration. This configuration is
used in the following procedures.
21Manual 1179.3521.02 ─ 04
Page 22
R&S®CHM
CHM host:
server1.local
CHM Windows agent:
win1.local
CHM CentOS agent:
centos1.local
System administration
Deploying certificates on R&S CHM agents
Figure 4-1: Example R&S CHM system
R&S CHM uses transport layer security (TLS) encryption to secure the communication
between the R&S CHM host and the R&S CHM agents. By default, certificates are selfsigned. Self-signed certificates are renewed automatically.
Also, you can use certificates that are provided by a central certificate authority (CA). If
you want to use certificates from a central CA, contact your certificate manager. Selfsigned certificates and a CA are generated automatically on the R&S CHM host during
software installation.
4.2.1Using self-singed certificates
You can use self-signed certificates as follows:
●
With pregenerated tickets, see "To deploy certificates with tickets"on page 22.
●
With certificate signing requests (CSR), see "To deploy certificates with signing
request"on page 24.
As a prerequisite for creating certificates, the R&S CHM host must be installed and
online.
To deploy certificates with tickets
The following figure shows the general workflow if you use self-signed certificates with
tickets.
22Manual 1179.3521.02 ─ 04
Page 23
R&S®CHM
Administrator
Administrator
CHM host
CHM host
CHM Windows agent
CHM Windows agent
Install CHM host software
and generate certificate infrastructure
(./install-chm-server)
Install agent software (MSI)
Generate ticket
(sudo chmpki winagent1.local)
Show ticket
(cb68312a78f6ddf428a3870773d00601e6d9bb0b)
Start script to request certificate with ticket
(chm-certificate-ticket.bat)
Request certificate with ticket
(chm-certificate-ticket.bat)
Create signed certificate
Start sending monitoring results
System administration
Deploying certificates on R&S
CHM agents
1. Log in to the shell of server1.local using ssh.
2. Execute sudo chmpki win1.local.
win1.local must be the FQDN of the windows agent.
A generated ticket is shown.
3. Note down that ticket.
4. Connect to the windows host.
5. Create certificates:
●On Windows, run this batch file:
%programfiles\chm\chm-certificate-ticket.bat
●On CentOS Linux, issue this command:
chm-certificate-ticket
The script prompts you for the server you want to connect to.
6. Enter server1.local and the ticket identifier.
The script creates the necessary certificates and configuration.
If necessary, you can call the script with command-line arguments to execute it
silently:
●On Windows, run the batch file with parameters, all on one line:
chm-certificate-ticket.bat
23Manual 1179.3521.02 ─ 04
Page 24
R&S®CHM
Administrator
Administrator
CHM host
CHM host
CHM Windows agent
CHM Windows agent
Install CHM host software
and generate certificate infrastructure
(./install-chm-server)
Note: Ensure that the timestamp and CN are correct to ensure that only valid
requests are singed.
The Windows agent can send its monitoring results to the R&S CHM host.
4.2.2Using CA-signed certificates
As an alternative to self-signed certificates, your company can use private certificate
authorities to issue certificates for your internal servers.
We recommend using the following naming conventions:
●
Certificate of the root CA: ca.crt
●
Certificate of the server: <fqdn>.crt, where fqdn is the fully qualified domain
name (FQDN).
1. Obtain the certificates from your certification authority.
2. Copy the certificates to these locations:
Deploying certificates on R&S
CHM agents
System componentLocation
R&S CHM host
Windows agent
CentOS Linux agent
/var/lib/icinga2/certs/
%programdata%\icinga2\var\lib\icinga2\certs\
/var/lib/icinga2/certs/
4.2.3Removing self-signed certificates
If necessary, you can remove all certificates on the R&S CHM host and the agents.
If you remove the certificates, system status monitoring is no longer possible.
► Execute these commands:
●On the R&S CHM host: sudo chm_clean_certificates
●On Windows agents: %programfiles\chm\clean_certificates.bat
●On CentOS Linux agents: sudo chm_clean_certificates
25Manual 1179.3521.02 ─ 04
Page 26
R&S®CHM
System administration
Configuring status monitoring
4.3Configuring status monitoring
Here, you can find all steps that are necessary to configure R&S CHM for system status monitoring. All data is contained in an editable configuration file. The configuration
file is written in YAML v1.2 notation standard.
YAML is a human readable data serialization language for all programming languages.
YAML is a case-sensitive language. It uses indentation with one or more spaces to represent the structure. Dashes (-) are used to represent the sequences (lists) and colons
(:) are used to represent key-value pairs. The upper part of the configuration file on the
R&S CHM host gives you an impression how this language looks like.
Table 4-4: Indicator characters - excerpt from the YAML syntax
Collection indicators
:Value indicator.
In threshold configurations, the colon (:) indicates the edges of the interval, see also
Thresholds on page 51
-Nested series entry indicator.
,Separate in-line branch entries.
[ ]Surround in-line series branch.
{ }Surround in-line keyed branch.
27Manual 1179.3521.02 ─ 04
Page 28
R&S®CHM
System administration
Configuring status monitoring
Misc indicators
#Throwaway comment indicator.
Use single quotes (' ') in YAML if your string value includes special characters. For
example, you possibly need single quotes around strings that contain these special
characters:
For details, see the YAML specification at https://yaml.org/spec in version v1.2.
4.3.2Changing the configuration
System administrators with root user account can configure R&S CHM and additional
monitoring hosts and services. All configurations are defined in a single configuration
file, which is the central configuration file for all objects that you want to monitor in the
network.
To access the configuration file
Access authorization: root
► On the R&S CHM host, you can find the configuration file here:
# /etc/opt/rohde-schwarz/chm/chm.yaml
You can edit the file locally. Alternatively, you can transfer the configuration file to
another PC, e.g. using WinSCP with SFTP or FTPS protocols. If finished, transfer it
back to its original location on the R&S CHM host.
To edit the configuration file
Access authorization: root
1. Open the chm.yaml file in an editor.
●On the local R&S CHM host, you can use the vi editor:
vi chm.yaml
●On a remote Windows host, you can use Windows Notepad or a more comfort-
able text editor with YAML syntax highlighting, e.g. Notepad++.
2. In the editor, navigate to the sequence item.
3. Add the key-value pairs.
4. Save the file.
5. If necessary, transfer the file back to its location on the R&S CHM host
(/etc/opt/rohde-schwarz/chm/chm.yaml).
6. Restart these services on the R&S CHM host to take the changes effect:
Configure the root element of the chm.yaml file. Specify the configuration and the
checks for the R&S CHM host and all other monitored R&S CHM agents and SNMP
devices.
Parameters:
nameSpecify the name of the host, i.e. the name of the R&S CHM
host, monitored R&S CHM agents and SNMP devices. A host
configuration always starts with the name key. The first host in
the file always denotes an R&S CHM host.
string
tagsStart a host group configuration. A host group comprises several
synchronized hosts. Specify this key for the R&S CHM host.
list of strings
29Manual 1179.3521.02 ─ 04
Page 30
R&S®CHM
System administration
Configuring status monitoring
chm
An R&S CHM host with tags: [chm] starts a monitoring system in which all hosts are synchronized in respect of configuration and monitoring state.
All hosts that are specified beneath, are part of this monitoring
system. The next R&S CHM host with tags: [chm] starts the
next system, and so forth.
In combination with exports, you configure multiple monitoring
systems. These hosts are not synchronized, because the
R&S CHM hosts are separated from each other, e.g. by a security gateway.
logging
exportsConfigure an R&S CHM host so that it sends status monitoring
authenticationConfigure LDAP-based user authentication. See
authorizationConfigure user authorization. See Authorization
webinterfaceConfigure a hyperlink to the management web interface of the
connectionsDefine the check plugin used.
hostgroupsList of groups the host belongs to. The groups help identify the
Configure the severity and the facility for event logging on the
R&S CHM host. See System loggingon page 33.
information to another R&S CHM host (optional). See
Export of status information on page 31.
Authentication on page 38.
on page 39.
host. See Hyperlink to management web interface
on page 35.
See Chapter 4.4, "Configuring services", on page 47.
For detailed R&S CHM host configuration examples, see Chap-
ter 4.5.1, "R&S CHM host configuration", on page 73 and
Chapter 4.5.2, "Linux host configurations", on page 75
30Manual 1179.3521.02 ─ 04
Page 31
R&S®CHM
System administration
Configuring status monitoring
Example: Single R&S CHM host configuration with some high-level keys.
hosts:
- name: host1.de
tags: [chm]
logging:
severity: info
facility: local0
authentication:
authorization:
webinterface:
connections: [icinga2_linux]
hostgroups: [monitoring, control]
checks: # The checks for this host
CHM agent connection (- chm_agent_connection)
Checks the connection between the R&S CHM host and the R&S CHM service that
runs on an agent. This check enhances reliability of the returned status.
Return status for checked agents:
●
"UP" if the service is running and connection is possible.
●
"DOWN" if the service is not running or connection is not possible.
You can configure this check for agents instead of ping.
Example:
checks:
- chm_agent_connection:
Dummy (- dummy)
Checks nothing but is mandatory if you add a host to the configuration although you do
configure a check for it. The check always shows status "UP" for the host. Use this
check if you cannot use another host check, e.g. if ICMP is blocked in the network.
Example:
- name: host_prepare.net
checks:
- dummy:
Export of status information (exports)
If two R&S CHM systems are separated by a security gateway, you can configure this
key to send status information from one R&S CHM host to the other R&S CHM host.
To do so, you configure the target R&S CHM host and the data format that is used by
R&S CHM for sending status monitoring information.
31Manual 1179.3521.02 ─ 04
Page 32
R&S®CHM
Domain B
Domain A
Monitored items (B)
CHM host
(B)
Monitored items (A)
Displayed items (B)
CHM host
(A)
Security gateway:
[filter data]
[Collect status
information]
[Display status
information]
[Collect status
information]
[Send status
information]
[Receive filtered
status information]
System administration
Configuring status monitoring
The following figure explains the basic principles. R&S CHM sends status information
from a Domain B to a separated Domain A. On its way, the status information is filtered by a security gateway. R&S CHM host (A) can monitor its own items and display
the monitored items from R&S CHM host (B).
Figure 4-2: Exporting status information form domain B to domain A
Prerequisite
Both R&S CHM hosts need identical chm.yaml files. So, first change the file on one
host. Then, transfer the file to the other host, e.g. using SSH. Example 2 at the end of
this description shows the high-level structure of the chm.yaml file.
Parameters:
xmlhttpInterface used for sending status information. This interface
uses HTTP with content type application/xml on TCP port 5669.
targetName of the R&S CHM host that receives the status information.
proxyIf the gateway acts as HTTP proxy, IP address or host name
(optional).
32Manual 1179.3521.02 ─ 04
Page 33
R&S®CHM
System administration
Configuring status monitoring
Example: Configuration with two R&S CHM hosts and some high-level
R&S CHM components send their log events into the Linux journal of the R&S CHM
host. The journal is a binary, ring-buffer like database.
By default, CentOS keeps the journal in volatile memory. You can persist messages to
text files by using the syslog service. It reads the journal and exports to text files by
some filter rules.
Note: Currently, R&S CHM does not provide means to change these export settings. If
you use the syslog service, R&S CHM logging can cause high IO and CPU load and
can degrade flash memory (SSDs). Ensure that only a subset of messages is exported, e.g. warning and higher.
For possible CentOS logging options, see the related man pages.
Logging configuration
You configure the logging level in the chm.yaml file under the hosts key, see Hosts
on page 29.
Viewing logs
33Manual 1179.3521.02 ─ 04
Page 34
R&S®CHM
System administration
Configuring status monitoring
As an administrator, you can view the logs using the # sudo journalctl command.
Log events can originate at different components. For identification of the component,
see Table 4-5.
Parameters:
severitySpecifies the severity level, i.e. the importance of the message.
For severity details, see Table 4-6.
If you change the severity, e.g. to err, only messages with
severity err or higher are logged (crit, alert, emerg). For
normal operation, we recommend the severity info.
*RST: info
facilitySpecifies the type of system that is logging the message accord-
ing to RFC 5424. Messages with different facilities can be handled differently.
local0
Locally used facility code. All R&S CHM components send their
logs as facility local0.
Range: local0 to local7
*RST: local0
Example: Logging configuration under the hosts key. The severities
with numerical code "0" to "5" are logged:
logging:
severity: notice
facility: local0
Example: Query of a specific component with # journalctl -t
<Identity> or # journalctl
SYSLOG_IDENTITY=<Identity>:
For example, query the monitoring web UI and the web server
status.
# journalctl -t chm-monitoring-webui -t chm-httpd
Example: Query of successful login, logout and failed login at the web
interface:
# journalctl | grep "User logged in"
# journalctl | grep "User logged out"
# journalctl | grep "User failed to authenticate"
Example: Filter for certain facilities using journalctl
SYSLOG_FACILITY=<facility_code>:
# journalctl SYSLOG_FACILITY=16
For a list of facility codes and their meaning, see RFC5424.
Example: Filter messages by severity with journalctl -p
<severity_or_severity_rage> or journalctl
PRIORITY=<numerical code>:
# journalctl PRIORITY=6
34Manual 1179.3521.02 ─ 04
Page 35
R&S®CHM
System administration
Configuring status monitoring
Example: Message output:
Oct 07 11:25:48 test.local chm-httpd[10476]:
Thu Oct 07 11:25:48.797427 2021] [ssl:info]
pid 121267] [client 172.27.18.70:56854]
AH01964: Connection to child 2 established
(server test.local.net:443)
Table 4-5: Functional components
Component identityDescription
icinga2Monitoring core
chm-monitoring-webuiMonitoring web UI
chm-monitoring-webui-auditUser login events at the monitoring web UI
chm-httpdWeb server status
chm-httpd-reqWeb server request and responses
Table 4-6: Logging levels (severities) in order of decreasing importance
Parameter valueNumerical codeDescription
emerg0Emergency - the system is unusable
alert1Alert - an action must be taken immediately
crit2Critical conditions
err3Error conditions
warning4Warning conditions
notice5Normal, but significant, condition
info6Informational message
debug7Debug-level message
Hyperlink to management web interface (webinterface)
Configure a hyperlink to the management web interface of monitored host. R&S CHM
shows the hyperlink on the web GUI.
35Manual 1179.3521.02 ─ 04
Page 36
R&S®CHM
System administration
Configuring status monitoring
12
Figure 4-3: Hyperlink to a web interface
1 = "Hosts" tab
2 = Hyperlink to web interface of the host
Configuration details
Select from the following options:
●
Compose the link automatically from the host name. This mechanism requires that
the host name is specified as fully qualified domain name. R&S CHM system status
monitoring automatically adds https:// in front of the host name to compose the
hyperlink, e.g. https://chm-staging-simulation.rsint.net.
●
Specify a dedicated URL, e.g. https://rohde-schwarz.com. The web GUI
shows this hyperlink.
●
Omit the parameter from the configuration to omit the entry on the web GUI.
HTTP or HTTPS web address of the web interface of the host. If the name of the host
is configured as URI, CHM automatically composes the hyperlink, e.g.
https://chm-staging-simulation.rsint.net.
Checks the availability of a host. To do so, R&S CHM sends ICMPv4 or ICMPv6
requests to the hosts.
This check cannot verify if the R&S CHM service runs on an agent. To check this property, use chm_agent_connection, see CHM agent connectionon page 31.
Example:
checks:
- ping:
4.3.4Configuring R&S CHM web users
Generally, you can select from two options for accessing the R&S CHM web GUI.
Local users
You can log in to the web GUI with one of the predefined local R&S CHM users.
If you do not configure both authentication and authorization, only the local users
admin and operator users are used. Users and permissions are fixed. The admin user
gets all permissions (acknowledge, check, comment, downtime, monitoring). The operator user gets only the monitoring permission.
LDAP users
You can configure an LDAP-based user authentication and authorization method.
R&S CHM then uses this method for restricting the permissions and the users that can
access the web GUI. Using LDAP, you can manage users or user groups centrally and
enhance security.
If you have configured LDAP authentication, the local users are irrelevant. Only LDAP
users can access the web GUI for monitoring the system status.
To control the permissions of the local R&S CHM users
You can use the local users admin and operator without further configuration. However, you can assign specific permissions, e.g. to the operator.
Access authorization: root
1. Under the first hosts list entry, add the authorization key.
2. Configure the permissions for specific roles. For example, configure check
and acknowledge for operators and the full set of permissions to
administrators. For all permissions and configuration details, see
Authorization on page 39.
You have configured the permissions for the local R&S CHM users.
37Manual 1179.3521.02 ─ 04
Page 38
R&S®CHM
System administration
Configuring status monitoring
To configure LDAP user authentication and authorization
LDAP usage also requires a configuration of the R&S CHM users in the central user
management of your company. Ask your local system administrator for support.
If you configure R&S CHM for LDAP authentication, the local users are no longer available on the web GUI.
Access authorization: root
1. Under the first hosts list entry, add the authentication key.
2. Configure user authentication. For the details, see Authentication
on page 38.
3. Add the authorization key on the same indention level as the
authentication key.
4. Configure user authorization. For the details, see Authorizationon page 39.
You have configured LDAP user authentication and authorization. You can log in to
the web GUI with the users or user groups that are configured on the LDAP server.
monitoringConfigure the authentication method for accessing the web GUI.
ldapObtain the credentials from a centrally maintained LDAP server.
serverSpecify the address of the LDAP server, either its fully qualified
domain name or its IP address. You can specify two redundant
LDAP servers to enhance availability of this authentication
method.
<FQDN> , <IP_address>
encryptionConfigure the encryption method that is used to secure the com-
munication between the LDAP server and the R&S CHM host.
The LDAP server must support your choice.
ldaps
Configure the LDAP over SSL protocol.
starttls
Configure the LDAP over TLS protocol.
base_dnSpecify the LDAP distinguished name (DN) of the branch of the
directory where the searches for users start from. The DN
uniquely identifies an object in the active directory.
string
38Manual 1179.3521.02 ─ 04
Page 39
R&S®CHM
System administration
Configuring status monitoring
user_classSpecify the LDAP class of user objects.
string
user_name_attrSpecify the LDAP attribute that holds the users name that is
used for the login.
string
bind_dnSpecify the DN used to bind to the server when searching for
users.
Currently, R&S CHM only supports simple authentication to an
LDAP server. Simple authentication in LDAP is an authentication
method that uses a DN and a password in a bind request for
LDAP authentication to a server.
string
bind_pwd_pathThe path of the LDAP simple authentication password within the
R&S CHM password store.
See also: Chapter 4.3.5, "Managing password identifiers",
on page 41
Configure user authorization. For the rules that apply for various configuration combinations, especially with LDAP authentication, see Chapter 4.3.4, "Configuring
R&S CHM web users", on page 37.
Parameters:
monitoringConfigure the authorization method for web GUI users.
rolesSpecify and configure the user roles that are available. You can
choose the names freely, e.g. administrators and
operators. The specified roles are generated on the
R&S CHM host.
string
permissionsList of permissions that is assigned to the role (optional).
acknowledge
Acknowledge hosts or service problems by selecting the
"Acknowledge" button on the web GUI.
39Manual 1179.3521.02 ─ 04
Page 40
R&S®CHM
System administration
Configuring status monitoring
check
Start a check immediately by selecting the
"Check now" button
on the web GUI.
comment
Leave a comment for a host or service by selecting the
"Com-
ment" button on the web GUI.
downtime
Schedule a downtime by selecting the "Downtime" button on
the web GUI. Host or service problems do not show up for the
dedicated host or service during the downtime.
usersList of users to which the role is applied, e.g. admin, operator,
john (optional).
Either specify users or groups.
<LDAP_user_name>
If you have configured LDAP authentication, only specify LDAP
user names.
admin
Name of the local administrator. Default password is
operator
Name of the local operator.
groupsList of LDAP user groups to which R&S CHM applies the role ,
e.g. company_chm_admins (optional).
This key is only relevant, if you have configured LDAP authentication.
All passwords for communication between R&S CHM and an LDAP server or
R&S CHM and the monitored services are encrypted using GPG. To ease password
handling, R&S CHM provides a password manager.
The password manager lets you safely specify necessary password identifiers for communication of R&S CHM via the following interfaces:
●
LDAP simple authentication password
●
SNMP
●
Proprietary interfaces, e.g. VMware
To list all password identifiers
Access authorization: root
1. Log in to the R&S CHM host.
2. Enter the following command:
# chmpass ls
The currently defined password identifiers are listed. For an example output, see
the following example.
Example: List configured password identifiers
$ chmpass ls
Password Store
├── tiger
├── bumblebee
└── ant
To add a password identifier
Access authorization: root
1. Log in to the R&S CHM host.
2. Type the following command:
# chmpass insert <password_identifier>.
41Manual 1179.3521.02 ─ 04
Page 42
R&S®CHM
System administration
Configuring status monitoring
Example: # chmpass insert tiger
3. Enter the password identifier.
4. Repeat the password identifier.
You successfully added the password identifier.
To remove a password identifier
Access authorization: root
1. Log in to the R&S CHM host.
2. Enter the following command:
# chmpass rm <password_identifier>
3. Confirm deletion.
You successfully removed the specified password identifier.
Example: Delete a password identifier
The name of the identifier is "tiger".
$ chmpass rm tiger
Are you sure you would like to delete tiger? [y/N] y
removed ‘/var/opt/chm/password-store//tiger.gpg’
To set a password identifier in the configuration file
Access authorization: root
1. Access the chm.yaml file.
See also: "To access the configuration file"on page 28
2. Under the check: key for the resource, add the key-value pair:
<identifier>: <password_identifier>
Examples
●For snmpv3: snmp_secname: tiger
●For vmware: user: lion
R&S CHM can access the checked resources via the set password identifier.
4.3.6Configuring R&S RAMON for monitoring
This monitoring method uses a gRPC-based R&S CHM service called chmrd. It replaces the deprecated Windows SNMP service.
42Manual 1179.3521.02 ─ 04
Page 43
R&S®CHM
System administration
Configuring status monitoring
Monitored hostR&S CHM host
Monitored application
(R&S RAMON)
Publish health
check via grpc:
port 18006
CHM monitoring
chmrd service
TLS encrypted:
port 18005
TLS encrypted:
port 18005
Network
Figure 4-4: Monitoring of applications, e.g. R&S RAMON
The following description explains the monitoring steps visualized in the previous figure.
Monitored application and R&S CHM
Applications "publish" monitoring data to chmrd. R&S CHM fetches the monitoring
data from chmrd.
The chmrd service
The service chmrd gathers monitoring data sent by applications and makes it available
to R&S CHM instances. Currently, it has to be installed on the same Windows host that
also runs the monitored application. It is necessary that you install the chmrd.msi on
the agent that runs R&S RAMON, see "To install Windows agents"on page 20.
Interface definition
The service provides a gRPC interface that can be used to both send and query monitoring data. The interface is defined in a protobuf file. This file describes the services
provided by chmrd and the data model that is used for communication and even how
this data is serialized on the wire. The file thus takes the role of a serialization document.
Security aspects
The chmrd service uses two separate TCP ports:
●
For communication with clients on the same host: local port, default port number
18006
On the local port, the service only listens for connections from localhost. There is
no encryption or authentication or authorization when using the local port. Its main
use case is for communication between chmrd and the monitored application.
●
For clients on remote hosts: remote port, default port number 18005.
43Manual 1179.3521.02 ─ 04
Page 44
R&S®CHM
4.3.6.1Configuring the chmrd service
System administration
Configuring status monitoring
When communicating over the remote port, chmrd enforces TLS encryption and
client authentication using X.509 certificates to secure network communication.
There is no authorization mechanism in place yet which means an authenticated
client is allowed to both send and query monitoring data without any restrictions.
The only officially supported way of configuring chmrd is to pass command-line arguments to the service.
Typically, you can use the default chmrd configuration. However, if you need to change
the configuration, continue as described in the following procedure.
To configure the chmrd service
This procedure assumes that the chmrd software is already installed.
1. Open the installation directory:
C:\Program Files\Rohde-Schwarz\chmrd\
2. Open a command prompt window in the installation directory.
3. Run the following command:
.\nssm.exe edit chmrd
The "NSSM service" editor opens.
4. Configure the desired arguments as listed in Table 4-7.
Note: Always keep the "-m chmrd" argument. This information tells the python
interpreter which module to use to start the service.
Table 4-7: Command-line arguments for configuring the chmrd service
Argument
(short)
Argument (long)Default
value
Description
"-a""--address""0.0.0.0"IP address the server runs on
"-p""--port""18005"Port for connections from remote hosts
" -P"" --local-port""18006"Port that clients on localhost can use with-
out needing to authenticate themselves
44Manual 1179.3521.02 ─ 04
Page 45
R&S®CHM
System administration
Configuring status monitoring
Argument
(short)
"-d""--cert-dir"
" -C""--server-cert"
" -R""--server-root-cert"
" -K""--server-priv-key"
" -c""--client-root-cert"
Argument (long)Default
value
" --insecure"
"--loglevel""info"One of "debug", "info", "warning", "error",
"--logfile"
" -- logfilemode""w""a" or "w"
Description
Directory with certificates and keys
Server certificate path
Server root certificate path
Server-private key path
Client root certificate path
If set, disable encrypted message transport and server/client authentication (without a value)
"critical"
Logfile path
"a" for appending to log file.
"w" for truncating log file and starting a
new one when the service is restarted
Example:
The following arguments set specific ports and how the log file is treated.
"-m chmrd -p=18007 -P=18008 --logfilemode=a"
About certificates and keys
All certificates and keys used for chmrd have to be PEM encoded.
To achieve encrypted and authenticated network communication, chmrd needs the following:
●
A server certificate chain
A certificate chain is a list of certificates where the issuer of each one of them
matches the subject of the following. Also each certificate - except for the last - is
signed with the secret key corresponding to the next certificate. The last certificate
in the chain is self-signed, which makes it a root certificate.
Usually, this chain consists of a certificate issued for the host on which the service
is running. This certificate is followed by some root CA's certificate that was used to
issue the certificate of the host. You can specify these two parts of the certificate
chain by using the "--server-cert" and the "--server-root-cert" arguments, including
the path to the corresponding files.
For the uncommon use case that the chain consists of more than two certificates,
you can split up the certificates to the two files specified by "--server-cert" and "-server-root-cert". Make sure that the resulting chain fulfills the criteria for a certificate chain described above.
●
A server-private key
This key is the private key corresponding to the certificate on the server, i.e. the
monitored host used for encrypting network communication. The file containing the
key can be specified by using the "--server-priv-key" argument.
45Manual 1179.3521.02 ─ 04
Page 46
R&S®CHM
System administration
Configuring status monitoring
●
A client root certificate
chmrd expects remote clients to provide a certificate chain to authenticate themselves. You can specify a file containing one or more root certificates for these
chains by using the "--client-root-cert" argument.
Default paths for certificates and keys
There are different possible combinations of how to use command-line arguments in
chmrd. The following tables list the defaults that are used in the different cases A, B
and C.
A) If no command-line arguments are specified, the defaults use the fully qualified
domain name (FQDN) of the host, see the following table.
Table 4-8: No command-line arguments are specified
The default file locations here correspond to the certificate settings you usually already
made for the R&S CHM Windows agent, see Chapter 4.2, "Deploying certificates on
R&S CHM agents", on page 21. Thus, no extra configuration is necessary for the
chmrd service. Also, the chmrd service expects that both server and clients to use
same root certificate by default.
B) If you specify "--cert-dir", you can set a custom location for all certificates and key,
see the following table.
Table 4-9: Only --cert-dir is specified
Argument (long)Default value
"--server-cert"
"--server-priv-key"
"--server-root-cert"
"--client-root-cert"
<CERT_DIR>\<FQDN>.crt
<CERT_DIR>\<FQDN>.key
<CERT_DIR>\ca.crt
<CERT_DIR>\ca.crt
C) If one or all "--server-cert", "--server-root-cert", "--server-priv-key", "--client-root-cert"
are specified, you can always specify a customized, absolute path to certificates and
key.
For information about configuration of the check in the chm.yaml file, see
gRPC-based R&S RAMON monitoring on page 66.
46Manual 1179.3521.02 ─ 04
Page 47
R&S®CHM
System administration
Configuring services
4.4Configuring services
R&S CHM can monitor a specific set of services. The following description provides an
overview of the hardware and software services you can monitor. Also, you find necessary information for configuration of new services.
Here, you can find the description of frequent keys (parameters) that you can use in
the check sections of configured hosts. For example, you need SNMP in all checks
that are based on this protocol.
Assigns a check to one or more specific groups that you can configure and display on
the web GUI.
Example:
checkgroups: [Cluster, Buster]
Example: If the check group contains a colon (:), enclose the whole check
group string in quotation marks.
checkgroups: ["Resources :- Disk space"]
Display name (displayname)
Display a user-friendly name on the GUI.
Example:
displayname: My special service name
SNMPv2 protocol (snmp_<property>)
Specify the properties of the SNMPv2 connection for unencrypted communication
between R&S CHM and the device. The following parameters also apply to the
SNMPv1 protocol.
47Manual 1179.3521.02 ─ 04
Page 48
R&S®CHM
System administration
Configuring services
For these common SNMP protocol parameters, see also SNMPv3 protocol
on page 48.
port
●
snmp_retries
●
snmp_timeout
●
Parameters:
snmp_versionSNMP protocol version, here version 1 or 2. See also
SNMPv3 protocol on page 48.
numeric
Range: 1 to 2
*RST: 2
snmp_communitySNMP community string for SNMPv1/v2 transactions. The com-
munity is a type of shared password between the SNMP management station and the device, which is used to authenticate
the SNMP management station.
string
*RST: public
Example:
port:161
snmp_version: 2
snmp_community: public
SNMPv3 protocol (port, snmp_<property>)
Specify the properties of the SNMPv3 connection for encrypted communication
between R&S CHM and the device.
See also: SNMPv2 protocolon page 47
Parameters:
portCommunication port at the device, the SNMP agent (optional).
numeric
*RST: 161
snmp_versionSNMP protocol version.
3
*RST: 2
snmp_secnameIdentifier (security name) used for authenticated SNMPv3 mes-
sages.
See also: Chapter 4.3.5, "Managing password identifiers",
on page 41
string
48Manual 1179.3521.02 ─ 04
Page 49
R&S®CHM
System administration
Configuring services
snmp_authprotoAuthentication protocol used for authenticated SNMPv3 mes-
sages. If your operating system is hardened with FIPS mode,
you cannot use MD5.
snmp_authpassPassword used for authenticated SNMPv3 messages (optional).
If not specified, R&S CHM looks up the password in the password store using the snmp_secname value as the identifier.
string
Option 1: Clear text password as used in the example at the
end of this key description.
Option 2: VAULT:<path_to_vault> as used in the example at the
end of this key description (recommended).
Option 3: If not specified, R&S CHM looks up the password in
the password store using the snmp_secname value as the identifier as used in the example at the end of this key description.
snmp_privproto
snmp_privpassPassword used for encrypted SNMPv3 messages (optional).
snmp_contextContext name used for SNMPv3 messages, e.g.
snmp_seclevelSecurity level used for SNMPv3 messages.
Privacy protocol used for encrypted SNMPv3 messages.
DES , 3DES, AES-128, AES-192 , AES-256, None
*RST: DES
string
Option 1: Clear text password as used in the example at the
end of this key description.
Option 2: VAULT:<path_to_vault> as used in the example at the
end of this key description (recommended).
Option 3: If not specified, R&S CHM looks up the password in
the password store using the snmp_secname value as the identifier as used in the example at the end of this key description.
spectracom_time
string
*RST: empty string ""
noAuthNoPriv , authNoPriv , authPriv
noAuthNoPriv authenticates with a username, i.e. no authentication and no encryption.
AuthNoPriv provides HMACMD5 or SHA algorithms for
authentication but no encryption.
AuthPriv provides HMAC MD5 or SHA algorithms for authentication and DES 56-bit encryption.
snmp_retriesNumber of retries to be used in the requests (optional).
numeric
*RST: 5
49Manual 1179.3521.02 ─ 04
Page 50
R&S®CHM
System administration
Configuring services
snmp_timeoutTimeout between retries (optional). Floating point numbers can
be used to specify fractions of seconds, e.g. 1.25.
numeric
*RST: 1
Default unit: s
Example: Option 1: Use the password store for a Spectracom Secure-
Sync timeserver and write the passwords in clear text to the
Option 3 (deprecated): Use the password store with identical
passwords:
- nport:
checkgroups: [water, earth, fire, air]
snmp_version: 3
snmp_context: nport
snmp_secname: mydeviceaccount
# lookup of passwords in password store
snmp_authproto: SHA
snmp_privproto: AES-256
50Manual 1179.3521.02 ─ 04
Page 51
R&S®CHM
System administration
Configuring services
Thresholds (thresholds)
Specify thresholds for alert levels. Use thresholds together with suitable checks as
mentioned in the description of the checks.
Thresholds are implemented according to the Monitoring Plugins Development Guide-
lines. The Table 4-11 is adopted from this guide.
Parameters:
warningThreshold for the warning alert level.
criticalThreshold for the critical alert level.
Example:
Generalized format of ranges:
[@]start:end
Table 4-11: Example ranges
Range definitionGenerate an alert if x...
10< 0 or > 10 (outside the range of {0 .. 10})
10:< 10, (outside {10 .. ∞})
~:10> 10, (outside the range of {-∞ .. 10})
10:20< 10 or > 20 (outside the range of {10 .. 20})
@10:20≥ 10 and ≤ 20 (inside the range of {10 .. 20})
4.4.2Hardware services
thresholds:
warning: :0 # E.g. alert if 1 or more exceed. occurred
critical: :0 # E.g. alert if 1 or more exceed. occurred
thresholds:
warning: 20: # E.g. alert if check cond. falls below 20
critical: 10: # E.g. alert if check cond. falls below 10
Here, you can find all services that you configure for monitoring of hardware components.
thresholdsCheck-specific alert levels. For more information about the
threshold syntax, see Thresholdson page 51. The following
values only apply to the current load on Windows.
For Linux, see load<minutes>.
*RST: warning: 90, critical: 99
Default unit: %
52Manual 1179.3521.02 ─ 04
Page 53
R&S®CHM
System administration
Configuring services
load<minutes>On Linux, check load averages in the last 1 min, 5 min and 15
min (fixed). The threshold defines the utilization ratio of all processor cores.
The Linux load averages depend on the number of processor
cores. For a single-core processor, a load of 1.0 means that the
processor is exactly at capacity. Smaller values indicate that
there is still capacity available. Higher values indicate problems,
i.e. the system is slowing down or hanging.
On a multicore system, ensure that the load does not exceed the
number of cores available. It does not matter how the cores are
spread out over CPUs. Two quad-cores match four dual-cores
match eight single-cores, i.e. in sum consider eight cores
when configuring the alert levels.
warning, critical
Increment:
0.01
Default unit: numeric
For alert level defaults, see Table 4-12.
Monitor the hardware status of a server with a Dell iDRAC interface via SNMP.
Checked values
●
Global system status
●
Global lcd status
●
System power
●
Global storage status
●
Power unit redundancy
●
Power unit status
●
Chassis intrusion sensor status
●
Cooling unit status
●
Status of all drives
●
Predictive status of all drives
●
All temperatures
If a component does not exist or if a sensor in the server version does not exist, set
this check manually to true. For example, if there are no hard disks (diskless server),
set key no_disks to true.
Related parameters
●
SNMPv3 protocol, SNMPv2 protocol
Parameters:
no_storageDo not check global storage condition (optional).
true
no_systemDo not check global system status (optional).
true
no_powerDo not check global power status (optional).
true
no_temperatureDo not check overall thermal environment condition (optional).
true
no_disksDo not check the disks (optional).
true
no_power_unitDo not check the power unit (optional).
true
no_intrusionDo not check the intrusion sensor (optional).
true
no_coolingDo not check the cooling unit (optional).
true
54Manual 1179.3521.02 ─ 04
Page 55
R&S®CHM
System administration
Configuring services
no_redundancyDo not check the power unit redundancy (optional).
true
no_predictiveDo not check the predictive status of the disks (optional).
true
no_lcdDo not check the LCD status (optional).
true
Example:
- idrac:
no_power_redundancy: true
Disk space (- os_disk)
Monitor available disk space.
Parameters:
includeList of drives (on Windows) or volumes (on Linux) that are moni-
tored (optional). If not set, R&S CHM monitors all disks or volumes.
string
*RST: none
thresholdsAlert levels for available disk space (optional).
For more information about the thresholds syntax, see
Thresholds on page 51.
warning , critical
On Windows: used disk space.
On Linux: free disk space.
Uninterruptible power supply - RFC1628-compatible (- ups)
Monitor a UPS that is compatible to RFC1628 via SNMP.
Related parameters
●
SNMPv3 protocol, SNMPv2 protocol
●
Thresholds
Select one of the following checks. Each check returns a single metric.
Parameters:
alarmsCheck the present number of active alarm conditions.
In combination with thresholds, R&S CHM generates an alert.
secondsonbatteryCheck if the unit is running on battery power? If not, the UPS
returns zero.
If the unit is not running on battery power the following is
checked, whichever is less:
The elapsed time since the UPS last switched to battery power.
– or –
The time since the network management subsystem was last
restarted.
In combination with thresholds, R&S CHM generates an alert.
Default unit: s
minutesremainingCheck estimated time to battery charge depletion under the
present load conditions in the following cases:
The utility power is off and remains off.
– or –
The utility power is going to be lost and remains off.
In combination with thresholds, R&S CHM generates an alert.
Default unit: min
thresholdsSpecify check-specific alert levels. For more information about
Monitor a VMware ESXi/vcenter server, e.g. datastores. You can specify up to four
checks for a host.
Available checks
●
Alarms
●
Datastore usage
●
CPU usage
●
Memory usage
Related parameters
●
Thresholds
Parameters:
userThe user name that is used to log in at the server.
string
insecureCheck the server certificate (optional).
false , true
Server certificate is checked ('false') or not checked ('true').
*RST: false
typeThe entity type of the monitored object: alarm, datastore,
hostsystem.
alarmCurrently not acknowledged alarms on the alarm list result in an
alert with the severest alarm state, i.e. warning or critical.
datastoreGets used disk space on datastore objects.
hostsystemGets CPU and memory usage on all HostSystem objects, i.e.
ESX(i) hosts. See also the thresholds parameter.
62Manual 1179.3521.02 ─ 04
Page 63
R&S®CHM
System administration
Configuring services
idThe unique identifier for the monitored object (optional). If no id
is given, all objects of the specified type are checked. E.g., for
datastores, id is the name of the datastore. The parameter is
not supported for alarm and hostsystem.
string
portPort of the VMware vSphere API (optional).
numeric
*RST: 443
thresholdsSpecify check-specific alert levels (optional). For more informa-
tion about the thresholds syntax, see Thresholds
on page 51. The thresholds for the datastore usage define the
used datastore space (in %).
Test the availability of DHCP servers on a network. By default, the check broadcasts a
DHCPDISCOVER packet to port 67/UDP and checks whether a DHCPOFFER is
received on 68/UDP within a given timeout.
Parameters:
serversList of IP address of DHCP servers from which an answer is
expected (optional). If multiple servers are specified, and some
but not all respond, this situation results in a warning alert.
IPaddress1 , IPaddress2 , IPaddress<n>
*RST: Any responding DHCP server is ok.
offeredipExpected IP address in DHCPOFFER (optional). If specified,
and a DHCPOFFER with unexpected IP is received, this situation results in a warning alert.
*RST: Any offered IP address is ok.
timeoutTime to wait for DHCPOFFER (optional).
*RST: 2
Default unit: s
interfaceInterface to be used for listening (optional).
*RST: eth0
64Manual 1179.3521.02 ─ 04
Page 65
R&S®CHM
System administration
Configuring services
macMAC address to use in the DHCP request (optional).
*RST: MAC address of the configured interface
unicastIf true, mimics a DHCP relay (optional). Requires to set also at
Test the availability of DNS servers on a network. The default servers from /etc/resolv.conf are used unless explicitly specified.
Related parameters
●
Thresholds
Parameters:
lookupThe hostname or IP to query the DNS for (optional).
string
*RST: Name of host where check is executed
serverThe DNS server to query.
IPaddress
*RST: The server configured in the OS.
query_typeThe DNS record type (optional).
A
IPv4 address record.
AAAA
IPv6 address record.
SRV
Service location record.
TXT
Text record.
MX
Mail exchange record.
ANY
A special query (meta-query, deprecated).
*RST:
A
answersThe answers to look for. A hostname must end with a dot. Multi-
ple answers must be defined as array (optional)
string
*RST: Do not check for specific addresses in answer
65Manual 1179.3521.02 ─ 04
Page 66
R&S®CHM
System administration
Configuring services
authoritativeExpect the server to send an authoritative answer. Non-authori-
tative answers are marked with "non-authoritative answer:" and
mean that a name server looked up the entry from it is local
cache (optional). If set to false, there is no check whether
authoritative or not.
boolean
*RST: false
accept_cnameAccept CNAME (canonical name, aka alias) responses as a
valid result to a query (optional).
timeoutSeconds before connection times out, i.e. forced interruption by
SIGALRM, then SIGKILL (optional).
numeric
*RST: 10
Default unit: s
thresholdsAlert levels for used datastore space (optional).
For more information about the thresholds syntax, see
Thresholds on page 51.
Example:
- dns
lookup: my_dnsserver
accept_cname:
timeout: 20
gRPC-based R&S RAMON monitoring (- chm_remote_grpc)
Monitor health summary, status, metrics of R&S RAMON and R&S SIMCOS. For concepts an configuration instructions, see Chapter 4.3.6, "Configuring R&S RAMON for
monitoring", on page 42.
Parameters:
appidThe identifier of the software, see Table 4-13.
string
checkidThe identifier of the device, see Table 4-13.
With R&S SIMCOS, set the checkid that you have specified
during device configuration.
string
portRemote TCP port.
numeric
*RST: 18005
server_root_certPath of the file that contains the PEM encoded root certificate of
the target host. The certificate is used for authenticating the target host.
string
*RST: /var/lib/icinga2/certs/ca.crt
66Manual 1179.3521.02 ─ 04
Page 67
R&S®CHM
System administration
Configuring services
client_root_certPath of the file that contains the PEM encoded root certificate of
the local host. The certificate is used by the server in combination with client_cert for authenticating the local host.
string
*RST: /var/lib/icinga2/certs/ca.crt
client_certPath of the file that contains the PEM encoded certificate of the
local host. The certificate is used by the server in combination
with client_root_cert for authenticating the local host.
string
*RST: /var/lib/icinga2/certs/<localhost_fqdn>.crt
client_privkeyPath of the file that contains the PEM encoded private key that
corresponds to client_cert of the local host.
string
*RST: /var/lib/icinga2/certs/<localhost_fqdn>.crt
insecureIf set to true, try connecting without encryption and client/server
authentication.
boolean
*RST: false
Example:
Table 4-13: Supported software and related parameters
Softwareappidcheckid
R&S SIMCOSSIMCOSIII<checkid>
R&S RAMON CA120CA120ServerStorageUnits
R&S RAMON CA120CA120ServerProcessingUnits
R&S RAMON CA120CA120ServerTuners
R&S RAMON CA120CA120ServerServer
R&S RAMON AntennamatrixAntennaMatrixDRVXXXChmSnmpCheck1
Check health and utilization data of R&S CHM instruments via LXI.
Example:
- hums:
Icinga2 cluster (- icinga2_cluster)
Check if all endpoints in the current Icinga2 zone and the directly connected zones are
working properly.
Example:
- icinga2_cluster:
Monitor file content (- file_content)
Monitor the content of a file on a Linux agent for a predefined string.
Parameters:
fileName of the monitored file (optional).
string
*RST: /tmp/import_service_result
stringThe search string (optional).
string
returnstatusReturn value if the check fails, i.e. WARNING or CRITICAL
(optional).
WARNING, CRITICAL
oksummaryThis text is shown if the string is found in the file.
string
badsummaryThis text is shown if the string is not found in the file.
string
showcontentShow the content of the file in the long output.
string
70Manual 1179.3521.02 ─ 04
Page 71
R&S®CHM
System administration
Configuring services
Example:
- file_content:
file: /tmp/import_service_result
string: specific_search_string
returnstatus: CRITICAL
oksummary: Import Service OK
badsummary: Import Service FAILED
Operating system process (- os_process)
Monitor if a defined process is running on the system.
Parameters:
nameName of the process. If at least one instance is found, the check
is OK.
commandlineThe check is performed against the command line of the proc-
ess (optional).
If at least one instance is found, the check is OK.
On Linux: Regex is supported. For escaping special characters,
use a backslash (\).
On Windows: Wildcards are supported (see: https://docs.micro-
Monitor any device that implements RS-RAMON-CHM-REMOTE MIB, e.g.
R&S RAMON and R&S SIMCOS.
Related parameters
●
SNMPv2 protocol
Parameters:
appidThe identifier of the software, see Table 4-13.
string
checkidThe identifier of the device, see Table 4-13.
With R&S SIMCOS, set the checkid that you have specified
during device configuration.
With R&S SIMCOS, set the checkid that you have specified
during device configuration.
The following YAML code snippet shows the top part of the configuration file with the
definition of the R&S CHM host. For configuration details, see Chapter 4.3.3, "Config-
See also: "To edit the configuration file"on page 28.
5.2R&S CHM shows message "Wrong SNMP PDU
digest"
Or you can see the SNMP error "No SNMP response received before timeout".
Resolution
► Check the SNMP settings on the device, i.e. context, snmp_authpass,
snmp_privpass, snmp_authproto, etc. The configuration in the chm.yaml file
does not match the monitored device.
See also: SNMPv3 protocolon page 48
5.3R&S CHM web GUI shows 404 error
This error is a standard HTTP error message code. It means that the website that you
were trying to reach could not be found on the server. One of the possible causes is
that the LDAP server is not reachable.
77Manual 1179.3521.02 ─ 04
Page 78
R&S®CHM
Troubleshooting
Contacting customer support
Resolution
1. Ensure that the LDAP server is up and running.
2. If you cannot fix the problem, consider disabling LDAP in the YAML configuration to
access the web GUI using a local user account.
To disable LDAP, see Chapter 4.3.4, "Configuring R&S CHM web users",
on page 37.
5.4Contacting customer support
Technical support – where and when you need it
For quick, expert help with any Rohde & Schwarz product, contact our customer support center. A team of highly qualified engineers provides support and works with you
to find a solution to your query on any aspect of the operation, programming or applications of Rohde & Schwarz products.
Contact information
Contact our customer support center at www.rohde-schwarz.com/support, or follow this
QR code:
Figure 5-1: QR code to the Rohde
&
Schwarz support page
78Manual 1179.3521.02 ─ 04
Page 79
R&S®CHM
Glossary: Abbreviations and terms
Glossary: Abbreviations and terms
A
AES: Advanced encryption standard
agent: A monitored Windows or Linux host is named as "agent" in the R&S CHM sta-
tus monitoring system.
API: Application programming interface
C
CA: Certificate authority
CentOS: Linux distribution that is derived from Red Hat Enterprise Linux (RHEL). Cen-
tOS is required for running the R&S CHM software.
CPU: Central processing unit
CSR: Certificate signing request
CTS: Clear to send
D
DES: Data encryption standard
DISA: Defense Information Systems Agency
DN: Distinguished name
DNS: Domain network service
DSR: Data set ready. A DSR signal change indicates that the power of the data com-
munication equipment is off.
DTR: Data terminal ready
F
FIPS: Federal Information Processing Standard. FIPS standards establish require-
ments, e.g. for ensuring computer security and interoperability.
FQDN: Fully qualified domain name
G
GPG: GNU privacy guard
79Manual 1179.3521.02 ─ 04
Page 80
R&S®CHM
Glossary: Abbreviations and terms
gRPC: General-purpose remote procedure calls
GUI: Graphical user interface
H
HDD: Hard disk drive
HMAC: Hash-based message authentication code
host: A physical server or virtual machine that runs the operating system and the
R&S CHM software.
HP iLO: Integrated Lights-Out interface from Hewlett-Packard for configuration, update
and remote server operation
HTTP: Hypertext transfer protocol
HTTPS: Hypertext transfer protocol secure
HUMS: Rohde & Schwarz health and utilization monitoring system
I
ICMP: Internet control message protocol
iDRAC: Integrated Dell remote access controller
ISO image: A disc image that contains everything that would be written to an optical
disc. The ISO image contains the binary image of the optical media file system.
L
LAN: Local area network
LCD: Liquid crystal display
LCSM: Life-cycle software manager
LDAP: Lightweight directory access protocol
LXI: LAN extensions for instrumentation
M
MAC: Media access control
MD5: Message digest algorithm 5
80Manual 1179.3521.02 ─ 04
Page 81
R&S®CHM
Glossary: Abbreviations and terms
MIB: Management information base. Collection of objects in a virtual database that
allows network managers using Cisco IOS software to manage devices such as routers and switches in a network.
N
NTP: Network time protocol
P
PAE: Port access entity
PDF: Portable document format. Frequently used file format for saving and exchanging
documents.
PEM: Privacy-enhanced mail; a container format that can include only a public certificate or an entire certificate chain, including public key, private key, and root certificates.
R
RAM: Random-access memory
S
SHA: Secure hash algorithm
SNMP: Simple network management protocol
SSD: Solid state drive
SSH: Secure shell
T
TCP: Transmission control protocol
TLS: Transport layer security
U
UPS: Uninterruptible power supply
UTC: Universal time coordinated
V
VM: Virtual machine
X
XML: Extensible markup language
81Manual 1179.3521.02 ─ 04
Page 82
R&S®CHM
Glossary: Abbreviations and terms
Y
YAML: YAML™ ain't markup language
82Manual 1179.3521.02 ─ 04
Page 83
R&S®CHM
Glossary: Specifications
Glossary: Specifications
R
RFC 5424: The Syslog Protocol
RFC1213: Management Information Base for Network Management of TCP/IP-based
CPU load..........................................................................................................................................................52
Disk space....................................................................................................................................................... 55
DNS server...................................................................................................................................................... 65
Export of status information............................................................................................................................. 31
gRPC-based R&S RAMON monitoring............................................................................................................66
HP iLO hardware............................................................................................................................................. 56
Hyperlink to management web interface..........................................................................................................35
NTP server time synchronization.....................................................................................................................71
Operating system process............................................................................................................................... 71
System logging................................................................................................................................................ 33
Uninterruptible power supply - RFC1628-compatible...................................................................................... 61
VMware ESXi/vcenter server inventory........................................................................................................... 62
Windows security update.................................................................................................................................73