ACS 5.1 shows no logged events in Monitoring and Reports
Hello
I have a Cisco ACS 5.1 virtual appliance which has been working fine, I have however just discovered that it is now unable to provide me with any logs.
TACACS authentication is still working without any issues, the only problem I have is viewing the logs.
Many Thanks in advance for the help.
George
everything is running. I have tried restarting some of the services, however I have had no joy.
ACS role: PRIMARY
Process 'database' running
Process 'management' running
Process 'runtime' running
Process 'view-database' running
Process 'view-jobmanager' running
Process 'view-alertmanager' running
Process 'view-collector' running
Process 'view-logprocessor' running
Similar Messages
-
Cisco Secure ACS 5.4/Monitoring and Report Viewer - SNMP Settings
Hello Everyone.
I hope this is the right forum for my question.
We just purchased 8 1121 ACS 5.4 appliances. I have some familiarity with the older 1113 and 1120 appliances running ACS 4.2. So I have a lot to learn.
Right now I'm trying to understand the Monitoring and Report Viewer System Configuration. I set the SNMP V2 read comm. string to the same string I configured from the CLI.
etc-labacsb1-1/admin# show runn | inc snmp
snmp-server contact "ACS1121;XXXXX"
snmp-server location "B1 Lab"
snmp-server community XXXXXX ro
1) It was not the same string as configured on CLI. Does setting this give me access to query more than system type or server type MIB objects.
2) Can you provide an example? (for example to query a switch - snmpwalk -v 1 -c XXXXXX hostname 1.3.6.1.4.1.9.9.43)
3) What is the MIB object tree OID (1.3.6.1.4.1.9.???) for these ACS appliances?
Thanks in advance.
Ray Westphal
EHIthat's correct. here is what we have in ACS 5.4 for snmp.
ACS 5.4 supports Simple Network Management Protocol (SNMP) to provide logging services. The SNMP agent provides read-only SNMPv1 and SNMPv2c support. The supported MIBs include:
•SNMPv2-MIB
•RFC1213-MIB (MIB II)
•IF-MIB
•IP-MIB
•TCP-MIB
•UDP-MIB
•CISCO-CDP-MIB
•ENTITY-MIB
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/device_support/sdt54.html#wp71020
~BR
Jatin Katyal
**Do rate helpful posts** -
IPS event monitor and reports not working
Dear after upgrading my IPS from E3 to E4 the event monitor and reports not working, can you please advice my to solve this issues
Hi All,
Filter settings below:
The filter works partially as I don't get alerts on the IPS itself.
Firewall LOG:
4 Feb 14 2014 15:33:22 39715 514 IPS requested to drop UDP packet from SOURCE_VLAN_NUMBER:/39715 to DESTINATION_VLAN_NUMBER:/514
IPS LOG (when enabled):
evIdsAlert: eventId=1352793300955167909 vendor=Cisco severity=low
originator:
hostId: SSM02
appName: sensorApp
appInstanceId: 1192
time: Feb 14, 2014 15:33:22 UTC offset=0 timeZone=GMT00:00
signature: description=IP Fragment Too Small id=1206 version=S212 type=anomaly created=20030801
subsigId: 0
sigDetails: Too many small IP fragments in datagram
interfaceGroup: vs0
vlan: 0
participants:
attacker:
addr: 172.x.x.x locality=OUT
port: 39715
target:
addr: x.x.x.x locality=OUT
port: 514
os: idSource=unknown type=unknown relevance=relevant
alertDetails: InterfaceAttributes: context="single_vf" physical="Unknown" backplane="GigabitEthernet0/1" ;
riskRatingValue: 50 targetValueRating=medium attackRelevanceRating=relevant
threatRatingValue: 50
interface: GigabitEthernet0/1 context=single_vf physical=Unknown backplane=GigabitEthernet0/1
protocol: udp
Our next step is to make a service policy exception on the firewall itself. We are also considering reloading the IPS device or at least the analysis engine.
Thanks for all your help so far. Any more suggestions are most welcome. I'll keep you up to date.
Regards
Mariusz -
Customizing the Monitoring and Report Viewer - ACS 5.2
Is there a way to modify the columns shown in the monitoring and reporting viewer so that I can see all of the relevant columns in one screen, similar to the ACS 4.x view? I would like to view things at a glance, rather than having to click into each item. Thank you for your help in advance.
that's correct. here is what we have in ACS 5.4 for snmp.
ACS 5.4 supports Simple Network Management Protocol (SNMP) to provide logging services. The SNMP agent provides read-only SNMPv1 and SNMPv2c support. The supported MIBs include:
•SNMPv2-MIB
•RFC1213-MIB (MIB II)
•IF-MIB
•IP-MIB
•TCP-MIB
•UDP-MIB
•CISCO-CDP-MIB
•ENTITY-MIB
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/device_support/sdt54.html#wp71020
~BR
Jatin Katyal
**Do rate helpful posts** -
Monitoring and Reporting on ACS 5.1 not working
Hello,
I have not managed to get the Monitoring to work on the ACS 5.1. This is an eval version. Advanced monitoring and reporting is installed on the ACS. This is my configuration on the Cisco Router
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
logging origin-id ip
logging facility syslog
logging source-interface GigabitEthernet1/1
logging host 1.1.1.1 transport udp port 20514
logging monitor informational
epm logging
On the ACS, when I open the dashboard --> ACS health -> I get Status not available.
Global Instance under Logging Categories been configured for local logging
ThanksThe view logprocessor is not running
ACS role: PRIMARY
Process 'database' running
Process 'management' running
Process 'runtime' running
Process 'adclient' running
Process 'view-database' running
Process 'view-jobmanager' running
Process 'view-alertmanager' running
Process 'view-collector' running
Process 'view-logprocessor' not monitored
Does anyone know how to start it??
Thanks -
Cisco ACS 5.2 (esx 4 vm) and Monitoring and Reports failure
I am evaling the Cisco ACS 5.2 Virtual Appliance on ESX4 and everything is working fine except for the "Monitoring and Reports" no matter what browser I try, it just keeps loading new tabs of the welcome screen, in the case of some browser versions it does this and does not stop.
I have tried the following browsers on Win7 Pro: IE 8, Firefox 4, Firefox 3, Chrome 12.
I have tried the following browsers on MacOS 10.6: FireFox 4, Safari 5.0.5
In Safari 5.0.5 it calls up one new window, but doesn't load anything in the right hand frame.
This is a fresh install, with an eval license. I am rather annoyed that it doesn't work out of the box, especially when there was not documentation that mentioned that anything needed to be setup for this to work after initial install, unless I missed something.
I installed the VM with the base 5.0.26 ISO and then applied patches 5.0.26-1 through 5.0.26-5.
Can anyone provide any help on this?I am evaling the Cisco ACS 5.2 Virtual Appliance on ESX4 and everything is working fine except for the "Monitoring and Reports" no matter what browser I try, it just keeps loading new tabs of the welcome screen, in the case of some browser versions it does this and does not stop.
I have tried the following browsers on Win7 Pro: IE 8, Firefox 4, Firefox 3, Chrome 12.
I have tried the following browsers on MacOS 10.6: FireFox 4, Safari 5.0.5
In Safari 5.0.5 it calls up one new window, but doesn't load anything in the right hand frame.
This is a fresh install, with an eval license. I am rather annoyed that it doesn't work out of the box, especially when there was not documentation that mentioned that anything needed to be setup for this to work after initial install, unless I missed something.
I installed the VM with the base 5.0.26 ISO and then applied patches 5.0.26-1 through 5.0.26-5.
Can anyone provide any help on this? -
Critical Logging Event Red ( /sapapo/om13)
Hello,
In /sapapo/om13--->checks, we can see critical logging event is red.
I logging section, message are
1> error in /SAPAPO/OM_REORG_DAILY (date 16.10.2007)
2> Planning version was created.(date 13.10.2007)
3> ATP time series active(date 12.10.2007)
4> error OM13 ( date 10.10.2007)
we want to turn this critical loging event to green.
Should we delete livecache application logs via /sapapo/om12 or is there any other way to turn it into green.
As far as I know, /sapapo/OM13->Logging contains last entries from logging log.(/sapapo/om13->Logging----
>Logging Log .)But Last entries means how many? any parameter to do this?(Just a query)
Can somebody please help me turning critical event log to green.
Please feel free to add thougts.Thanks.
Regards,
Tushar
Message was edited by:
Tushar ChavanHello Tushar,
You could turn critical event log to green if you will not have the Critical Logging Events for the last 5 days.
For example, OM13 could Shows the Critical Logging Event as Yellow. You could run the transaction /sapapo/om11 or /sapapo/OM13 -> tab 'logging' to review the critical logging events, which have occurred recently on your system. If , for example, the 'Old transactional simulations deleted' by the //om_ reorg_daily report or corrections of the inconsistencies in /sapapo/om17 were done on your system, the events will be listed in the 'logging' section. And the OM13 Shows Critical Logging Event (Yellow) to pay attention for you to check 'logging' for more details.
Information to the reason of the yellow light can be found via the blue info button.
For example on the my local system in the transaction /sapapo/om13 -Checks -> 'Critical Logging Event' shows the yellow light. Before the yellow light you will see the last Event to be checked in "Logging".
The next info was displayed, when I was clicked blue info button:
At least one critical logging event has occurred recently. See "Logging"
in the Writer for more details.
And when will go to the transaction /sapapo/om13 -> logging ( or you could use the transaction /sapapo/om11 ), you will see "Logging" list of events for more details.
-> In your case if you have red light for the Critical Logging Event, you need to correct the problem with the error in "Logging" event.
-> You should not delete the "Logging" events on your system to get the green light
in //om13->checks, "Logging" events needed for the further analysis of the LCA problems on your system, if you have them or will have in future.
-> If the error in /SAPAPO/OM_REORG_DAILY occurred, it has to be checked/corrected. And if the job will run without errors the problem is gone. See the SAP note 800927.
->"2> Planning version was created.(date 13.10.2007)
3> ATP time series active(date 12.10.2007)"
Please review the SAP note: 792286 Repairing/activating ATP time series.
Are you running the system upgrade?
< If yes, then the note 792286 is NOT needed to be applied or pay attention.
During the upgrade the step to activate the ATP time series is before to load the master data to liveCache in the target release. And during the load master data the planning versions were loaded < created > to the liveCache from APO database. >
What is the version of your system?
-> I recommend you to create the OSS message to the component 'BC-DB-LCA'
to check the critical LCA events on your system.
Thank you and best regards, Natalia Khlopina -
Error showing on the Event Viewer
Hello,
I have installed the Oracle9iAS at win2k SP3, i have this error when i reboot my server where this showing in the event viewer log.
The OracleOra9ias_homeWebCache service hung on starting.
But when i go to the services, it show this service started. But it give error on the server.
Do you have any idea to solve this problem??
Thanks
Regards,
mingjadeHi Jordan,
Actually i can't solve that problem. So, i formated the server since is not on production yet. So it run fine now.
Thanks
Regards,
Ming Jade -
Log file sequential read and RFS ping/write - among Top 5 event
I have situation here to discuss. In a 3-node RAC setup which is Logical standby DB; one node is showing high CPU utilization around 40~50%. The CPU utilization was less than 20% 10 days back but from 9th oldest day it jumped and consistently shows the double figure. I ran AWR reports on all three nodes and found one node with high CPU utilization and shows below tops events-
EVENT WAITS TIME(S) AVG WAIT(MS) %TOTAL CALL TIME WAIT CLASS
CPU time 5,802 34.9
RFS ping 15 5,118 33,671 30.8 Other
Log file sequential read 234,831 5,036 21 30.3 System I/O
Sql*Net more data from
client 24,171 1,087 45 6.5 Network
Db file sequential read 130,939 453 3 2.7 User I/O
Findings:-
On AWR report(file attached) for node= sipd207; we can see that "RFS PING" wait event takes 30% of the waits and "log file sequential read" wait event takes 30% of the waits that occurs in database.
Environment :- (Oracle- 10.2.0.4.0, O/S - AIX .3)
1)other node awr shows "log file sync" - is it due to oversized log buffer?
2)Network wait events can be reduced by tweaking SDU & TDU values based on MDU.
3) Why ARCH processes taking much to archives filled redo logs; is it issue with slow disk I/O?
Regards
WORKLOAD REPOSITORY report for<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<DB Name DB Id Instance Inst Num Release RAC Host
XXXPDB 4123595889 XXX2p2 2 10.2.0.4.0 YES sipd207
Snap Id Snap Time Sessions Curs/Sess
Begin Snap: 1053 04-Apr-11 18:00:02 59 7.4
End Snap: 1055 04-Apr-11 20:00:35 56 7.5
Elapsed: 120.55 (mins)
DB Time: 233.08 (mins)
Cache Sizes
~~~~~~~~~~~ Begin End
Buffer Cache: 3,728M 3,728M Std Block Size: 8K
Shared Pool Size: 4,080M 4,080M Log Buffer: 14,332K
Load Profile
~~~~~~~~~~~~ Per Second Per Transaction
Redo size: 245,392.33 10,042.66
Logical reads: 9,080.80 371.63
Block changes: 1,518.12 62.13
Physical reads: 7.50 0.31
Physical writes: 44.00 1.80
User calls: 36.44 1.49
Parses: 25.84 1.06
Hard parses: 0.59 0.02
Sorts: 12.06 0.49
Logons: 0.05 0.00
Executes: 295.91 12.11
Transactions: 24.43
% Blocks changed per Read: 16.72 Recursive Call %: 94.18
Rollback per transaction %: 4.15 Rows per Sort: 53.31
Instance Efficiency Percentages (Target 100%)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Buffer Nowait %: 99.99 Redo NoWait %: 100.00
Buffer Hit %: 99.92 In-memory Sort %: 100.00
Library Hit %: 99.83 Soft Parse %: 97.71
Execute to Parse %: 91.27 Latch Hit %: 99.79
Parse CPU to Parse Elapsd %: 15.69 % Non-Parse CPU: 99.95
Shared Pool Statistics Begin End
Memory Usage %: 83.60 84.67
% SQL with executions>1: 97.49 97.19
% Memory for SQL w/exec>1: 97.10 96.67
Top 5 Timed Events Avg %Total
~~~~~~~~~~~~~~~~~~ wait Call
Event Waits Time (s) (ms) Time Wait Class
CPU time 4,503 32.2
RFS ping 168 4,275 25449 30.6 Other
log file sequential read 183,537 4,173 23 29.8 System I/O
SQL*Net more data from client 21,371 1,009 47 7.2 Network
RFS write 25,438 343 13 2.5 System I/O
RAC Statistics DB/Inst: UDAS2PDB/udas2p2 Snaps: 1053-1055
Begin End
Number of Instances: 3 3
Global Cache Load Profile
~~~~~~~~~~~~~~~~~~~~~~~~~ Per Second Per Transaction
Global Cache blocks received: 0.78 0.03
Global Cache blocks served: 1.18 0.05
GCS/GES messages received: 131.69 5.39
GCS/GES messages sent: 139.26 5.70
DBWR Fusion writes: 0.06 0.00
Estd Interconnect traffic (KB) 68.60
Global Cache Efficiency Percentages (Target local+remote 100%)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Buffer access - local cache %: 99.91
Buffer access - remote cache %: 0.01
Buffer access - disk %: 0.08
Global Cache and Enqueue Services - Workload Characteristics
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Avg global enqueue get time (ms): 0.5
Avg global cache cr block receive time (ms): 0.9
Avg global cache current block receive time (ms): 1.0
Avg global cache cr block build time (ms): 0.0
Avg global cache cr block send time (ms): 0.1
Global cache log flushes for cr blocks served %: 2.9
Avg global cache cr block flush time (ms): 4.6
Avg global cache current block pin time (ms): 0.0
Avg global cache current block send time (ms): 0.1
Global cache log flushes for current blocks served %: 0.1
Avg global cache current block flush time (ms): 5.0
Global Cache and Enqueue Services - Messaging Statistics
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Avg message sent queue time (ms): 0.1
Avg message sent queue time on ksxp (ms): 0.6
Avg message received queue time (ms): 0.0
Avg GCS message process time (ms): 0.0
Avg GES message process time (ms): 0.1
% of direct sent messages: 31.57
% of indirect sent messages: 5.17
% of flow controlled messages: 63.26
Time Model Statistics DB/Inst: UDAS2PDB/udas2p2 Snaps: 1053-1055
-> Total time in database user-calls (DB Time): 13984.6s
-> Statistics including the word "background" measure background process
time, and so do not contribute to the DB time statistic
-> Ordered by % or DB time desc, Statistic name
Statistic Name Time (s) % of DB Time
sql execute elapsed time 7,270.6 52.0
DB CPU 4,503.1 32.2
parse time elapsed 506.7 3.6
hard parse elapsed time 497.8 3.6
sequence load elapsed time 152.4 1.1
failed parse elapsed time 19.5 .1
repeated bind elapsed time 3.4 .0
PL/SQL execution elapsed time 0.7 .0
hard parse (sharing criteria) elapsed time 0.3 .0
connection management call elapsed time 0.3 .0
hard parse (bind mismatch) elapsed time 0.0 .0
DB time 13,984.6 N/A
background elapsed time 869.1 N/A
background cpu time 276.6 N/A
Wait Class DB/Inst: UDAS2PDB/udas2p2 Snaps: 1053-1055
-> s - second
-> cs - centisecond - 100th of a second
-> ms - millisecond - 1000th of a second
-> us - microsecond - 1000000th of a second
-> ordered by wait time desc, waits desc
Avg
%Time Total Wait wait Waits
Wait Class Waits -outs Time (s) (ms) /txn
System I/O 529,934 .0 4,980 9 3.0
Other 582,349 37.4 4,611 8 3.3
Network 279,858 .0 1,009 4 1.6
User I/O 54,899 .0 317 6 0.3
Concurrency 136,907 .1 58 0 0.8
Cluster 60,300 .0 41 1 0.3
Commit 80 .0 10 130 0.0
Application 6,707 .0 3 0 0.0
Configuration 17,528 98.5 1 0 0.1
Wait Events DB/Inst: UDAS2PDB/udas2p2 Snaps: 1053-1055
-> s - second
-> cs - centisecond - 100th of a second
-> ms - millisecond - 1000th of a second
-> us - microsecond - 1000000th of a second
-> ordered by wait time desc, waits desc (idle events last)
Avg
%Time Total Wait wait Waits
Event Waits -outs Time (s) (ms) /txn
RFS ping 168 .0 4,275 25449 0.0
log file sequential read 183,537 .0 4,173 23 1.0
SQL*Net more data from clien 21,371 .0 1,009 47 0.1
RFS write 25,438 .0 343 13 0.1
db file sequential read 54,680 .0 316 6 0.3
DFS lock handle 97,149 .0 214 2 0.5
log file parallel write 104,808 .0 157 2 0.6
db file parallel write 143,905 .0 149 1 0.8
RFS random i/o 25,438 .0 86 3 0.1
RFS dispatch 25,610 .0 56 2 0.1
control file sequential read 39,309 .0 55 1 0.2
row cache lock 130,665 .0 47 0 0.7
gc current grant 2-way 35,498 .0 23 1 0.2
wait for scn ack 50,872 .0 20 0 0.3
enq: WL - contention 6,156 .0 14 2 0.0
gc cr grant 2-way 16,917 .0 11 1 0.1
log file sync 80 .0 10 130 0.0
Log archive I/O 3,986 .0 9 2 0.0
control file parallel write 3,493 .0 8 2 0.0
latch free 2,356 .0 6 2 0.0
ksxr poll remote instances 278,473 49.4 6 0 1.6
enq: XR - database force log 2,890 .0 4 1 0.0
enq: TX - index contention 325 .0 3 11 0.0
buffer busy waits 4,371 .0 3 1 0.0
gc current block 2-way 3,002 .0 3 1 0.0
LGWR wait for redo copy 9,601 .2 2 0 0.1
SQL*Net break/reset to clien 6,438 .0 2 0 0.0
latch: ges resource hash lis 23,223 .0 2 0 0.1
enq: WF - contention 32 6.3 2 62 0.0
enq: FB - contention 660 .0 2 2 0.0
enq: PS - contention 1,088 .0 2 1 0.0
library cache lock 869 .0 1 2 0.0
enq: CF - contention 671 .1 1 2 0.0
gc current grant busy 1,488 .0 1 1 0.0
gc current multi block reque 1,072 .0 1 1 0.0
reliable message 618 .0 1 2 0.0
CGS wait for IPC msg 62,402 100.0 1 0 0.4
gc current block 3-way 998 .0 1 1 0.0
name-service call wait 18 .0 1 57 0.0
cursor: pin S wait on X 78 100.0 1 11 0.0
os thread startup 16 .0 1 53 0.0
enq: RO - fast object reuse 193 .0 1 3 0.0
IPC send completion sync 652 99.2 1 1 0.0
local write wait 194 .0 1 3 0.0
gc cr block 2-way 534 .0 0 1 0.0
log file switch completion 17 .0 0 20 0.0
SQL*Net message to client 258,483 .0 0 0 1.5
undo segment extension 17,282 99.9 0 0 0.1
gc cr block 3-way 286 .7 0 1 0.0
enq: TM - contention 76 .0 0 4 0.0
PX Deq: reap credit 15,246 95.6 0 0 0.1
kksfbc child completion 5 100.0 0 49 0.0
enq: TT - contention 141 .0 0 2 0.0
enq: HW - contention 203 .0 0 1 0.0
RFS create 2 .0 0 115 0.0
rdbms ipc reply 339 .0 0 1 0.0
PX Deq Credit: send blkd 452 20.1 0 0 0.0
gcs log flush sync 128 32.8 0 2 0.0
latch: cache buffers chains 128 .0 0 1 0.0
library cache pin 441 .0 0 0 0.0
Wait Events DB/Inst: UDAS2PDB/udas2p2 Snaps: 1053-1055
-> s - second
-> cs - centisecond - 100th of a second
-> ms - millisecond - 1000th of a second
-> us - microsecond - 1000000th of a second
-> ordered by wait time desc, waits desc (idle events last)We only apply on one node in a cluster so I would expect that the node running SQL Apply would have much higher usage and waits. Is this what you are asking?
Larry -
Is this enabled by default on Cisco IOS switch ports? What logging level will ensure I see link status in the router buffer log?
logging event link-status global (global configuration)
To change the default switch-wide global link-status event messaging settings, use the
logging event link-status global command. Use the no form of this command to disable the link-status event messaging.
logging event link-status global
no logging event link-status global
Syntax Description
This command has no arguments or keywords.
Defaults
The global link-status messaging is disabled.
Command Modes
Global configuration
Command History
Release Modification
12.2(25)SG
Support for this command was introduced on the Catalyst 4500 series switch.
Usage Guidelines
If link-status logging event is not configured at the interface level, this global link-status setting takes effect for each interface.
Examples
This example shows how to globally enable link status message on each interface:
Switch# config terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)# logging event link-status global
Switch(config)# end
Switch#
Related Commands
logging event link-status global (global configuration)
logging event link-status (interface configuration)
To enable the link-status event messaging on an interface, use the logging event link-status command. Use the no form of this command to disable link-status event messaging. Use the
logging event link-status use-global command to apply the global link-status setting.
logging event link-status
no logging event link-status
logging event link-status use-global
Defaults
Global link-status messaging is enabled.
Command Modes
Interface configuration
Command History
Release Modification
12.2(25)SG
Support for this command was introduced on the Catalyst 4500 series switch. -
SCEP manager is not showing current logs for any SCEP clients
I have installed SCEP manager on one machine and it is managing one client, which is on another machine.
Client is showing virus detected logs in SCEP client UI, but the same events/logs are not getting stored in SCEP manager database, i tried pulling out records from database, there is no entry for detected viruses in the database, and SCEP manager UI monitor
tab is also not showing any detected events.Hi,
Active means that it has been active and communicated with the MP within the last 7 days, not that it is active now.
That means that you either haven't extended the Active Directory or created the System Management container in AD and delegated permission to that container and all the child object to the ConfigMgr Primary Site Server Computer account. But that isn't a
requirement only a rekommendation.
If you look in the client in ClientLocation.log file can the client find an MP to communicate with? Any more errors in the MPcontrol.log file on the server?
Regards,
Jörgen
-- My System Center blog ccmexec.com -- Twitter
@ccmexec -
Hi guys, i m using ACS 3.3 windows version, these are the commands
aaa accounting update periodic 1
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
but i m not getting all the show commands logged, i usually get logging of show running, show start-up, but no other show commands like show ip int brief and such, what is the reason ? how can i get all the exec commands logged ?
thanksOvais
The command that you have configured:
aaa accounting commands 15 default start-stop group tacacs+
will generate accounting records for the commands that are entered that require level 15 privilege (such as show run, show start, etc) but will not generate accounting records for commands which only require level 1 privilege (such as sh ip int brief, etc). If you also want these commands to generate accounting records then you should add this to your config:
aaa accounting commands 1 default start-stop group tacacs+
HTH
Rick -
Switch doesn't show any log when AC is put in back.
I'm using two kind of switches i.e Cat2960S-24TD-L and Cat2960S-48TS-L with RPS2300 for backup power.
One question was raising in my head during the power redundancy test on the switches.
My question is how NMS can recognize that AC power is put in back as normal status without any log.
Each switch has two power sources. One from AC built-in power and the other from RPS2300 as below.
Access_SW#show env all
FAN is OK
TEMPERATURE is OK
Temperature Value: 39 Degree Celsius
Temperature State: GREEN
Yellow Threshold : 50 Degree Celsius
Red Threshold : 60 Degree Celsius
SW PID Serial# Status Sys Pwr PoE Pwr Watts
1 Built-in Good
2 Built-in Good
SW Status RPS Name RPS Serial# RPS Port#
1 Active RPS1 FDO1447YGT3 3
2 Active RPS1 FDO1447YGT3 6
~snipped~
DCOut State Connected Priority BackingUp WillBackup Portname SW#
1 Active No 6 No Yes <> -
2 Active No 6 No Yes <> -
3 Active Yes 6 No Yes Access_SW 1
4 Active No 6 No Yes <> -
5 Active No 6 No Yes <> -
6 Active Yes 6 No Yes Access_SW 2
When I pull out the AC power cable out from the switch, it shows the proper log saying as below.
Access_SW#
Jul 8 17:15:46 UTC: %PLATFORM_ENV-1-PWR: Internal power supply not supplying power (Access_SW-2)
Access_SW#show env all
FAN is OK
TEMPERATURE is OK
Temperature Value: 39 Degree Celsius
Temperature State: GREEN
Yellow Threshold : 50 Degree Celsius
Red Threshold : 60 Degree Celsius
SW PID Serial# Status Sys Pwr PoE Pwr Watts
1 Built-in Good
2 Built-in Unavail
SW Status RPS Name RPS Serial# RPS Port#
1 Active RPS1 FDO1447YGT3 3
2 Active RPS1 FDO1447YGT3 6
~snipped~
DCOut State Connected Priority BackingUp WillBackup Portname SW#
1 Active No 6 No Yes <> -
2 Active No 6 No Yes <> -
3 Active Yes 6 No Yes Access_SW 1
4 Active No 6 No Yes <> -
5 Active No 6 No Yes <> -
6 Active Yes 6 Yes Yes Access_SW 2
But I put AC power cable back into the switch, it doesn't show any log and any change to me. It still shows 'Built-in is Unavail' as below.
Access_SW#show env all
~snipped~
SW PID Serial# Status Sys Pwr PoE Pwr Watts
1 Built-in Good
2 Built-in Unavail
SW Status RPS Name RPS Serial# RPS Port#
1 Active RPS1 FDO1447YGT3 3
2 Active RPS1 FDO1447YGT3 6
~snipped~
DCOut State Connected Priority BackingUp WillBackup Portname SW#
1 Active No 6 No Yes <> -
2 Active No 6 No Yes <> -
3 Active Yes 6 No Yes Access_SW 1
4 Active No 6 No Yes <> -
5 Active No 6 No Yes <> -
6 Active Yes 6 Yes Yes Access_SW 2
The problem is how the operator can decide 'Now AC power is okay so I will push the button on RPS to make it backup again' without getting any information from the switch.Hi innetee9228:
If the output of "show env all" doesn't change when you put the AC power back in, that's indicating a bigger problem. You see the %PLATFORM_ENV-1-PWR: message go when the power comes out, so there should be one when the power goes back. That's more indicative of an IOS problem where the status isn't getting updated as it should.
The SNMP agent rides along side the guts of the IOS that feed the SHOW commands. If the hardware isn't reporting correctly or whatever and "show env all" doesn't tell the truth, it's not likely that the SNMP agent is going to be receiving truth, either.
Once you have that addressed, you should be able to turn up power supply event traps and send them to whatever SNMP Manager you'd like, and have that alert your operator.
nms-6506-e(config)#snmp-server enable traps envmon supply ?
fan Enable SNMP envmon fan traps
shutdown Enable SNMP environmental monitor shutdown traps
status Enable SNMP environmental status change traps
temperature Enable SNMP environmental monitor temperature traps
nms-6506-e(config)# -
When looking at the Site Analytics Report in SP Foundation 2010, I see that many users (though not all it appears) have been logged under the 'Top Visitors' section as both "DOMAINNAME\username" as well as "domainname\username". This makes it hard
to get actual counts of hits the visitors have made since they show up in two places on the report. In my case, I always log in using the same credentials (more recently I have had permissions upgraded so log in is automatic), yet I still see that I
get posted for different usage numbers under the uppercase and lowercase instances. Does anyone know why this would be occurring?Even i am facing similar kind of problem. Some of my users are displayed as DomainName\ID while some are displayed as Lastname, Firstname. I think we need to know the location where these reports are stored.
-
I used a Roxie program to bring in my video from VHS. I know it's in my computer and when I right click in the event in IMovie and click "capture movie, a screen comes up showing it but it won't capture it and bring it into IMovie. What am I doing wrong
Firefox can find plugins in several locations, but Firefox 21 changed the location of the "shared" plugin folder so older installers like the Microsoft Windows Media Plugin no longer drop the DLL file in the correct location.
There apparently are two ways to address this:
(1) Change a Firefox preference so that Firefox checks the old location. Here's how:
(i) In a new tab, type or paste '''about:config''' in the address bar and press Enter. Click the button promising to be careful.
(ii) In the filter box, type or paste '''plugins''' and pause while the list is filtered
(iii) Double-click '''plugins.load_appdir_plugins''' to switch its value from false to true.
This will take effect after you restart Firefox.
(2) Copy the plugins folder to the new location. Here's how on Win 7 64-bit:
Open a Windows Explorer window to:
C:\Program Files (x86)\Mozilla Firefox
Right-click and copy the '''Plugins''' folder
Double-click the '''browser''' folder to open it
Right-click and paste
Right-click the new copy of '''Plugins''' and rename it to '''plugins'''
After restarting Firefox, the plugins in that folder should now be available.
''Edit: I suggest just doing #1.''
Maybe you are looking for
-
"Can't open a scratch file" error
Running PSD 12.0.4 (Extended) on a Mac Pro, Mac OS 10.7.3. Plenty of ram; plenty of hard disk space. I just finished installing a new 1TB drive in one of my bays; I now have (3) 1TB drives total. Initialized the new drive (Mac OS Extended/Journaled),
-
File Chooser to open a document?
Does anyone know how I can display a file chooser for a directory on the application server in Forms 10g and then open the file?
-
How to see all structure and key figures
HI friends, I can not to see in query designer all structure, all calculated and restricted key figure than I have create. How can I do?? Thanks bye bye
-
Re: Windows 8 reinstall - productkey issue
Hello, Due to a destructive virus I had to wipe my harddisk. Now I am trying to reinstall Windows 8. I use a Windows 8 OEM DVD for this which I purchased with a new PC. It asks for a productkey, which I don't have. I understand the productkey should
-
Hello Experts, Some of the data missing while writing appl server when scheduled. But when the program ran manually the data is correct. Could you please advise what are the possibilites for this. Thanks Konda Reddy