Cisco prime syslog alarm

Is it possible to generate an alarm for especific Syslog Messges sent to Cisco Prime?
Admin > Network > Notification and Action Settings > Syslog Automated Actions
Here is possible to send an email. But I would like to see the alarm in the Monitoring dashboard.

It's a bit kludgey but one of the available automated actions is to run a script. The script could be a homegrown utility to generate a trap which is subsequently forwarded to the server itself. The server will then will parse this new "trap" and then display it on the dashboard.
See this document for example.

Similar Messages

  • Cisco Prime syslog server

    Where are syslogs stored, if I point my devices to Cisco Prime acting as my syslog server? I am running 2.0
    thanks, Jerry

    Hi ,
    As of now , this feature is not available , I mean PI will not work as syslog server.
    Syslog messages received by  PI from managed devices are found under Monitor > Alarms and Events > Syslogs
    as you are using PI 2.2 , you will be able to see all device syslog messages (0-7 severity)
    That display will show you up to 200,000 messages at a time.
    Check the below link for other related details proved by Marvin :
    https://supportforums.cisco.com/discussion/12486126/cisco-prime-syslog-functionality#sthash.Wbj2a3lj.dpuf
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ****

  • Including Interface Description in Cisco PRime Infrastructure Alarm Message

    Hi all,
    i succesfully configured a Cisco Prime Infrastructure 2.1 applliance to display an alarm and to send me an e-mail when switch uplink ports goes down.
    The text displayed in alarm message is :
    port 'interface_id' is down on device 'device_ip_address'
    I'd like to include in this text also the interface description so the text will display :
    port 'interface_id'  'interface_descriprion' is down on device 'device_ip_address' 
    Is this possible?
    Thankyou in advance

    Hi,
    i followed these steps :
    SWITCH SIDE
    - configured Prime Infrastructure as snmp-server host;
    - enabled snmp-traps for linkup and linkdown events globally;
    - disabled snmp-traps for linkup and linkdown on non relevant interfaces using the no snmp trap link-status command
    PRIME INFRASTRUCTURE SIDE
    - under "Deploy/Monitor Deployment" i deployed template "Interface Health"  for all the interested switches
    -  under "Administration/System Settings/Mail Server Configuration" configured my internal SMTP server to make Prime Infrastructure able to send e-mails
    - under "Operate/Alarms & Events" click on "Email Notifications" , then on "Switches and Hubs"
       - check the "critical" box ,  insert the destination e-mail address into the "To" field then click "Save"
     -  check the "switches and Hubs" box and then click Save
    As i know is possible to avoid to configure every single not-interesting port on the switches with "no snmp trap link-status" command (it's a bit annoying when you have tens of switches), using Port Grouping configuration on PI but i tried it without success.
    Hope this helps.
    Best Regards,

  • Cisco prime syslog functionality

    Hello All,
    I have added devices in cisco prime. I can see logging option in cisco prime under Administration > Logging .  I have given one server IP  (10.18.89.43) where I wanted logs to get saved but I am not sure whether prime is acting as a syslog server and if its really collecting those syslog. Also how do I know where its saving those logs on server. (See attached image)
    Please help me with exact configuration.

    Thanks Marvin for valuable reply. I can see Prime generated syslog message for one of added switch under Inventory > Device Management > Network Audit.
    But it was just one message as follows:
    Syslog Message<189>92196: Apr 21 17:33:55: %SYS-5-CONFIG_I: Configured from console by 5588648 on vty0 (10.18.83.170)
    How do I configure Prime so i can increase buffer for these messages.

  • Cisco prime Infrastructure alarms by e-mail

    hi all,
    my Cisco PI1.2 not send me a notification e-mail with specific alarm if occurred twice and the first time is not cleared or deleted.
    i.e.
    if a switch is down it send me a notification e-mail, and this switch comes up again but i did not remove the first alarm, the PI not send me a notification.
    please advice
    thanks in advance

    Alarm Status
    Description
    New
    When an event triggers a new alarm or an event is associated with an existing alarm.
    Acknowledged
    When you acknowledge an alarm, the status changes from New to Acknowledged.
    Cleared
    An alarm can be in these statuses:
    Auto-clear from the device—The fault is resolved on the device and an event is triggered for the same. For example, a device-reachable event clears the device-unreachable event. This in-turn, clears the device-unreachable alarm.
    Manual-clear from Prime Infrastructure users: You can manually clear an active alarm without resolving the fault in the network. A clearing event is triggered and this event clears the alarm.
    If the fault continues to exist in the network, a new event and alarm are created subsequently based on the event notification (traps/syslogs).
    This might be the reason, I believe.
    Please refer the following link for better understanding.
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/1-2/user/guide/prime_infra_ug/alarms.html
    Hope that helps.

  • Cisco Prime NCS - Alarms for Channel Utilization

    Hello,
    I have Prime NCS 1.3 with several WLCs (5508, 2504, etc.) configured.
    I would like to receive an e-mail alert when an AP reached high channel utlization.  Is this possible with Prime NCS?  In checking, I don't see any way to create customized events or alarms.  I  have monitoring templates, but they do not directly apply to wireless statistics.
    David

    Thanks for your response.  Maybe there's another approach what I am trying to do.  I need to know when an AP is providing poor client performance due to events like high channel utilization, high transmit/receive rates, etc.  I would like to receive an alert when a condition like this exists.
    Is there a way to get an alert on these kinds of events?  The primary mechanism for alerts seems to be based on SNMP traps from the WLC to Prime.  My 5508 (on v7.2.111.3) GUI shows the following for AP traps, which is limited:
    AP Register, AP Up/down, AP Authorization.  It also shows some very limited client events like Client Association, Client Authentication.
    David

  • Cisco Prime - create a Fault Alarm for Syslog Messages

    Is it possible to generate an alarm for especific Syslog Messges sent to Cisco Prime?
    Admin > Network > Notification and Action Settings > Syslog Automated Actions
    Here is possible to send an email. But I would like to see the alarm in the Monitoring dashboard.

    Hi Leonardo,
    unfortunately ,Automated action that you create on syslog will not show in the Monitoring dashboard :(
    Thanks-
    Afroz
    ****Ratings Encourages Contributors ****

  • Configure the syslog of ASA 5512-X for display on Cisco Prime Infrastructure 2.1

    Hi, I'm working on implementing the Cisco Prime Infrastructure 2.1 and want to display the syslog about ASA5512-X with Software Version 9.2.
    What would be the procedure for configuring?
    Thanks in advance.

    Hi,
    Enable "logging host x.x.x.x "  command to enable logging
    check the below link:
    http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/monitor_syslog.html#68764
    FYI: Prime Infrastructure support only SEV 0,1,2 syslogs as of now.
    Operate > alarm and events > syslogs
    Thanks-
    Afroz
    ****Ratings Encourages Contributors *****

  • Cisco Prime Infrastructure 1.4 SNMP Traps are not converted into Alarms

    Hi everybody,
    I just configured SNMP Traps on a Cisco Catalyst 3750-x to send to our Cisco Prime Infrastructure 1.4 Appliance.
    Now I forced the Switch to send some traps (Power off a Power Supply, Interface errdisable). The only events I see in Alarms & Events on PI is the same information message everytime:
    Configuration management event has been recorded in ccmHistoryEventTable.
    I think the forced traps should be converted into alarms? Why can't I see them?
    Thanks,
    Marc

    Ok, I started debugging as you said. I get the following output:
    Mar 13 09:28:13.711: SNMP: V2 Trap, reqid 11689, errstat 0, erridx 0
     sysUpTime.0 = 198609846
     snmpTrapOID.0 = ciscoSyslogMIB.2.0.1
     clogHistoryEntry.2.1688 = PM
     clogHistoryEntry.3.1688 = 5
     clogHistoryEntry.4.1688 = ERR_RECOVER
     clogHistoryEntry.5.1688 = Attempting to recover from bpduguard err-disable state on Gi1/0/13
     clogHistoryEntry.6.1688 = 198609844
    Mar 13 09:28:13.737: SNMP: Queuing packet to xx.xx.xx.xx
    Looks like the Switch is sending SNMP Traps from the ciscoSyslogMIB. Is this why PI can't show the Traps and convert it into a alarm?
    After this test I configured logging (syslog) to the PI. Now the errors are showed but still not converted into alarms. I just want to be notified by email when such errors occurs.
    Thanks,
    Marc

  • SYSLOG Cisco Prime LMS

    Hi friends,
    I have a question about my syslog from Cisco Prime LMS 4.1, the hours from this syslog in the LMS is diferent from my switch log.  I dont kown why.. I verified the hours betewen switch y the Cisco Prime is the same(the LMS is over Windows Server 2008R2) . both are the same log but in diferent hours about 5 hours.
    maybe I have to configure the hours for Syslog in the Cisco Prime.
    Log from Switch
    Log from Cisco Prime LMS

    If you have LMS, i am not sure, but if you have PI 1.2. Take a look at my post.
    Basically, syslog feature doesn't work well. I could see couple of syslog through event / alarm, but syslog itself is not working properly.
    https://supportforums.cisco.com/message/3861981#3861981

  • Can Cisco Prime Infra 2.1 work as syslog server

    Hello all,
        Customer want Cisco Prime Infra 2.1 to work as syslog server.  they want to query text in syslog and get raw log file from Cisco Prime Infra.  but when i see in user interface.  I think that it cannot query and search text in syslog.  but i am not sure whether we can get raw log file per devices from Cisco Prime Infra.   Can anyone know about this.?
    thanks
    sompoj

    Hi Sompoj,
    In the prime infrastructure Syslogs are directly read from udp port 514 and then filtered
    , the non SEV1 and SEV2 syslogs will be dropped and will not be entered into db . The
    syslog messages will not be saved into log files .
    Thanks-
    Afroz
    ****Ratings Encourages Contributors ****

  • Cisco Prime Infrastructure 1.2 - web browser freezes when managing rogue APs alarms

    Hello all,
    has anybody faced a freezing problem when you click in Cisco Prime Infrastructure 1.2 down on alarm bar and then to Rogue AP alarms and then try to add an annotitation or change a rogue alarm to Friendly?
    I tried it on different PC, different browsers (Firefox 14.0.1. Chrome ...) and the problem is still there.
    Has anybody an idea?
    Thanks.
    Regards
    Karel

    I just tried it from my lab VM and had no problems.  I use Chrome and the browser does sometimes not refresh for a while but that is just when I start to  click around.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Cisco Prime Infrastructure and no new events / alarms since update to 2.2.1

    Hello,
    I have upgraded our Cisco Prime Infrastructure from version 2.1 to 2.2.1 (with a backup and restore). We have round about 700 APs and three 5208 Controller. So far everything seems to work really fine. The only problem is that there are no new alarms/events under "Monitor", "Alarms and Events".
    The last entries (events and alarms) are dated before the upgrade. Other informations (like client counts for example) are correct.
    Is there a known bug related to my problem? Can anybody help?
    Thanks

    I have done some research:
    I see the following problems in the log-package (downloaded from Prime):
    ===
    <msg time='2015-04-07T12:10:50.620+02:00' org_id='oracle' comp_id='rdbms'
     client_id='' type='UNKNOWN' level='16'
     host_id='rzprime' host_addr='xxx.xxx.xxx.xxx' module='JDBC Thin Client'
     pid='9499'>
     <txt>ORA-1652: unable to extend temp segment by 128 in tablespace                 TS_EVENTS 
     </txt>
    </msg>
    <msg time='2015-04-07T12:10:50.727+02:00' org_id='oracle' comp_id='rdbms'
     client_id='' type='UNKNOWN' level='16'
     host_id='rzprime' host_addr='xxx.xxx.xxx.xxx' module='JDBC Thin Client'
     pid='15177'>
     <txt>ORA-1652: unable to extend temp segment by 128 in tablespace                 TS_EVENTS 
     </txt>
    </msg>
    ===
    I think that there is a problem with a too small tablespace. But I can´t fix that. Anybody? ;)

  • Cisco Prime Infrastructure 2.0 Alarms (switch port down)

    We have a cisco Prime Infrastructure 2.0 managing switches, routers and AP.
    By default, when a port of a switch goes down, the cisco Prime Infrastructre generates a Critical Alarm for that. (this is a problem, because every phone of laptop disconnection will generate a critical alarm for me)
    I found out that if we go to Administration --> Alarm Severity --> Link down, I can change the Alarm from Critical to another type of alarm.(ex: warning)
    The problem is that I want to keep the Critical Alarm for my Uplinks ports and for some important switch ports, and I would like to make the alarm as warning for the normal user ports.
    I know that I can create Port Groupping and add ports to each group and apply monitoring templates on those groups. But This couldn't Help me solving my alarm problem.
    So I just need to know how to manage the alarms severity for each group of ports.
    Thank you

    Hi,
    Same problem here.
    I am using Cisco Prime Infrastructure 2.0 (evaluation version for 60 days). I want to deploy port monitoring for my trunk ports between switches and some other important ports e.g. servers. Basically I want to get alarms when these ports are down, there are errors on ports and etc.
    So in Design>Port Grouping I created User Defined group with important ports. In Deploy>Monitoring Deployment I selected Interface Health (default)>Deploy selected Port Groups and when selected port group I created.
    Now the rule shows Deployed: Yes and Status: Active. After that I just pulled out one port which was in monitored group, waited 5min as it is set in Interface Health (default) template, and nothing happened, and worse, alarms started to show up of other ports where regular users are connected (computers was turned off), which I do not want to see at all. I tried redeploy template, I even created my own template but still no desired result.
    Any suggestions how to make port monitoring work?

  • E-mail will be suppressed up to 30 minutes for these alarms. Cisco Prime

    Hi
    I'm trying out the email notification in the cisco prime and encountered this issue.
    E-mail will be suppressed up to 30 minutes for these alarms.
    This causes the other AP's that I restart to not send an notification, and I cannot find a way to remove this email suppression.
    I want all the critical emails to be sent and not get dropped.
    Or am I misunderstanding this? I cant find any threshold to change / disable
    Cisco prime 2.0 fyi
    thanks!

    This is still a problem in Prime 2.0.  I opened a case asking how to change the email suppression time period from 30 minutes to 4 hours so that alarms tripped overnight that won't be acknowledged wouldn't result in a flooded mailbox, and was told this is not a configurable option. So apparently the only "fix" is to turn off the alarm, or change the category to a lesser one that won't result in an email being sent.  I hope in a future release they will decide to make this configurable.

Maybe you are looking for

  • Suspend Not Working Post 2013-09-17 Move Away From Init

    Hello,     I would first like to say I have been happily using Arch for about a year now and I'm very thankful for the wonderful arch wiki that has answered more questions than I can count. However, I seem to be stuck on this one. Recently, after upd

  • Can I buy a Macbook Pro from Apple store Singapore and send it to Italy?

    I' m wandering if I can buy a Macbook Pro Display Retina from Apple Store Singapore online and then send it to Italy. Please answer. Thank you :)

  • Export giving "Invalid column type" error

    Hi, I am using Export button in my page and I provided "BICOSortedDetlsVO1" for View instance property. After I ran I got java.sql.SQLException: Invalid column type. Can any one let me know where I am doing wrong? Thanks, Subramanyam.

  • Re: Profit Center Default

    Hi, I am trying to configure the 3KEH and 3KEI so that their is a Profit Center default for two particular accounts. I have set up the Derivation Rule and everything looks ok, however, i carry out a posting with those accounts and it does not work. I

  • Best way for skinning a JSF2.0 application

    Hi, I’m wondering what is the best way to skin my application. My applications uses facelet templates with css files included. The css of my custom components are injected with the @ResourceDependancy annotation. My question is if there is a standard