Alerting on runZero system events

View as Markdown

runZero logs system events for administrative actions involving assets, agents, tasks, users, and other components of the platform. Alerting on those events helps you monitor your runZero environment. The agent-offline system event covers the case where an Explorer goes offline.

Who is this playbook for and why?

System events can be useful to a broad range of roles, depending on how your runZero implementation is staffed, but IT operations and cybersecurity personnel are the most common audience. Sending alerts by email or webhook lets you monitor runZero the same way you monitor the other platforms in your technology stack, which improves overall efficiency.

How will runZero help?

runZero monitors Explorer health and notifies you when an Explorer goes offline.

What will I need to do?

To monitor for agent-offline system events, you will:

  1. Determine the appropriate system event action for your use case.
  2. Create an alert template.
  3. Configure a notification channel.
  4. Create a rule.

Steps to implement

Follow these steps to configure a notification rule for the agent-offline system event.

Configure an alert template

  1. Go to Alerts > Templates and select Create Template.
  2. Enter a Name.
  3. Select a Template type.
  4. Choose a Subject line for message.
  5. Format the Body of message.
  6. Click Save Template.

You can customize both the subject line and the body of the message, and you can include details from the system event in either one using event detail objects. The use cases section below lists the fields available for each event, and the creating alert templates page lists additional variables.

Configure a notification channel

  1. Go to Alerts > Channels and select Create Channel.
  2. Enter a Name.
  3. Select a Channel type.
    • For Email, enter the Email address that will receive notifications.
    • For Webhook, enter the Webhook URL and any Additional headers the notification may require.
  4. Select Save Channel.
Tip
To send alerts by SMS, select the Email address option and enter the phone's SMS email address. For example, 1235556789 @msg.fi.google.com sends an SMS message to a Google Fi device with the number 123-555-6789.

Configure an alert rule

  1. Go to Alerts > Rules and select Create Rule.
  2. Select an event type.
  3. Select Configure Rule.
  4. Enter a Name for the new rule.
  5. Select the Conditions for the rule. By default, Any organization and Any site are selected.
  6. Select the Notification channel that you created.
  7. Select the Notification template that you created.
  8. Confirm that Enabled is checked and click Save Rule.

Use cases

Each use case below applies the previous instructions to one event type. It describes the event, names the event type to select when configuring the alert rule, and lists the event detail objects you can use when configuring an alert template.

Alerting on agent-offline system events

The agent-offline event type notifies you when an Explorer goes offline. It is useful to the people who administer the runZero platform and to the IT Operations and SRE personnel who monitor the overall health of IT infrastructure.

Event details

These event detail objects are available in an alert template for agent-offline events. View all objects available for configuration.

Field Contents Example
{{event.agent_external_ip}} The external IP address of the Explorer that is offline 13.248.161.247
{{event.agent_host_id}} The UUID of the host where the offline Explorer is installed a3b7245bde3ddd053bd0d477ade8f364
{{event.agent_id}} The UUID of the runZero Explorer that is offline d388b66a-8052-466e-8d38-1a406c240bb2
{{event.agent_internal_ip}} The internal IP address of the Explorer that is offline 192.168.1.100
{{event.agent_last_seen}} The epoch date and time that the offline Explorer was last seen 1662544551
{{event.agent_name}} The name of the Explorer that is offline EXPLORER01
{{event.agent_os}} A summary of the Explorer’s operating system Microsoft Windows Server 2016
{{event.agent_tags}} An array of tags set on the Explorer location=datacenter
{{event.agent_version}} The version of the Explorer software installed 3.0.15 (build 20220901210518) [c538aa22b33e72ad048d7d03204397ecba0bb354]
{{event.organization_id}} The UUID of the organization where the offline Explorer is located 98828456-f9ee-485d-aff6-11ddc91b2468
{{event.organization_name}} The name of the organization where the offline Explorer is located runZero
{{event.site_id}} The UUID of the site where the Explorer is assigned, if applicable 22f9bfba-31ef-4640-8c95-379474c1ffb1
{{event.site_name}} The name of the site where the Explorer is assigned, if applicable Datacenter

Alerting on agent-reconnect system events

The agent-reconnected event type complements agent-offline by notifying you when an offline Explorer reconnects to the console. It is useful to the same audience: the people who administer the runZero platform and the IT Operations and SRE personnel who monitor the overall health of your IT infrastructure.

Event details

These event detail objects are available in an alert template for agent-reconnect events. View all objects available for configuration.

Field Contents Example
{{event.agent_external_ip}} The external IP address of the Explorer that is offline 13.248.161.247
{{event.agent_host_id}} The UUID of the host where the offline Explorer is installed a3b7245bde3ddd053bd0d477ade8f364
{{event.agent_id}} The UUID of the runZero Explorer that is offline d388b66a-8052-466e-8d38-1a406c240bb2
{{event.agent_internal_ip}} The internal IP address of the Explorer that is offline 192.168.1.100
{{event.agent_last_seen}} The epoch date and time that the offline Explorer was last seen 1662544551
{{event.agent_offline_time}} How long the Explorer was offline 19h37m19.848350811s
{{event.agent_name}} The name of the Explorer that is offline EXPLORER01
{{event.agent_os}} A summary of the Explorer’s operating system Microsoft Windows Server 2016
{{event.agent_tags}} An array of tags set on the Explorer location=datacenter
{{event.agent_version}} The version of the Explorer software installed 3.0.15 (build 20220901210518) [c538aa22b33e72ad048d7d03204397ecba0bb354]
{{event.organization_id}} The UUID of the organization where the offline Explorer is located 98828456-f9ee-485d-aff6-11ddc91b2468
{{event.organization_name}} The name of the organization where the offline Explorer is located runZero
{{event.site_id}} The UUID of the site where the Explorer is assigned, if applicable 22f9bfba-31ef-4640-8c95-379474c1ffb1
{{event.site_name}} The name of the site where the Explorer is assigned, if applicable Datacenter

Alerting on license-limit-exceeded system events

The license-limit-exceeded event type notifies you when your total number of live assets exceeds the maximum your license allows.

Event details

These event detail objects are available in an alert template for license-limit-exceeded events. View all objects available for configuration.

Field Contents Example
{{event.asset_overage}} The total number of assets over the max asset limit 150
{{event.license_live_asset_count}} The total number of live assets associated with your account 1150
{{event.license_max_assets}} The maximum number of assets permitted under your license 1000
{{event.license_project_asset_count}} The total number of project assets associated with your account 3000
{{event.license_recent_asset_count}} The total number of assets seen in the last 30 days 1150
{{event.license_recent_project_asset_count}} The total number of project assets seen in the last 30 days 3500
{{event.license_type}} The type of license that is assigned to your account platform
{{event.source_id}} The ID of the source that led to the license overage 1
{{event.source_type}} The name of the source that led to the license overage runZero
{{event.task_type}} The type of task that led to the license overage import

Sample system event alert templates

Alert templates let you customize and format the alerts your rules trigger. Start with one of these two templates.

Sample JSON for agent-offline and agent-reconnect system events

{
  "agent_name": "{{event.agent_name}}",
  "agent_internal_ip": "{{event.agent_internal_ip}}",
  "agent_external_ip": "{{event.agent_external_ip}}",
  "agent_last_seen": "{{event.agent_last_seen}}",
  "agent_offline_time": "{{event.agent_offline_time}}",
  "agent_host_id": "{{event.agent_host_id}}",
  "agent_id": "{{event.agent_id}}",
  "agent_os": "{{event.agent_os}}",
  "agent_tags": ["{{event.agent_tags}}"],
  "agent_version": "{{event.agent_version}}",
  "organization_id": "{{event.organization_id}}",
  "organization_name": "{{event.organization_name}}",
  "site_id": "{{event.site_id}}",
  "site_name": "{{event.site_name}}"
}

Sample JSON for license-limit-exceeded system events

{
  "asset_overage": "{{event.asset_overage}}",
  "license_recent_asset_count": "{{event.license_recent_asset_count}}",
  "license_live_asset_count": "{{event.license_live_asset_count}}",
  "license_max_assets": "{{event.license_max_assets}}",
  "license_project_asset_count": "{{event.license_project_asset_count}}",
  "license_recent_project_asset_count": "{{event.license_recent_project_asset_count}}",
  "license_type": "{{event.license_type}}",
  "source_id": "{{event.source_id}}",
  "source_type": "{{event.source_type}}",
  "task_type": "{{event.task_type}}"
}

Outcome demo

This short video shows what the outcome of alerting on runZero system events may look like.

Getting help

For help building out this process, book a session with a runZero Customer Success Engineer.

Updated