Hi All,
I'm making an iMC 7.3 Standard Edition into a network, and want to make working "Escalate to alarm" working with syslog events.
My goal is :
make an alarm immediatly when a link is DOWN and show it in "real time alarms" in the dashboard. Nothing complicated but... it doesn't work.
My configuration :
----------------------------
Syslog event received : "
<187>Jul 31 15:42:30 2017 NET_COE_001 %%10IFNET/3/PHY_UPDOWN: -DevIP=10.1.100.1; Physical state on the interface Bridge-Aggregation100 changed to down."
----------------------------------------
My "Syslog to alarm" event :
Status : enabled
Custom view : my network view (contains all switches)
Syslog type : any
Syslog level : all checked
Statistic : Single Device
Repeat interval : 1
Repeat times : 1
Alarm level : Major
Alarm description : %Syslog%
Syslog template : *changed to down*
Param settings : NOTHING (because no variables for now)
Alarm recovery rule : unchecked (for now)
-------------------------------------
SYSLOG TEMPLATE :
Name : lienDown
Template content : "use regular expression" unchecked
textbox contains *changed to down*
Description display template : Disabled
Description : line down
------------------------
In System > System Settings I let "No Filter" in all "interface up/down alarm.
-----------------------
I have Syslog Management service deplayed and running.
Thx in advance all !
Sylvain.