Network Management

 View Only
Expand all | Collapse all

iMC 7.3 - Escalate to alarm doesn't work

This thread has been viewed 0 times
  • 1.  iMC 7.3 - Escalate to alarm doesn't work

    Posted Jul 31, 2017 10:48 AM

    Hi All,

    I'm making an iMC 7.3 Standard Edition into a network, and want to make working "Escalate to alarm" working with syslog events.

    My goal is :

    make an alarm immediatly when a link is DOWN and show it in "real time alarms" in the dashboard. Nothing complicated but... it doesn't work.

    My configuration :

    ----------------------------

    Syslog event received : "

    <187>Jul 31 15:42:30 2017 NET_COE_001 %%10IFNET/3/PHY_UPDOWN: -DevIP=10.1.100.1; Physical state on the interface Bridge-Aggregation100 changed to down."

    ----------------------------------------

    My "Syslog to alarm" event :

    Status : enabled

    Custom view : my network view (contains all switches)

    Syslog type : any

    Syslog level : all checked

    Statistic : Single Device

    Repeat interval : 1

    Repeat times : 1

    Alarm level  : Major

    Alarm description : %Syslog%

    Syslog template : *changed to down*

    Param settings : NOTHING (because no variables for now)

    Alarm recovery rule : unchecked (for now)

    -------------------------------------

    SYSLOG TEMPLATE :

    Name : lienDown

    Template content : "use regular expression" unchecked

    textbox contains *changed to down*

    Description display template : Disabled

    Description : line down

    ------------------------

    In System > System Settings I let "No Filter" in all "interface up/down alarm.

    -----------------------

    I have Syslog Management service deplayed and running.

    Thx in advance all !

    Sylvain.

     

     



  • 2.  RE: iMC 7.3 - Escalate to alarm doesn't work

    Posted Sep 13, 2017 12:13 PM

    Hello Sylvain,

    I remember to possible issues:

    #1 since IMC 7.3 E0506 you have to enable several trap to alarm rulse. Go to Alarm -> Trap Management -> Trap to Alarm an verify if "iMC Syslog" rule is enabled. 

    #2 Check if iMC Syslog traps a listed in the "unfiltered Duplicate Traps" list: go to Alarm -> Trap Management -> Filtering Trap -> Duplicate Trap Filter, click on "Select" and put the trap "Trap upgraded from syslog" in the unfiltered duplicate trap list.

    Best Regards,
    Michael