2026-09-17 18:48:25 +00:00
|
|
|
resource "aws_cloudwatch_metric_alarm" "no_incoming_records" {
|
|
|
|
|
alarm_name = "Syslog-NoIncomingRecords"
|
|
|
|
|
alarm_description = "No Firehose IncomingRecords for 2 days. UniFi pipeline may be down."
|
2026-09-16 21:29:43 +00:00
|
|
|
comparison_operator = "LessThanThreshold"
|
|
|
|
|
evaluation_periods = 2
|
2026-09-17 18:48:25 +00:00
|
|
|
metric_name = "IncomingRecords"
|
|
|
|
|
namespace = "AWS/Firehose"
|
2026-09-16 21:29:43 +00:00
|
|
|
period = 86400
|
|
|
|
|
statistic = "Sum"
|
|
|
|
|
threshold = 1
|
|
|
|
|
treat_missing_data = var.no_logs_treat_missing_data
|
|
|
|
|
alarm_actions = [local.site_alerts_arn]
|
|
|
|
|
|
|
|
|
|
dimensions = {
|
2026-09-17 18:48:25 +00:00
|
|
|
DeliveryStreamName = aws_kinesis_firehose_delivery_stream.unifi.name
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "aws_cloudwatch_metric_alarm" "firehose_delivery" {
|
|
|
|
|
alarm_name = "Syslog-FirehoseDeliveryFailed"
|
|
|
|
|
alarm_description = "Firehose DeliveryToS3.Success average below 1 for 10 min. S3 PUTs are failing."
|
|
|
|
|
comparison_operator = "LessThanThreshold"
|
|
|
|
|
evaluation_periods = 2
|
|
|
|
|
metric_name = "DeliveryToS3.Success"
|
|
|
|
|
namespace = "AWS/Firehose"
|
|
|
|
|
period = 300
|
|
|
|
|
statistic = "Average"
|
|
|
|
|
threshold = 1
|
|
|
|
|
treat_missing_data = "notBreaching"
|
|
|
|
|
alarm_actions = [local.site_alerts_arn]
|
|
|
|
|
|
|
|
|
|
dimensions = {
|
|
|
|
|
DeliveryStreamName = aws_kinesis_firehose_delivery_stream.unifi.name
|
2026-09-16 21:29:43 +00:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "aws_cloudwatch_metric_alarm" "status_check" {
|
|
|
|
|
alarm_name = "EC2-StatusCheck-syslog-server"
|
2026-09-17 18:48:25 +00:00
|
|
|
alarm_description = "syslog-server EC2 status check failed (instance and/or system) for 10 min. Host may be hung or unreachable."
|
2026-09-16 21:29:43 +00:00
|
|
|
comparison_operator = "GreaterThanOrEqualToThreshold"
|
|
|
|
|
evaluation_periods = 2
|
|
|
|
|
metric_name = "StatusCheckFailed"
|
|
|
|
|
namespace = "AWS/EC2"
|
|
|
|
|
period = 300
|
|
|
|
|
statistic = "Maximum"
|
|
|
|
|
threshold = 1
|
|
|
|
|
treat_missing_data = "breaching"
|
|
|
|
|
alarm_actions = [local.site_alerts_arn]
|
|
|
|
|
|
|
|
|
|
dimensions = {
|
|
|
|
|
InstanceId = aws_instance.this.id
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "aws_cloudwatch_metric_alarm" "system_recover" {
|
|
|
|
|
alarm_name = "EC2-StatusCheckSystem-syslog-server-recover"
|
2026-09-17 18:48:25 +00:00
|
|
|
alarm_description = "syslog-server EC2 system status check failed. Underlying host impaired; auto-recovering onto new hardware."
|
2026-09-16 21:29:43 +00:00
|
|
|
comparison_operator = "GreaterThanOrEqualToThreshold"
|
|
|
|
|
evaluation_periods = 2
|
|
|
|
|
metric_name = "StatusCheckFailed_System"
|
|
|
|
|
namespace = "AWS/EC2"
|
|
|
|
|
period = 300
|
|
|
|
|
statistic = "Maximum"
|
|
|
|
|
threshold = 1
|
|
|
|
|
treat_missing_data = "notBreaching"
|
|
|
|
|
alarm_actions = [
|
|
|
|
|
local.site_alerts_arn,
|
|
|
|
|
"arn:aws:automate:${var.aws_region}:ec2:recover",
|
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
dimensions = {
|
|
|
|
|
InstanceId = aws_instance.this.id
|
|
|
|
|
}
|
|
|
|
|
}
|