MRTG 系列 :参数设定(中篇)

{ Posted on 星期六, 十二月 11, 2010 by Kaiser.XKw }
MRTG 系列 :参数设定(中篇)

ConversionCode

 

Some devices may produce non-numeric values that would nevertheless be useful to graph with MRTG if those values could be converted to numbers. The ConversionCode keyword specifies the path to a file containing Perl code to perform such conversions. The code in this file must consist of one or more Perl subroutines. Each subroutine must accept a single string argument and return a single numeric value. When RRDtool is in use, a decimal value may be returned. When the name of one of these subroutines is specified in a target definition (see below), MRTG calls it twice for that target, once to convert the the input value being monitored and a second time to convert the output value. The subroutine must return an undefined value if the conversion fails. In case of failure, a warning may be posted to the MRTG log file using Perl's warn function. MRTG imports the subroutines into a separate name space (package MRTGConversion), so the user need not worry about pollution of MRTG's global name space. MRTG automatically prepends this package declaration to the user-supplied code.

Example: Suppose a particular OID returns a character string whose length is proportional to the value to be monitored. To convert this string to a number that can be graphed by MRTG, create a file arbitrarily named ``MyConversions.pl'' containing the following code:

 

# Return the length of the string argument

sub Length2Int {

  my $value = shift;

  return length( $value );

}

 

Then include the following global keyword in the MRTG configuration file (assuming that the conversion code file is saved in the mrtg/bin directory along with mrtg itself):

 

ConversionCode: MyConversions.pl

 

This will cause MRTG to include the definition of the subroutine Length2Int in its execution environment. Length2Int can then be invoked on any target by appending ``|Length2Int'' to the target definition as follows:

 

Target[myrouter]: 1.3.6.1.4.1.999.1&1.3.6.1.4.1.999.1:public@mydevice|Length2Int

 

See ``Extended Host Name Syntax'' below for complete target definition syntax information.

 


 

Per target configuration

 

Each monitoring target must be identified by a unique name. This name must be appended to each parameter belonging to the same target. The name will also be used for naming the generated webpages, logfiles and images for this target.

 

# 注释 :下面开始介绍监测对象的配置。

 

# 由于一个 mrtg.cfg 文件中可以配置多个监测对象,为了区分不同的对象

 

# 每个被监测的对象都要有一个名称,所有和该对象相关的属性的定义都必须引用该名称,用于区分到底是定义那个对象的。

 

# 注释 :同时这个名称还被用于页面的生成、日志文件、

 


 

Target

With the Target keyword you tell mrtg what it should monitor. The Target keyword takes arguments in a wide range of formats:

 

# 注释 :首先就是 Target 选项了。它不仅为被监测对象分配一个名称,也指出了要监测对象的 oid

 

# Target 的格式是 :Target[<name>]:[parameters],其中 <name> 就是用于定义监测对象的名称

Basic

The most basic format is ``port:community@router'' This will generate a traffic graph for the interface 'port' of the host 'router' (dns name or IP address) and it will use the community 'community' (snmp password) for the snmp query.

Example:

 

# 注释 :最常见的一种格式就是 : Target[<name>]: <int_index>:<community>'@'<hostname | ip>

 

# 要注意,下面的例子中的 '2' 是 interface index ,所以要监测一个端口的信息前,要先知道该端口所对应的 interface index 是多少

 

# 在 Cisco 的设备上可以用 sh int index 来查看

 

Target[myrouter]: 2:public@wellfleet-fddi.ethz.ch

 

If your community contains a ``@'' or a `` '' these characters must be escaped with a ``\''.]

 

# 注释 :如果 community 中包含有 @ 字符或者空格,应该用 \ 进行转义

 

Target[bla]: 2:stu\ pi\@d@router

 

SNMPv2c

If you have a fast router you might want to try to poll the ifHC* counters. This feature gets activated by switching to SNMPv2c. Unfortunately not all devices support SNMPv2c yet. If it works, this will prevent your counters from wraping within the 5 minute polling interval, since we now use 64 bit instead of the normal 32 bit.

Example:

 

# 注释 :有些情况下需要用到 snmp v2c 的对象,例如 snmp v1 的计数器只有 32 bit 长度,而 snmp v2c 的为 64 bit

 

# 对于一些百兆口或者千兆口,32 bit 是远远不够的。只能用 64 bit 的来表示

 

# 要明确表示该对象是 snmp v2c 的,则在主机名或者ip部分的后面加上 ":::::2" 这个字符串,注意共5个 ':' ,之间没有任何空格

 

Target[myrouter]: 2:public@router1:::::2

 

SNMPv3

 

As an alternative to SNMPv2c, SNMPv3 provides access to the ifHC* counters, along with encryption. Not all devices support SNMPv3, and you will also need the perl Net::SNMP library in order to use it. It is recommended that cfgmaker be used to generate configurations involving SNMPv3, as it will check if the Net::SNMP library is loadable, and will switch to SNMPv2c if v3 is unavailable.

SNMP v3 requires additional authentication parameters, passed using the SnmpOptions[] per-target keyword.

Example: Target[myrouter]: 2:router1:::::3 SnmpOptions[myrouter]: username=>'user1'

 


 Reversing

 

Sometimes you are sitting on the wrong side of the link, and you would like to have mrtg report Incoming traffic as Outgoing and vice versa. This can be achieved by adding the '-' sign in front of the ``Target'' description. It flips the incoming and outgoing traffic rates.

Example:

 

# 注释 :有时候想把输入/输出调反来显示,例如把流入的流量当成流出的流量来显示,可以在 Target 之后的第一 ":" 加上一个 "-" 号,表示相反的意思

 

Target[ezci]: -1:public@ezci-ether.ethz.ch

 


 Explicit OIDs

 

You can also explicitly define which OID to query by using the following syntax 'OID_1&OID_2:community@router' The following example will retrieve error counts for input and output on interface 1. MRTG needs to graph two variables, so you need to specify two OID's such as temperature and humidity or error input and error output.

 

# 注释 :MRTG 不仅可以监测接口,还可以使用 oid 来指定接口之外的其他监测对象

 

# 如果直接使用 oid ,需要同时给出两个 oid ,也就是 "<oid_1>&<oid_2>:<community>@<host | ip> 的格式

 

# 因为 MRTG 需要两个变量的值才能画图,所以你必须给出两个 oid


 

Example:

 

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14.1&1.3.6.1.2.1.2.2.1.20.1:public@myrouter

 


 MIB Variables

 

MRTG knows a number of symbolic SNMP variable names. See the file mibhelp.txt for a list of known names. One example are the ifInErrors and ifOutErrors. This means you can specify the above as:

Example:

 

# 注释 :MRTG 本身也知道一些 symbolic 格式的 snmp 对象。所以可以不用 oid 而直接用对象的名称来表示。

 

# 例如 ifInErrors 和 ifOutErrors

 

Target[myrouter]: ifInErrors.1&ifOutErrors.1:public@myrouter

 


 SnmpWalk

 

It may be that you want to monitor an snmp object that is only reachable by 'walking'. You can get mrtg to walk by prepending the OID with the string WaLK or if you want a particular entry from the table returned by the walk you can use WaLKx where x is a number starting from 0 (!).

Example:

 

# 注释 :如果有些对象是必须使用 snmpwalk 才能访问的,则可以在oid前面加上 "Walk" 的字符串,

 

# 如果要从某个表返回第几个记录,则用 "Walk<n>" 的方式

 

 Target[myrouter]: WaLKstrangeOid.1&WaLKstrangeOid.2:public@myrouter

 Target[myrouter]: WaLK3strangeOid.1&WaLK4strangeOid.2:public@myrouter

 

 Interface by IP

 

Sometimes SNMP interface index can change, like when new interfaces are added or removed. This can cause all Target entries in your config file to become offset, causing MRTG to graphs wrong instances etc. MRTG supports IP address instead of ifindex in target definition. Then MRTG will query snmp device and try to map IP address to the current ifindex. You can use IP addresses in every type of target definition by adding IP address of the numbered interface after OID and separation char '/'.

Make sure that the given IP address is used on your same target router, especially when graphing two different OIDs and/or interface split by '&' delimiter.

 

# 注释 :有时候,接口的 index 会改变,例如增加接口或者删除接口,这时候可以通过 ip 来标识,在内部 MRTG 会尝试将 ip 和 ifIndex 给映射起来。

 

# 要使用 ip ,格式是 :

 

#     -) "Target[<name>]: /<ip>:<community>@<host|ip>"

 

#     -) "Target[<name>]: <oid_1>/<ip_1>&<oid_2>/<ip_2>:<community>@<host|ip>"

 

You can tell cfgmaker to generate such references with the option --ifref=ip.

 

# 注释 :如果是使用 cfgmaker 命令,则为 --ifref=ip

 

Example:

 

Target[myrouter]: /1.2.3.4:public@wellfleet-fddi.ethz.ch

Target[ezci]: -/1.2.3.4:public@ezci-ether.ethz.ch

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14/1.2.3.4&1.3.6.1.2.1.2.2.1.14/1.2.3.4:public@myrouter

Target[myrouter]: ifInErrors/1.2.3.4&ifOutErrors/1.2.3.4:public@myrouter

 


 Interface by Description

 

If you can not use IP addresses you might want to use the interface names. This works similar to the IP address aproach except that the prefix to use is a \ instead of a /

You can tell cfgmaker to generate such references with the option --ifref=descr.

Example:

 

# 注释 :除了 ifIndex、ip之外,还可以用接口的描述信息来引用某个接口,不过和ip方式不同的是,“/” 换成了 “\" 字符

 

# 如果是使用 cfgmaker 命令,则为 --ifref=descr 选项


 

Target[myrouter]: \My-Interface2:public@wellfleet-fddi.ethz.ch

Target[ezci]: -\My-Interface2:public@ezci-ether.ethz.ch

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14\My-Interface2&1.3.6.1.2.1.2.2.1.14\My-Interface3:public@myrouter

Target[myrouter]: ifInErrors\My-Interface2&ifOutErrors\My-Interface3:public@myrouter

 

If your description contains a ``&'', a ``:'', a ``@'' or a `` '' you can include them but you must escape with a backlash:

 

# 注释 :如果接口的注释信息中包含了 ”&" ,":" , "@" ," " ,则应该使用 \ 字符进行转义

 

Target[myrouter]: \fun\:\ ney\&ddd:public@hello.router

 

 Interface by Name

 

This is the only sensible way to reference the interfaces of your switches.

You can tell cfgmaker to generate such references with the option --ifref=name.

 

# 注释 :除了 ifIndex、ip、ifDescr 之外,还可以用接口名称来标识,对于交换机来说,这是唯一有意义的方式,

 

# 因为交换机的端口不存在ip,描述信息和 ifIndex 也比较麻烦,直接用 <module>/<port> 的方式最直接明了

 

# 和 ip、ifDescr 方式不同,用端口名称的方式使用

 

#     -) Target[<name>]: #<module>/<port>:<community>@<host|ip>

 

#     -) Target[<name>]: <oid_1>#<module>/<port>&<oid_2>#<module>/<port>:<community>@<host|ip>


 

Example:

 

Target[myrouter]: #2/11:public@wellfleet-fddi.ethz.ch

Target[ezci]: -#2/11:public@ezci-ether.ethz.ch

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14#3/7&1.3.6.1.2.1.2.2.1.14#3/7:public@myrouter

Target[myrouter]: ifInErrors#3/7&ifOutErrors#3/7:public@myrouter

 

If your description contains a ``&'', a ``:'', a ``@'' or a `` '' you can include them but you must escape with a backlash:

 

# 注释 :如果接口的名称中包含了 ”&" ,":" , "@" ," " ,则应该使用 \ 字符进行转义

 

Target[myrouter]: #\:\ fun:public@hello.router

 

Note that the # sign will be interpreted as a comment character if it is the first non white-space character on the line.

 

# 注释 :要注意,# 同时也可以起到注释的作用,不过必须出现在行首

 


 Interface by Ethernet Address

 

When the SNMP interface index changes, you can key that interface by its 'Physical Address', sometimes called a 'hard address', which is the SNMP variable 'ifPhysAddress'. Internally, MRTG matches the Physical Address from the *.cfg file to its current index, and then uses that index for the rest of the session.

 

# 注释 :除了 ifIndex、ip、ifDescr、ifName 之外,还可以用 MAC 地址来标识一个地址。

 

# 补充 :接口的 MAC 地址可以用 ifPhysAddress 对象来查询

 

You can use the Physical Address in every type of target definition by adding the Physical Address after the OID and the separation char '!' (analogous to the IP address option). The Physical address is specified as '-' delimited octets, such as ``0a-0-f1-5-23-18'' (omit the double quotes). Note that some routers use the same Hardware Ethernet Address for all of their Interfaces which prevents unique interface identification. Mrtg will notice such problems and alert you.

 

# 注释:如果用 mac 地址来标识接口,可以用

 

#     -)Target[<name>]: !<mac>:<community>@<host|ip>

 

#     -)Target[<name>]: <oid_1>!<mac_1>&<oid_2>!<mac_2>:<community>@<host|ip>

 

You can tell cfgmaker to generate configuration files with hardware ethernet address references by using the option --ifref=eth.

 

# 注释 :如果用 cfgmaker 命令,则对应 --ifref=eth 选项

 

Example:

 

Target[myrouter]: !0a-0b-0c-0d:public@wellfleet-fddi.ethz.ch

Target[ezci]: -!0-f-bb-05-71-22:public@ezci-ether.ethz.ch

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14!0a-00-10-23-44-51&!0a-00-10-23-44-51:public@myrouter

Target[myrouter]: ifInErrors!0a-00-10-23-44-51&ifOutErrors!0a-00-10-23-44-51:public@myrouter

 

 Interface by Type

 

It seems that there are devices that try to defy all monitoring efforts: the interesting interfaces have neither ifName nor a constant ifDescr not to mention a persistant ifIndex. The only way to get a constant mapping is by looking at the interface type, because the interface you are interested in is unique in the device you are looking at ...

You can tell cfgmaker to generate such references with the option --ifref=type.

Example:


 

Target[myrouter]: %13:public@wellfleet-fddi.ethz.ch

Target[ezci]: -%13:public@ezci-ether.ethz.ch

Target[myrouter]: 1.3.6.1.2.1.2.2.1.14%13&1.3.6.1.2.1.2.2.1.14%14:public@myrouter

Target[myrouter]: ifInErrors%13&ifOutErrors%14:public@myrouter

 

 Extended Host Name Syntax

 

In all places where ``community@router'' is accepted, you can add additional parameters for the SNMP communication using colon-separated suffixes. You can also append a pipe symbol ( | ) and the name of a numeric conversion subroutine as described under the global keyword ``ConversionCode'' above. The full syntax is as follows:

 

# 注释 :在 Target 语句的 "<community>@<host|ip>" 部分,可以对 host|ip 部分再进一步的设置。

 

community@router[:[port][:[timeout][:[retries][:[backoff][:[version]][|name]]]]]

 

where the meaning of each parameter is as follows:

port

the UDP port under which to contact the SNMP agent (default: 161)

 

# 注释 :<port> 设置 MRTG 连接 Agent 的那个 UDP 端口,默认是 161

timeout

initial timeout for SNMP queries, in seconds (default: 2.0)

 

# 注释 :<timeout> 设置 SNMP 操作第一次的超时时间,默认是2秒

retries

number of times a timed-out request will be retried (default: 5)

 

# 注释 :<retries> 设置超时重试的次数,默认为5次

backoff

factor by which the timeout is multiplied on every retry (default: 1.0).

 

# 注释 :backoff 设置超时时间的因子,也就是说每次重试间隔的时间等于 <timeout>*<backoff>

version

for SNMP version. If you have a fast router you might want to put a '2' here. For authenticated or encrypted SNMP, you can try to put a '3' here. This will make mrtg try to poll the 64 bit counters and thus prevent excessive counter wrapping. Not all routers support this though. SNMP v3 requires additional setup, see SnmpOptions[] for full details.

 

# 注释 :version 表示默认使用什么版本

 

Example:

 

3:public@router1:::::2

 

# 注释 :我们在前面提到如何使用 snmp v2,要在 Target 后加上 ":::::2" ,其中的5个 ":" 就是代表 ":"port":"timeout":"retires":"backoff":"version 的5个 “:”

 

 name

the name of the subroutine that MRTG will call to convert the input and output values to integers. See the complete example under the global keyword ``ConversionCode'' above.

 

# 注释 :<name> 部分就是 MRTG 用于将输入/输出的值转换我也整数的脚本名称

 

# 具体见 “ConversionCode” 语句

 

Example:

 

1.3.6.1.4.1.999.1&1.3.6.1.4.1.999.2:public@mydevice:161::::2|Length2Int

 

This would retrieve values from the OID 1.3.6.1.4.1.999.1 for input and .2 for output on mydevice using UDP port 161 and SNMP version 2, and would execute the user-defined numeric conversion subroutine Length2Int to convert those values to integers.

 

# 注释 :上面的语句表示将 .13.6.1.4.1.999.1 的值作为输入,1.3.6.1.4.1.999.2 的值作为输出,并使用 snmp v2 。

 

# 然后把这两个值通过脚本 Length2Int 转换为整数


 

A value that equals the default value can be omitted. Trailing colons can be omitted, too. The pipe symbol followed by the name parameter, if present, must come at the end. There must be no spaces around the colons or pipe symbol.

 

# 注释 :如果某个值等于默认值,可以省略,只用 ":" 表示, 同时,最后一个 ":" 也可以省略

 

# 如果用到 subroutine ,则必须放在最后

 

# 不管是 ":" 还是 “|” 之间都没有空格

 

Example:

 

 Target[ezci]: 1:public@ezci-ether.ethz.ch:9161::4

 

This would refer to the input/output octet counters for the interface with ifIndex 1 on ezci-ether.ethz.ch, as known by the SNMP agent listening on UDP port 9161. The standard initial timeout (2.0 seconds) is used, but the number of retries is set to four. The backoff value is the default.

 


 Numeric IPv6 addresses

 

If IPv6 is enabled you may also specify a target using its IPv6 address. To avoid ambiguity with the port number, numeric IPv6 addresses must be placed in square brackets.

Example:

 

Target[IPv6test]: 2:public@[2001:760:4::]:6161::4

 

 External Monitoring Scripts

 

If you want to monitor something which does not provide data via snmp you can use some external program to do the data gathering.

The external command must return 4 lines of output:

 

# 注释 :如果要监测的对象并不在 snmp mib 总,则要通过脚本来实现。

 

# 这个外部的脚本必须返回4行输出,分别代表 :

Line 1

current state of the first variable, normally 'incoming bytes count'

 

# 注释 :第一行代表监测对象第一个属性的当前状态,也被 MRTG 作为 “流入的字节数” 看待

Line 2

current state of the second variable, normally 'outgoing bytes count'

 

# 注释 :第二行代表监测对象第二个属性的当前状态,也被 MRTG 作为 “流出的字节数” 看待

Line 3

string (in any human readable format), telling the uptime of the target.

 

# 注释 :第三行是一个字符串,告诉监测对象的 Uptime

Line 4

string, telling the name of the target.

 

# 注释 :第四行也就是字符串,告诉 MRTG 被监测对象的名称

 

# 问题 :外部脚本输出的4行信息中,第1和2行是否应该为数字格式?如果中间存在空行可以吗?

 

Depending on the type of data your script returns you might want to use the 'gauge' or 'absolute' arguments for the Options keyword.

 

# 注释 :同时可以针对脚本返回的数据类型设定 Options 语句中的 "gauge" 或者 "absolute" 参数


 

Example:

 

Target[myrouter]: `/usr/local/bin/df2mrtg /dev/dsk/c0t2d0s0`

 

Note the use of the backticks (`), not apostrophes (') around the command.

If you want to use a backtick in the command name this can be done but you must escape it with a backslash ...

If your script does not have any data to return but does not want mrtg to complain about invalid data, it can return 'UNKNOWN' instead of a number. Note though that only rrdtool is realy equipped to handle unknown data well.

 

# 注释 :如果要使用脚本,则连同脚本名称和参数都必须用 ` ` 括起来

 

# 如果命令中含有 “`” ,应该用 “\" 进行转义

 

# 补充 :如果脚本什么也不返回,又不想 MRTG 报错,可以返回“UNKNOWN” 字符串,不过只有 rrdtool 才能较好地处理未知数据


 


 Multi Target Syntax

 

You can also combine several target definitions in a mathematical expression. Any syntactically correct expression that the Perl interpreter can evaluate to will work. An expression could be used, for example, to aggregate both B channels in an ISDN connection or to calculate the percentage hard disk utilization of a server from the absolute used space and total capacity.

 

# 注释 :还有一种情况就是在 Target 行需要用到数学计算。

 

# 例如计算整个磁盘的空间利用率,而不仅仅是单个分区的利用率。

 

# 可以在 Target 行使用 "+" , "-" , "*" , "/" 来连接数学表达式的两个部分。

 

# 但要注意,数学符号的两边必须有空格,否则会引起混乱,例如 "/" 既可以做为除号,也可以用于标识端口 /<ip>

 

Examples:

 

Target[myrouter]: 2:public@wellfleetA + 1:public@wellfleetA

Target[myrouter]: 1.3.6.1.4.1.999.1&1.3.6.1.4.1.999.2:public@mydevice /

    1.3.6.1.4.1.999.3&1.3.6.1.4.1.999.4:public@mydevice * 100

 

Note that whitespace must surround each target definition in the expression. Target definitions themselves must not contain whitespace, except in interface descriptions and interface names, where each whitespace character is escaped by a backslash.

 


 

MRTG automatically rounds the result of the expression to an integer unless RRDTool logging is in use and the gauge option is in effect for the target. Internally MRTG uses Perl's Math::BigFloat package to calculate the result of the expression with 40 digits of precision. Even in extreme cases, where, for example, you take the difference of two 64-bit integers, the result of the expression should be accurate.

 

# 注释 :MRRTG 对于表达式的值会自动四舍五入,并精确到小数点后40位,除非使用了 RRDTool 日志,或者 Target 的值类型为 Gauge 。

 

# MRTG 在内部使用 Perl 的 Match::BigFloat 软件包来计算表达式的值


SNMP Request Optimization

 

MRTG is designed to economize on its SNMP requests. Where a target definition appears more than once in the configuration file, MRTG requests the data from the device only once per round of data collection and uses the collected data for each instance of a particular target. Recognition of two target definitions as being identical is based on a simple string match rather than any kind of deeper semantic analysis.

 

# 注释 :MRTG 会尽量的节省发送 SNMP 请求的次数。

 

# 例如在 mrtg.cfg 中如果重复出现一个对象,则 MRTG 只会在一个 Interval 内对该对象查询1次,

 

# 而不是对于该对象每次出现都执行一次 snmp 请求。同时该值就应用于配置文件中该对象出现的所有位置

 

# 注释 :MRTG 只是通过简单的字符串比较来发现配置文件中一个对象是否重复出现,并没有其他的手段

 

Example:

 

Target[Targ1]: 1:public@CiscoA

Target[Targ2]: 2:public@CiscoA

Target[Targ3]: 1:public@CiscoA + 2:public@CiscoA

Target[Targ4]: 1:public@CISCOA

 

This results in a total of three SNMP requests. Data for 1:public@CiscoA and 2:public@CiscoA are requested only once each, and used for Targ1, Targ2, and Targ3. Targ4 causes another SNMP request for 1:public@CISCOA, which is not recognized as being identical to 1:public@CiscoA.

 

# 注释 :在上面的例子中,Targ1 和 Targ2 的 "1:public@CiscoA" 相同, Targ2 和 Targ3 的 "2:public@CiscoA" 相同

 

# 所以 MRTG 在取得 Targ1 和 Targ2 的值后,在计算 Targ3 时就不再查询 "1:public@CiscoA" 和 "2:public@CiscoA" 了

 

# 不过 Targ4 的 "1:public@Cisc0A" 和 “1:public@CiscoA" 不同,所以 MRTG 会发送一个 snmp 查询

 


 

MaxBytes

 

The maximum value either of the two variables monitored are allowed to reach. For monitoring router traffic this is normally the bytes per second this interface port can carry.

If a number higher than MaxBytes is returned, it is ignored. Also read the section on AbsMax for further info. The MaxBytes value is also used in calculating the Y range for unscaled graphs (see the section on Unscaled).

 

# 注释 :可以为监测对象的两个属性定义最大值。单位是字节

 

# 如果 snmp 查询返回的值大于 MaxBytes 的值,则被忽略。

 

# MaxBytes 同样用于画图时的 Y 轴。

 

Since most links are rated in bits per second, you need to divide their maximum bandwidth (in bits) by eight (8) in order to get bytes per second. This is very important to make your unscaled graphs display realistic information. T1 = 193000, 56K = 7000, 10 MB Ethernet = 1250000, 100 MB Ethernet = 12500000. The MaxBytes value will be used by mrtg to decide whether it got a valid response from the router.

 

# 注释 :在计算时要注意单位的换算。

 

# 10MB= 10*1000*1000/8=1250000

 

# 100MB= 100*1000*1000/8=12500000

 

# 1GB= 1000*1000*1000/8=125000000

 

If you need two different MaxBytes values for the two monitored variables, you can use MaxBytes1 and MaxBytes2 instead of MaxBytes.

Example:

 

# 注释 :可以对两个属性值定义不同的 MAX 值,分别用 MaxBytes1 和 MaxBytes2 来表示

 

MaxBytes[myrouter]: 1250000

 


 

Title

 

Title for the HTML page which gets generated for the graph.

Example:

 

# 注释 :Title 用于指定生成的 HTML 页面的标题

 

Title[myrouter]: Traffic Analysis for Our Nice Company

 


 

Optional per target keywords

 

# 注释 :下面这些都是每个 Target 可选的选项

 

PageTop

 

Things to add to the top of the generated HTML page. Note that you can have several lines of text as long as the first column is empty.

Note that the continuation lines will all end up on the same line in the html page. If you want linebreaks in the generated html use the '\n' sequence.

 

# 注释 :PageTop 是用于在生成的 HTML 页面的顶部添加一些信息。

 

# 不像 Title ,PageTop 可以多行,只要后续的行以空白开头就可以了,就像 sendmail 的一样, MRTG 会把它当成是上一行的继续。

 

# 如果要输出换行,可以使用 "\n" 表示

        

Example:

 

PageTop[myrouter]: <H1>Traffic Analysis for ETZ C95.1</H1>

  Our Campus Backbone runs over an FDDI line \n

  with a maximum transfer rate of 12.5 megabytes per

  Second.


 


 

RouterUptime

 

In cases where you calculate the used bandwidth from several interfaces you normaly don't get the router uptime and router name displayed on the web page.

If these interfaces are on the same router and the uptime and name should be displayed you have to specify its community and address again with the RouterUptime keyword.

 

# 注释 :如果在 Target 使用了表达式,MRTG 不会显示该 Target 的 Uptime 和 Name

 

# 如果 Target 中的接口都是在同一个 Agent 上的,可以用  RouterUptime 来告诉 MRTG

 

# 用给定的 community 查询那个设备就可以得到真正的 Uptime 和 Name


 

Example:

 

Target[kacisco.comp.edu]: 1:public@194.64.66.250 + 2:public@194.64.66.250

RouterUptime[kacisco.comp.edu]: public@194.64.66.250

 

 

 RouterName

 

If the default name of the router is incorrect/uninformative, you can use RouterName to specify a different OID on either the same or a different host.

A practical example: sysName on BayTech DS72 units always display ``ds72'', no matter what you set the Unit ID to be. Instead, the Unit ID is stored at 1.3.6.1.4.1.4779.1.1.3.0, so we can have MRTG display this instead of sysName.

Example:

RouterName[kacisco.comp.edu]: 1.3.6.1.4.1.4779.1.1.3.0

 

A different OID on a different host can also be specified:

 

RouterName[kacisco.comp.edu]: 1.3.6.1.4.1.4779.1.1.3.0:public@194.64.66.251

 

 

 MaxBytes1

Same as MaxBytes, for variable 1.

 

MaxBytes2

Same as MaxBytes, for variable 2.

 


 

IPv4Only

Many IPv6 routers do not currently support SNMP over IPv6 and must be monitored using IPv4. The IPv4Only option forces mrtg to use IPv4 when communicating with the target, even if IPv6 is enabled. This is useful if the target is a hostname with both IPv4 and IPv6 addresses; without the IPv4Only keyword, monitoring such a router will not work if IPv6 is enabled.

 

If set to no (the default), mrtg will use IPv6 unless the target has no IPv6 addresses, in which case it will use IPv4. If set to yes, mrtg will only use IPv4.

Note that if this option is set to yes and the target does not have an IPv4 address, communication with the target will fail.

This option has no effect if IPv6 is not enabled.

Example:

 

Target[v4onlyrouter_1]: 1:public@v4onlyrouter

IPv4Only[v4onlyrouter_1]: Yes

 


 

SnmpOptions (V3)

SNMPv3 requires a fairly rich set of options. This per-target keyword allows access to the User Security Model of SNMPv3. Options are listed in the same syntax as a perl hash.

Security Modes

SNMPv3 has three security modes, defined on the device being polled. For example, on Cisco routers the security mode is defined by the snmp-server group global configuration command.

NoAuthNoPriv

Neither Authentication nor Privacy is defined. Only the Username option is specified for this mode.

Example:

SnmpOptions[myrouter]: username=>'user1'

AuthNoPriv

Uses a Username and a password. The password can be hashed using the snmpkey application, or passed in plain text along with the ContextEngineID

Example:

SnmpOptions[myrouter]: username=>'user1',authpassword=>'example',

  contextengineid=>'80000001110000004000000'

Priv

Both Authentication and Privacy is defined. The default privacy protocol is des.

Example: SnmpOptions[myrouter]: authkey=>'0x1e93ab5a396e2af234c8920e61cfe2028072c0e2', authprotocol=>'sha',privprotocol=>'des',username=>'user1', privkey=>'0x498d74940c5872ed387201d74b9b25e2'

snmp options

The following option keywords are recognized:

username

The user associated with the User Security Model

contextname

An SNMP agent can define multiple contexts. This keyword allows them to be polled.

contextengineid

A unique 24-byte string identifying the snmp-agent.

authpassword

The plaintext password for a user in either AuthNoPriv or Priv mode.

authkey

A md5 or sha hash of the plain-text password, along with the engineid. Use the snmpkey commandline program to generate this hash, or use Net::SNMP::Security::USM in a script.

authprotocol {sha|md5}

The hashing algorithm defined on the SNMP client. Defaults to md5.

privpassword

A plaintext pre-shared key for encrypting snmp packets in Priv mode.

privkey

A hash of the plain-text pre-shared key, along with the engineid. Use the snmpkey commandline program to generate this hash, or use Net::SNMP::Security::USM in a script.

privprotocol {des|3desede|aescfb128|aescfb192|aescfb256}

Specifies the encryption method defined on the snmp agent. The default is des.

 



MRTG 系列 :参数设定(上篇)

{ Posted on 星期六, 十二月 11, 2010 by Kaiser.XKw }
MRTG 系列 :参数设定(上篇)

mrtg-reference

 

Overview

 

The runtime behaviour of MRTG is governed by a configuration file. Run-of- ther-mill configuration files can be generated with cfgmaker. (Check the cfgmaker manpage). But for more elaborate configurations some hand-tuning is required.

This document describes all the configuration options understood by the mrtg software.

 

# 注释 :该文档描述了 MRTG 所知道的所有配置文件的选项

 


 

Syntax

 

MRTG configuration file syntax follows some simple rules:

 

# 注释 :MRTG 配置文件的语法有如下几个规则 :

 

#     -)第一是所有的 keyword 必须从行首开始

 

#     -)如果一个行以空白(空格或者tab)开始,而上一行不是空白行,则被追加到上一行的行尾。这点和 sendmail.cf 的一样

 

#     -)空行被忽略

 

#     -)以 # 开头的行被认为是注释

 

#     -)可以在配置文件中插入其他文件,就是使用 Include:指令

  • Keywords must start at the beginning of a line.
  • Lines which follow a keyword line which start with a blank are appended to the keyword line
  • Empty Lines are ignored
  • Lines starting with a # sign are comments.
  • You can add other files into the configuration file using

Include: <file>

 

Example:

Include: base-options.inc

 

If included files are specified with relative paths, both the current working directory and the directory containing the main config file will be searched for the files.

 

# 注释 :如果 Include:给出的文件是相对路径的,则当前工作目录和存放主要配置文件的目录都会被搜索

 


 

Global keywords

 

#  注释 :下面介绍全局性的关键字

 

WorkDir

 

WorkDir specifies where the logfiles and the webpages should be created.

Example:

 

WorkDir: /usr/tardis/pub/www/stats/mrtg

 

# 注释 :首先是 WorkDir:选项 ,这是必须的一个选项,表示 MRTG 的日志文件和 HTML 页面放在那里


 

Optional global keywords

 

# 注释 :下面这些是可选的全局选项

 

HtmlDir

 

HtmlDir specifies the directory where the html (or shtml, but we'll get on to those later) lives.

NOTE: Workdir overrides the settings for htmldir, imagedir and logdir.

 

Example:

 

Htmldir: /www/mrtg/

 

# 注释 :Hmtldir  表示 HTML 文件放在那里。

 

# 注意,WorkDir 将覆盖 Htmldir 、Imagedir、Logdir  这三个选项。

 

# 所以如果要指定其中一个,就需要三个单独定义

 


ImageDir

 

ImageDir specifies the directory where the images live. They should be under the html directory.

Example:

 

Imagedir: /www/mrtg/images

 

# 注释 :Imagedir 表示那里存放生成的图片。不过要注意,该目录必须是 HtmlDir 所指定的目录下的一个子目录

 


LogDir

 

LogDir specifies the directory where the logs are stored. This need not be under htmldir directive.

Example:

 

Logdir: /www/mrtg/logs

 

# 注释 :Logdir 选项指定日志存放的目录,同样也必须是 Htmdir 所指定的目录的一个子目录

 


Forks (UNIX only)

 

With system that supports fork (UNIX for example), mrtg can fork itself into multiple instances while it is acquiring data via snmp.

For situations with high latency or a great number of devices this will speed things up considerably. It will not make things faster, though, if you query a single switch sitting next door.

As far as I know NT can not fork so this option is not available on NT.

Example:

 

# 注释 :Forks 选项是 UNIX 才有的。MRTG 可以在通过 SNMP 获取数据的同时 fork 出多个实例。

 

# 对于网络延迟较大或者需要轮询的设备数量众多的情况,该选项可以一定程度的减少所需要的时间

 

# forks:后面加上要 fork 的实例的数目

 

 

Forks: 4

 

EnableIPv6

 

When set to yes, IPv6 support is enabled if the required libraries are present (see the the mrtg-ipv6 manpage manpage). When IPv6 is enabled, mrtg can talk to routers using SNMP over IPv6 and targets may be specified by their numeric IPv6 addresses as well as by hostname or IPv4 address.

If IPv6 is enabled and the target is a hostname, mrtg will try to resolve the hostname to an IPv6 address and, if this fails, to an IPv4 address. Note that mrtg will only use IPv4 if you specify an IPv4 address or a hostname with no corresponding IPv6 address; it will not fall back to IPv4 if it simply fails to communicate with the target using IPv6. This is by design.

Note that many routers do not currently support SNMP over IPv6. Use the IPv4Only per target option for these routers.

IPv6 is disabled by default.

Example:

 

EnableIPv6: Yes

 


 

EnableSnmpV3

When set to yes, uses the Net::SNMP module instead of the SNMP_SESSION module for generating snmp queries. This allows the use of SNMPv3 if other snmpv3 parameters are set.

SNMPv3 is disabled by default.

Example:

 

EnableSnmpV3: yes

 

 Refresh

 

How many seconds apart should the browser (Netscape) be instructed to reload the page? If this is not defined, the default is 300 seconds (5 minutes).

Example:

 

# 注释 :Refresh 选项设置 MRTG 多长时间 reload 页面。也就是更新图表和日志。

 

# 默认是会议300秒,也就是5分钟

 

Refresh: 600

 

 


Interval

 

How often do you call mrtg? The default is 5 minutes. If you call it less often, you should specify it here. This does two things:

  • The generated HTML page contains the right information about the calling interval ...
  • A META header in the generated HTML page will instruct caches about the time-to-live of this page .....

# 注释: Interval 设置多长时间调用一次 MRTG 。默认也是5分钟,和 Refresh 一致。 这样可以做到及时更新。

 

# 该选项将会做两件事 :

 

#    -)生成的 HTML 页面将包括 Interval 的设置

 

#     -)HTML 页面中的 META header 将会告诉 cache 多长时间更新一次

 

In this example, we tell mrtg that we will be calling it every 10 minutes. If you are calling mrtg every 5 minutes, you can leave this line commented out.

Example:

 

Interval: 10

 

Note that unless you are using rrdtool you can not set Interval to less than 5 minutes. If you are using rrdtool you can set interval down to 1 minute. Note though, setting the Interval for an rrdtool/mrtg setup will influence the initial creation of the database. If you change the interval later, all existing databases will remain at the resolution they were initially created with.

 

# 注释 :注意,除非是使用 rrdtool ,否则 Interval 不能小于5分钟

 

# 如果使用 rrdtool ,可以调整为 1分钟

 

# 在安装 rrdtool/mrtg 时指定 Interval 会影响到数据库一开始的建立。

 

# 假如在后期改变了 Interval ,则原先的数据库仍然被保留


 


 

MaxAge

MRTG relies heavily on the real time clock of your computer. If the time is set to a wrong value, especially if it is advanced far into the future, this will cause mrtg to expire lots of supposedly old data from the log files.

To prevent this, you can add a 'reasonability' check by specifying a maximum age for log files. If a file seems to be older, mrtg will not touch it but complain instead, giving you a chance to investigate the cause.

Example:

 

# 问题 :MaxAge 选项的作用是什么?

 

MaxAge: 7200

 

The example above will make mrtg refuse to update log files older than 2 hours (7200 seconds).

 


 

WriteExpires

 

With this switch mrtg will generate .meta files for CERN and Apache servers which contain Expiration tags for the html and gif files. The *.meta files will be created in the same directory as the other files, so you will have to set ``MetaDir .'' and ``MetaFiles on'' in your apache.conf or .htaccess file for this to work

NOTE: If you are running Apache-1.2 or later, you can use the mod_expire to achieve the same effect ... see the file htaccess.txt

Example:

 

WriteExpires: Yes

 

NoMib2

 

Normally we ask the SNMP device for 'sysUptime' and 'sysName' properties. Some do not have these. If you want to avoid getting complaints from mrtg about these missing properties, specify the nomib2 option.

An example of agents which do not implement base mib2 attributes are Computer Associates - Unicenter TNG Agents. CA relies on using the base OS SNMP agent in addition to its own agents to supplement the management of a system.

Example:

 

# 注释 :有些设备并不具备 sysUptime 或者 sysName 这些特性。为了防止 MRTG 报错,可以使用 NoMibs2 选项。

 

NoMib2: Yes

 

SingleRequest

 

Some SNMP implementations can not deal with requests asking for multiple snmp variables in one go. Set this in your cfg file to force mrtg to only ask for one variable per request.

Examples :

 

# 注释 :有些 SNMP 的实现不能一次性查询多个 SNMP 对象。所以用 SingleRequest 选项来强迫 MRTG 每个请求只查询一个对象

 

SingleRequest: Yes

 

SnmpOptions

Apart from the per target timeout options, you can also configure the behaviour of the snmpget process on a more profound level. SnmpOptions accepts a hash of options. The following options are currently supported:

 

timeout                   => $default_timeout,

retries                   => $default_retries,

backoff                   => $default_backoff,

default_max_repetitions   => $max_repetitions,

use_16bit_request_ids     => 1,

lenient_source_port_matching => 0,

lenient_source_address_matching => 1

 

The values behind the options indicate the current default value. Note that these settings OVERRIDE the per target timeout settings.

A per-target SnmpOptions[] keyword will override the global settings. That keyword is primarily for SNMPv3.

The 16bit request ids are the only way to query the broken SNMP implementation of SMC Barricade routers.

Example:

 

SnmpOptions: retries => 2, only_ip_address_matching => 0

 

Note that AS/400 snmp seems to be broken in a way which prevents mrtg from working with it unless

 

SnmpOptions: lenient_source_port_matching => 1

 

is set.

 


 

IconDir

If you want to keep the mrtg icons in someplace other than the working (or imagedir) directory, use the IconDir variable for defining the url of the icons directory.

Example:

 

# 注释 :IconDir 选项设置 MRTG 所使用的图标的目录

 

# 默认是在 WorkDir 或者 Imagedir

 

IconDir: /mrtgicons/

 

LoadMIBs

 

Load the MIB file(s) specified and make its OIDs available as symbolic names. For better efficiancy, a cache of MIBs is maintained in the WorkDir.

 

Example:

 

# 注释 :LoadMIBs 表示加载那些 MIB 。MRTG 会同时把这些 mib 拷贝一份放在 WorkDir 目录下

 

LoadMIBs: /dept/net/mibs/netapp.mib,/usr/local/lib/ft100m.mib

 


Language

Switch output format to the selected Language (Check the translate directory to see which languages are supported at the moment. In this directory you can also find instructions on how to create new translations).

 

Currently the following laguages are supported:

 

big5 brazilian bulgarian catalan chinese croatian czech danish dutch eucjp french galician gb gb2312 german greek hungarian icelandic indonesia iso2022jp italian korean lithuanian malay norwegian polish portuguese romanian russian russian1251 serbian slovak slovenian spanish swedish turkish ukrainian

 

Example:

 

# 注释 :Language 设置 HTML 页面的语言。

 

# 要看当前支持那些语言,可以查看 translate 目录

 

# 当前支持的语言如上,中文就是 chinese ,gb,gb2312 ,繁体中文是 big5


 

Language: danish

 

LogFormat

Setting LogFormat to 'rrdtool' in your mrtg.cfg file enables rrdtool mode. In rrdtool mode, mrtg relies on rrdtool to do its logging. See the mrtg-rrd manpage.

Example:

 

# 注释 :如果 LogFormat 为 rrdtool ,则 mrtg.cfg 允许 rrdtool 模式的日志,不过要依赖于 rrdtool 来生成日志

 

LogFormat: rrdtool

 

LibAdd

If you are using rrdtool mode and your rrdtool Perl module (RRDs.pm) is not installed in a location where perl can find it on its own, you can use LibAdd to supply an appropriate path.

Example:

 

LibAdd: /usr/local/rrdtool/lib/perl/

 

 

PathAdd

If the rrdtool executable can not be found in the normal PATH, you can use this keyword to add a suitable directory to your path.

Example:

PathAdd: /usr/local/rrdtool/bin/

 

 

RunAsDaemon

 

The RunAsDaemon keyword enables daemon mode operation. The purpose of daemon mode is that MRTG is launched once and not repeatedly (as it is with cron). This behavior saves computing resourses as loading and parsing of configuration files happens only once.

 

# 注释 :RunAsDaemon 关键字允许 MRTG 以守护进程的模式运行。要注意同 cron 运行的方式区别开来。

 

# 以守护进程模式运行有一个好处就是不用频繁地启动 mrtg 程序,不用重复的读取配置文件,可以节省资源

 

Using daemon mode MRTG itself is responible for timing the measurement intervals. Therfore its important to set the Interval keyword to an apropiate value.

 

# 注释 :由于不是由 crond 控制多长时间调用 mrtg 程序一次,所以 daemon 模式下的 mrtg 就必须设置好 Interval 这个参数

 

# 由 mrtg 程序自己负责计时工作


 

Note that when using daemon mode MRTG should no longer be started from cron as each new process runs forever. Instead MRTG should be started from the command prompt or by a system startup script.

 

# 注释 :要注意一点,一旦使用了 daemon 模式,mrtg 就不应该以 cron 的方式来启动。

 

# 应该从命令行启动(并进入 daeon 模式),或者通过 /etc/rc.d/init.d/ 下类似的方式来启动

 

If you want mrtg to run under a particular user and group (it is not recomended to run MRTG as root) then you can use the --user=user_name and --group=group_name options on the mrtg commandline.

 

# 注释 :假如你想要 mrtg 以某个特定的身份来运行(不推荐以 root 身份来运行 mrtg),则需要用到 --user= 和 --group= 两个命令行的选项


 

mrtg --user=mrtg_user --group=mrtg_group mrtg.cfg

 

Also note that in daemon mode restarting the process is required in order to activate changes in the config file.

 

# 注释 :由于处于 daemon 模式,mrtg 并不会自动定时 reload 配置文件,需要手工重启进程

 

Under UNIX, the Daemon switch causes mrtg to fork into background after checking its config file. On Windows NT the MRTG process will detach from the console, but because the NT/2000 shell waits for its children you have to use this special start sequence when you launch the program:

 

# 注释 :在 unix 下,RunAsDaemon 会促使 mrtg 在读取配置文件后自动进入后台,

 

# 但在  windows NT/2000 下,需要执行 "start /b mrtg mrtg.cf" 命令,才能进入后台,否则会一直处于 cmd 命令窗口下

 

start /b perl mrtg mrtg.cfg

 

You may have to add path information equal to what you add when you run mrtg from the commandline.

Example

 

RunAsDaemon: Yes

Interval:    5

 

This makes MRTG run as a daemon beginning data collection every 5 minutes

 

# 注释 :上面的配置将使 MRTG 运行在 daemon 模式,每隔5分钟就收集一次数据。

 

# 所以 MRTG 不会自动去收集数据的,而是通过 Interval 来“强迫” MRTG 去收集数据

 

# 这和 refresh 是不同的,refresh 是多长时间刷新页面,如果 interval > refresh ,则图表的更新比较及时

 

# 如果 interval < refresh ,则图表的更新较数据的收集慢,最好是两者差不多

 

If you are daemontools and still want to run mrtg as a daemon you can additionally specify

 

NoDetach:     Yes

 

this will make mrtg run but without detaching it from the terminal.