Skip to content

Check rpm-updates

Overview

Checks for available RPM package updates on RHEL, CentOS, Fedora, and compatible systems. Reports the number and type of available advisories (bugfix, enhancement, security). Alerts when the number of pending updates reaches the warning threshold, and when the number of security updates reaches the critical threshold. This check only lists updates and never actually installs anything.

Important Notes:

  • The --query parameter accepts an SQL WHERE clause to filter the list of available updates. The following database columns can be used:
    • arch (TEXT)
    • package (TEXT)
    • repo_installed (TEXT)
    • repo_upgrade (TEXT)
    • version_installed (TEXT)
    • version_upgrade (TEXT)
  • The "State" column says whether a package is overdue or still counting down (due in 1W 23h), and marks the ones a WARNING or CRITICAL hangs on, so an alert can be traced back to the packages responsible for it
  • The "Type" column in the output lists the type of update for each intermediate version. Abbreviation meanings:
    • B: Bugfix
    • E: Enhancement
    • S: Security
    • U: Unspecified
    • no character: unknown

Data Collection:

  • Executes yum list --upgrades, yum list --installed, and yum updateinfo list --available
  • Stores all package and advisory information in a local SQLite database that lives only for the duration of the run, for SQL-based filtering via --query
  • Counts an update as security-critical when it carries a security advisory (S in the "Type" column). Optionally narrows the report down to those updates (--only-critical); the security count is reported either way
  • Records when an update for a package first showed up, so --grace-updates and --grace-security can hold the alert back until the host has had a patch window. An update inside its grace period is still listed and still counted in the performance data, it just does not drive the check state yet. The clock keys on the package name, so a newer candidate version does not restart it, and it starts over if the package drops off the list and comes back. A security update is governed by --grace-security alone, which by default is 0D, so security never waits. Both are 0D out of the box; the shipped Icinga Director service template sets --grace-updates=8D to cover a weekly patch window
  • Plugin execution may take more than 10 seconds due to yum operations (default timeout: 120 seconds)

Fact Sheet

Fact Value
Check Plugin Download https://github.com/Linuxfabrik/monitoring-plugins/tree/main/check-plugins/rpm-updates
Nagios/Icinga Check Name check_rpm_updates
Check Interval Recommendation Every day
Can be called without parameters Yes
Runs on Linux
Compiled for Windows No
Uses State File $TEMP/linuxfabrik-monitoring-plugins-rpm-updates.db

Help

usage: rpm-updates [-h] [-V] [--always-ok] [-c CRIT]
                   [--grace-security GRACE_SECURITY]
                   [--grace-updates GRACE_UPDATES] [--no-perfdata]
                   [--only-critical] [--query QUERY] [--timeout TIMEOUT]
                   [-w WARN]

Checks for available RPM package updates on RHEL, CentOS, Fedora, and
compatible systems. Reports the number and type of available advisories
(bugfix, enhancement, security). Alerts when the number of pending updates
reaches the warning threshold, and when the number of security updates reaches
the critical threshold. This check only lists updates and never actually
installs anything.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit
  --always-ok           Always returns OK.
  -c, --critical CRIT   Minimum number of pending security updates to trigger
                        a CRITICAL. Counts the updates carrying a security
                        advisory, within the scope of `--query`. Unset by
                        default, so security updates raise a WARNING like any
                        other update until a threshold is given. Example:
                        `--critical=1` Default: None
  --grace-security GRACE_SECURITY
                        How long a pending security update is tolerated before
                        it counts towards the thresholds. Starts when the
                        update is first seen, and starts over if the package
                        drops off the list and comes back. A duration such as
                        `12h`, `8D` or `2W`; `0D` disables the grace period.
                        Default: 0D
  --grace-updates GRACE_UPDATES
                        How long a pending update is tolerated before it
                        counts towards the thresholds. Set this to cover the
                        interval between two patch windows, so a host stays
                        quiet about updates it has had no chance to install
                        yet. Starts when the update is first seen, and starts
                        over if the package drops off the list and comes back.
                        A duration such as `12h`, `8D` or `2W`; `0D` disables
                        the grace period. Default: 0D
  --no-perfdata         Suppress the performance data section from the output.
                        The status message and the exit code are unaffected,
                        so alerting keeps working while trending data is
                        dropped.
  --only-critical       Only report security updates and upgrades.
  --query QUERY         SQL WHERE clause to filter the list of available
                        updates. Supports regular expressions via a REGEXP
                        statement. See the README for a list of available
                        columns. If specified, a list of matching updates is
                        printed. Example: `--query='package like "bind9-%"'`.
                        Default: 1
  --timeout TIMEOUT     Network timeout in seconds. Default: 120 (seconds)
  -w, --warning WARN    Minimum number of pending updates to trigger a
                        WARNING. Default: 1

Documentation:
https://linuxfabrik.github.io/monitoring-plugins/check-plugins/rpm-updates/

Usage Examples

./rpm-updates --only-critical --query='package in ("audit", "bind-utils", "gcc-c++")'

Output:

30 updates available. [WARNING]

Package    ! Installed          ! Upgrade to           ! Type ! State
-----------+--------------------+----------------------+------+------------------
audit      ! 3.0.7-5.el8        ! 3.1.2-1.el8          ! B    ! overdue [WARNING]
bind-utils ! 32:9.11.36-11.el8  ! 32:9.11.36-16.el8_10 !      ! overdue [WARNING]
gcc-c++    ! 8.5.0-20.el8       ! 8.5.0-26.el8_10      ! BSB  ! overdue [WARNING]

Wake somebody up as soon as an update carrying a security advisory is pending:

./rpm-updates --critical=1

Output:

2 updates available, 2 of them critical. [CRITICAL]

Package     ! Installed        ! Upgrade to       ! Type ! State
------------+------------------+------------------+------+-------------------
vim-data    ! 2:9.2.240-1.fc42 ! 2:9.2.280-1.fc42 ! S    ! overdue [CRITICAL]
vim-minimal ! 2:9.2.240-1.fc42 ! 2:9.2.280-1.fc42 ! S    ! overdue [CRITICAL]

Hold ordinary updates back until the host has had its weekly patch window, while security updates keep alerting right away. The "State" column says which packages the alert hangs on, and when the rest follow:

./rpm-updates --grace-updates=8D

Output:

5 updates available, 2 of them critical. 3 of them within the grace period (updates: 8D, security: 0D). [WARNING]

Package       ! Installed         ! Upgrade to        ! Type ! State
--------------+-------------------+-------------------+------+------------------
glib2         ! 2.56.4-170.el8_10 ! 2.56.4-177.el8_10 ! S    ! overdue [WARNING]
libssh        ! 0.9.6-16.el8_10   ! 0.9.6-17.el8_10   !      ! due in 1W 18h
libssh-config ! 0.9.6-16.el8_10   ! 0.9.6-17.el8_10   !      ! due in 1W 18h
libxml2       ! 2.9.7-21.el8_10.6 ! 2.9.7-21.el8_10.7 ! S    ! overdue [WARNING]
wget          ! 1.19.5-12.el8_10  ! 1.19.5-16.el8_10  !      ! due in 1W 18h

States

  • OK if no updates are available (or both counts stay below their thresholds).
  • WARN if the number of pending updates is >= --warning (default: 1).
  • CRIT if the number of security updates is >= --critical. Unset by default, so security updates raise a WARNING like any other update until a threshold is given.
  • UNKNOWN if one of the yum calls fails.
  • --always-ok suppresses all alerts and always returns OK.

Perfdata / Metrics

Name Type Description
critical_updates Number Number of updates carrying a security advisory, matching the current --query.
updates Number Number of updatable packages matching the current --query. With --only-critical this is the security count.

Credits, License