add code blocks

This commit is contained in:
MulliganSecurity 2025-06-06 17:18:06 +02:00
parent a70be9f6e9
commit 2490348b65

View file

@ -27,16 +27,20 @@ Simple threshold-based alert are reactive by nature, but their automated monitor
- Threshold-based: a [SMARTCTL](https://en.wikipedia.org/wiki/Smartctl) alert creating a notification when any hard drive within your infrastructure crosses a pre-failure threshold
~~~
smartctl_device_attribute{attribute_flags_long=\~".*prefailure.*", attribute_value_type="value"}
<=
on (device, attribute_id, instance, attribute_name)
smartctl_device_attribute{attribute_flags_long=\~".*prefailure.*", attribute_value_type="thresh"}
~~~
- Statistical (anomaly detection): CPU spike or under-use
~~~
cpu_percentage_use > (avg_over_time(cpu_percentage_use[5m]) + (3* stddev_over_time(cpu_percentage_use[5m])))
OR
cpu_percentage_use < (avg_over_time(cpu_percentage_use[5m]) - (3* stddev_over_time(cpu_percentage_use[5m])))
~~~
## Associated Risks