CSS Show summary command question

When I issue "show summary" within the owner of SPOT-WT-PROD-EXT (please excuse the names I didn�t pick them)
I get the below results. my question is why does content web-servers have 3.1 mil + hits when the other two content rules have the same number of hits but far less. Before I issued the show summary command I typed "zero all" to bring the counts to zero. any thoughts?
Owner                               Content Rules                         State     Services                             Service Hits
SPOT-WT-PROD-EXT         SPOT-WT-PROD-EXT-A          Master    ACE-SPOT-WT-PROD        2816 
                                        SPOT-WT-PROD-EXT-B           Master    ACE-SPOT-WT-PROD        2816
                                        web-servers                             Master    ACE-SPOT-WT-PROD       3162510

The show summary gives you info about traffic coming in.
The CSS is not responsible if it gets more traffic for one rule vs another one.
You should check upstream ....or it might be the nature of the application....the last rule attracting more users...or generating more connections.
Gilles

Similar Messages

  • Show Service Summary - Command Details

    Dear All,
    It would be nice if any one can share me the parameter details of Show Service Summary command. The 2 parameters I am confused of is "Conn" and "State Transition".
    My query is,
    1) Does Conn means the current hits to that serivce. And how long this conn value would show?
    2) What is the meaning of State Transitions? What information does it reveal?
    Please need your help.
    BR//
    Adnan

    Hi Adnan,
    Here are the answers to your questions:
    1) Does Conn means the current hits to that serivce. And how long this conn value would show?
    The "Conn" counter shows the amount of connections currently active on that service. It will be updated as soon as connections are added/removed from the flow table.
    2) What is the meaning of State Transitions? What information does it reveal?
    This indicates how many times the service changed state since the last time the counters were cleared. It will be incremented every time a service moves from "Alive" to "Down" or the other way around
    I hope this answers your questions, but if you need further clarification, just let me know
    Regards
    Daniel

  • Question about ACE show Conn command (tcp duration)

    Hello,
    I was checking connections and noticed that I would see the initial connection, but after a short time the connection quits showing up in the counters and the “show conn” command. However the user is still up and working.
    This is the command I used:
    sho conn serverfarm STAGING-HTTPS detail
    The output shows all the connection info from source to destination, and in the ESTABLISHED state.
    However, after maybe 2~3 minutes, when I up arrow I don't see any connection info. The web page is still up. If I refresh the web page, I do see the connections come in.
    Can someone kindly point me to a document or provide an answer on how long should the connection be stored before they are flushed?
    Config profile:
    4 real servers
    HTTPS protocol
    Leastconn for predictor
    sticky based on src/dst IP
    Thanks,
    Raman

    Raman,
    If you would play with a sniffer capture, you could answer the question yourself.
    If the browser loads a flash object or a java applet, once it is loaded, you can still work on the page but there is no data transfer.
    with a sniffer tool you could see the browser closing the connections.
    The default TCP idle timeout on ACE is 1 hour.
    Gilles.

  • IPS Tech Tip - "show tech" command part 2 - IPS dev team webinar

    Hi Folks,
    The IPS product management and development team would like to invite you to this 30-40 minute webinar followed by Q&A sessions. These will be recorded and put on this forum as well. We hope you can attend.
    -Robert
    Robert Albach invites you to attend a Web seminar using WebEx. This event requires registration.
    Topic: Cisco IPS Tech Tips - show tech part 2
    Host: Robert Albach
    This month's Cisco IPS Tech Tip will continue December's show tech command discussion. The show tech command holds a wealth of information regarding your IPS's performance and status. Cisco IPS development team members will continue to talk about what all this information means to you and then answers your questions.
    Date and Time:
    January 27, 2011 10:00 am, Central Standard Time (Chicago, GMT-06:00)
    To register for the online event
    1. Go to https://cisco.webex.com/ciscosales/onstage/g.php?d=202882129&t=a&EA=ralbach%40cisco.com&ET=85576c2dbfd6dca4b756de40b6728a2b&ETR=5d7e40b0e38f564be0a8bd55114369fc&RT=MiM3&p
    2. Click "Register".
    3. On the registration form, enter your information and then click "Submit".
    Once the host approves your registration, you will receive a confirmation email message with instructions on how to join the event.

    Sadly we did not get the recording done. The presentation and the example pcaps  however are on this forum now.
    -Robert

  • Cisco ACE - "show conn" command queries

    Hi all,
    i have some queries regarding the "show conn" command in Cisco ACE.
    Working Scenario:
    VIP : 10.10.10.1
    Server 1 : 10.10.20.1
    Server 2 : 10.10.20.2
    Client: 30.30.30.1
    When a client 30.30.30.1 initiates a connection to the VIP on 10.10.10.1, the ACE load balances it to Server 1, 10.10.20.1. Looking at the "show conn" table, it shows that Server 1 is replying back to the Client 30.30.30.1 through the ACE.
    Now, my question is when the ACE returns the traffic to the Client, should the Client be seeing the source IP coming from the VIP or Server 1? My understanding is that the Client should be seeing traffic returning from the VIP. But the show conn table does not seem to suggest so.
    show conn table
    conn-id    np dir proto vlan source                destination           state
    ----------+--+---+-----+----+---------------------+---------------------+------+
    1768       1  in  TCP   10   30.30.30.1:9221   10.10.10.1:80       ESTAB
    41         1  out TCP   52    10.10.20.1:80    30.30.30.1:9221   CLOSED

    Daniel,
    The client is expecting a response from the VIP otherwise there would be an asymmetrical routing problem and conns will never complete.
    The fact that you're seeing 30.30.30.1 as the destination address is just that the server is able to see client's IP address on the request, when your backend servers sends the reply back to the client this response is forced to go through the ACE, when the ACE looks at the packet it matches with a previously conn created on the flow table so it "NATs"  the reply so now the source of the packet is the VIP and destination is 30.30.30.1.
    This is a expected behavior as you're not using S-NAT on your network.
    HTH.
    Pablo

  • Show Dot11 Commands

    Hi all,
    Can somebody ,please, clarify for me what the command "show dot11 statistics client-traffic" shows to me? The output usually looks like:
    xxxx.xxxx.xxx pak in 24289 bytes in 5050182 pak out 32230 bytes out 35936358
    dup 47 decrpyt err 0 mic mismatch 0 mic miss 0
    tx retries 3455 data retries 3455 rts retries 0
    signal strength 62 signal quality N/A
    But is the units for signal strength are dBm or mW? And why the quality is N/A? What values are better ? 60 or 19 (for strength)? So if anybody can provide me with an explanation for the last 2 lines it would be great. By the way, do you know where on Cisco.com all the "show dot11" commands get explained?
    Cause, additional hard to understood output is "show dot11 associations" shows MACs "not related to any ssid" (how can it be in the first place?) or shows MACs which are do associated to (the only) broadcasted SSID but the IP is 0.0.0.0? Why and what does it mean?
    Thanks in advance,
    Alex.

    First of all thank you for answering my question. On the other hand, look - this was the first place for me to go on Cisco.com. Unfortunately (and this is the very problem itself), for some odd and mysterious reasons there is no clear explanation for those commands on this or any other page on Cisco.com. In fact, the only (!) explanation for "show dot11 statistics client-traffic" is "Use the show dot 11 statistics client-traffic privileged EXEC command to display the radio client traffic statistics".
    No single word about the output and it interpretation. That's strange as its sounds.
    The same goes for why there are Macs which are "not associated to any SSID" in "show dot11 associations".
    So, if anybody knows the answer for the previously posted questions - please post the answers. For my opinion it would be interesting for the whole community.

  • Right syntax of show conn command

    Good day!
    Please, help me with correct syntax of show conn command...
    I need to show all active tcp connections from inside to outside on port 60565...
    Thank you...!

    Hi,
    Well there are a lot of options.
    Below is the basic command
    show conn
    You can use the below commands to get more detailed information
    show conn long
    show conn detail
    You can show certain port connections with the command (with some added parameters)
    show conn detail port 60565
    Some variation of the below command might also be helpfull
    show local-host
    Use the "?" (question mark) after the "show local-host" to see what options you have. Same option naturally applies to any other command on the ASA in general.
    I would also suggest checking out the ASA Command Reference when you are unclear of the purpose of a certain command. They are listed in alphabetic order
    http://www.cisco.com/en/US/docs/security/asa/command-reference/cmdref.html
    - Jouni

  • Cisco IPS Tech Tips: 2010 Dec 16 - show tech commands

    Robert Albach invites you to attend a Web seminar using WebEx. This event requires registration.
    IPS Tech Tips are monthly webinars lasting approximately 30 minutes with question and answer to follow. This month’s event will focus on the “show tech” command and its potential relevance to your IPS operation.
    Topic: Cisco IPS Tech Tip 2010 Dec 16 - Show Tech
    Host: Robert Albach
    Date and Time:
    December 16, 2010 10:00 am, Central Standard Time (Chicago, GMT-06:00)
    To register for the online event
    1. Go to https://cisco.webex.com/ciscosales/onstage/g.php?d=205452108&t=a&EA=ralbach%40cisco.com&ET=72ce549014a807001ae666a6d82dcc7c&ETR=6ff5ff3ebf442ab68017b906c9ead1a7&RT=MiM3&p
    2. Click "Register".
    3. On the registration form, enter your information and then click "Submit".
    Once the host approves your registration, you will receive a confirmation email message with instructions on how to join the event.
    For assistance
    You can contact Robert Albach at:
    [email protected]
    http://www.webex.com
    IMPORTANT NOTICE: This WebEx service includes a feature that allows audio and any documents and other materials exchanged or viewed during the session to be recorded. By joining this session, you automatically consent to such recordings. If you do not consent to the recording, discuss your concerns with the meeting host prior to the start of the recording or do not join the session. Please note that any such recordings may be subject to discovery in the event of litigation.

    The recordings and the presentation slides are placed here on the Cisco Support Community. I think if you roll the threads back some you will see the prior month's Tech Tips (then called Tech Talks) posted.
    This one will be posted a few days after the event.
    -Robert

  • Weblogic 12c Servlet Response - Special characters show up as question mark

    My web app is running on Weblogic 12c (12.1.1) using WebWork + Hibernate. The program streams data (bytes making up a pdf) from a CLOB in an Oracle Database to the AsciiStream of the servlet output response. No exceptions are thrown, but the generated pdf contains blank pages. Comparing the bytes of the generated pdf, special characters are showing up as question marks.
    Some of the bytes read in from the database contain 8 bits (correct data), but the bytes that the servlet return contain only 7 (all bytes with 8 bits become "1111111"). The number of bytes returned from the servlet is correct.
    Code:
    //Response is HttpServletResponse
    response.setContentType("application/pdf");
    response.setHeader("Content-Disposition", "inline; filename=\"test.pdf\"");
    out = response.getOutputStream();
    byte[] buf = new byte[16 * 1024];
    InputStream in = clob.getAsciiStream();
    int size = -1;
    while ((size = in.read(buf)) != -1){
    // buf contains the correct data
    out.write(buf, 0, size);
    // other exception handling code, etc
    out.flush();
    out.close();
    "Correct" pdf byte example:
    10011100
    10011101
    1010111
    1001011
    1101111
    11011011
    Incorrect pdf byte example:
    111111
    111111
    1010111
    1001011
    1101111
    111111
    I have verified that the data read from the CLOB in the database IS correct. My guess is that the Weblogic server has some strange servlet settings that causes the bytes to be written to the servlet output stream incorrectly, or a character encoding issue. Any ideas?
    Edited by: 944705 on Jul 26, 2012 10:17 AM

    Solution found, I'll post the work around to those who might encounter the same problem.
    Somewhere in the layers of technology (webwork or weblogic I'd guess), the servlet response is encoded into UTF-8 regardless. The encoding in the database was ISO-8859-1. Sending ISO encoded bytes by UTF-8 caused the conflicting character codes (anything above 127) to show up as undefined.
    The fix is to decode the input byte array into ISO-8859 string, then encode that string into UTF-8, which can be send by Weblogic.
    isoConvert = new String(buf, "ISO-8859-1");
    out.write(isoConvert.getBytes("UTF-8"), 0, isoConvert.getBytes("UTF-8").length);

  • HT1752 My MacBook on startup shows file with question mark ,, what now?

    My Mac shows file with question mark, what now.

    Press the power button down to force a emergency use only hardware shutdown.
    Press and hold the Option/alt key on the built in keyboard, boot the machine.
    If MacintoshHD appears, select it and click the arrow, then in System Preferences > Startup Disk reset that. Done.
    Sometimes a NVRAM reset is required then the above done again.
    Folder with question mark issue
    ..Step by Step to fix your Mac
    If MacintoshHD doesn't appear, or if it boots to gray screen or other issues, then it's more complicated of a fix, but once inside OS X then reset the Startup Disk.
    Gray, Blue or White screen at boot, w/spinner/progress bar
    ..Step by Step to fix your Mac
    You might need this if you don't have a recent backup and your problem is software related, Disk Utiltiy can't fix the drive and recommends you backup, erase and install.
    .Create a data recovery/undelete external boot drive
    If Disk Utility + Hardware Test shows no boot drive, then you have a dead drive or cable, or Mac issue.
    My computer is not working, is my personal data lost?

  • Where is the "show duplicates" command in iTunes 11?

    I can't find the "show dupicates" command in iTunes 11 and I have a number I want to delete.

    https://discussions.apple.com/message/20438897?ac_cid=op123456#20438897

  • Clarification on the SHOW TOP command

    Does anyone know much about the Show Top command? I am trying to get specs on the bandwidth utilization of a port. When
    I do the Top command it tells me a percent of utilization. However it looks to be too low. I verified the util using a traffic generator test set and it has results of almost double the util. that the Top command stated. So my thoughts are that if the port is set for 100/Full then the Top stats for Util show only half Dux. Is this so??? I think that I need to double the Top results for util and that will be the true Util for the port. Can anyone verify this????

    you are kind of correct, that it will look like a half duplex utilization because process actually bundles the TX AND rx into the same counter and it also looks at the full duplex bandwidth when calculating the % utilization. So a GE port is really 2000Mbps full-duplex. so, from the traffic generator you are sending at line rate of 1 Gig, the TOP will see that as 50% utilization. Does that make sense. This is how I understand it.

  • "SHOW ALL" command in RMAN

    Hi
    I need to understand, what does RMAN use to read configuration info in case of No Recovery catalog.
    We all know that it read from Control file about backup information.
    But, when my database is in NOMOUNT mode, I connect to rman target /
    Then I run show all; command.
    It displays RMAN configuration, Where is this information stored?
    Any idea?
    Thanks in advance

    Hi,
    Did you compare the output of the <show all ;> commands in nomount and mount (or open) mode?
    In nomount you get the defaults :
    RMAN configuration parameters are:
    CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default
    CONFIGURE BACKUP OPTIMIZATION OFF; # default
    CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default
    CONFIGURE CONTROLFILE AUTOBACKUP OFF; # default
    CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default
    CONFIGURE DEVICE TYPE DISK PARALLELISM 1 BACKUP TYPE TO BACKUPSET; # default
    CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE MAXSETSIZE TO UNLIMITED; # default
    CONFIGURE ENCRYPTION FOR DATABASE OFF; # default
    CONFIGURE ENCRYPTION ALGORITHM 'AES128'; # default
    CONFIGURE ARCHIVELOG DELETION POLICY TO NONE; # default
    In mount mode you get the actual settings:
    using target database control file instead of recovery catalog
    RMAN configuration parameters are:
    CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default
    CONFIGURE BACKUP OPTIMIZATION OFF; # default
    CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default
    CONFIGURE CONTROLFILE AUTOBACKUP ON;
    CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default
    CONFIGURE DEVICE TYPE DISK PARALLELISM 1 BACKUP TYPE TO BACKUPSET; # default
    CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE CHANNEL DEVICE TYPE DISK FORMAT '/backup/DB10G/%U';
    CONFIGURE MAXSETSIZE TO UNLIMITED; # default
    CONFIGURE ENCRYPTION FOR DATABASE OFF; # default
    CONFIGURE ENCRYPTION ALGORITHM 'AES128'; # default
    CONFIGURE ARCHIVELOG DELETION POLICY TO NONE; # default
    CONFIGURE SNAPSHOT CONTROLFILE NAME TO '/u01/appl/ora102/product/10.2.0/dbs/snapcf_DB10G.f'; # default
    Regards,
    Tycho

  • "Show Diag" command on 3750 IOS 12.1(19)EA1c

    Hi,
    I'm trying to run the "show diag" command on a 3750 with IOS 12.1(19)EA1c and the command is not recongised. I'm in enable mode and cannot find an equivalent command.
    I need to do this as the Cisco Software Advisor is asking for a copy of the output.
    Any pointers gladly recived.
    Cheers,
    Gareth

    Hi,
    The tool you need is the "Feature Navigator" which can be found here:
    http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp
    Launch the tool by selecting "Search by Feature"
    Searching for "802.1x" gives a list of all those features, select "Wake on LAN support" (for example) and click add, then continue.
    The platform box gives a list of all platforms that support the feature, so select 3750.
    The lowest feature set is IP Base (you might have something else but worth checking this first as it's the lowest feature set)
    This gives a list of about 20 versions of software which support the feature so you can see you need at least 12.2(25)SEC to get this particular feature.
    The process is pretty much the same for any feature. If you know the actual command you need (in this case it's "dot1x control-direction" then you could get the same info by just looking it up in the latest command reference as that will also tell you when the feature first appeared.
    Finally, if you just want a list of features for a particular release then use the same link and choose search by platform, but be aware this will be a *long* list.
    HTH
    Andrew.

  • Show log command on 4500

    Dear all,
    If I do a show log command on switch it starts showing logs which are several months old.
    How can I filter those to show only last month log -like pipe is one way or anything to be set on switch.
    Also if I do sh log and if it starts showing logs for last 6 months then i can't break it and hence might b causing overhead.
    Please advise.
    Sent from Cisco Technical Support iPhone App

    Hi,
    I believe there is no other options to view the logs options apart from using the pipe filter.
    or we can tune the logging level in such a way to capture only the interested message by applying the below options.
    There are eight levels of logging. If you specify a particular level of logging for console logging, for example the messages of that level and of the higher levels (numerically lower) are forwarded to the console.
    Level
    Logging Message
    0
    Emergencies
    1
    Alerts
    2
    Critical
    3
    Errors
    4
    Warnings
    5
    Notifications
    6
    Informational
    7
    Debugging
    Router(config)# logging monitor error
    Now let us discuss the anatomy of the logging messages. Each message is associated with one of the eight levels of logging, which is referred to as the severity of the message
    Level Name
    Severity
    Description
    Syslog Definition
    Emergencies
    0
    System unusable
    LOG_EMERG
    Alerts
    1
    Immediate action needed
    LOG_ALERT
    Critical
    2
    Critical conditions
    LOG_CRIT
    Errors
    3
    Error conditions
    LOG_ERR
    Warnings
    4
    Warning conditions
    LOG_WARNING
    Notifications
    5
    Normal significant conditions
    LOG_NOTICE
    Informational
    6
    Informational messages only
    LOG_INFO
    Debugging
    7
    Debugging messages
    LOG_DEBUG
    Hope this helps
    Cheers
    Somu
    Rate helpful posts

Maybe you are looking for

  • Multiple pages in smartform

    hi all i hav a following prob i m printing data of one internal table in my smartform and this internal table contains only one record now i want to know, if there are 10 different record in my smartform how can i print these 10 records on diferent 1

  • ICal showing current date on the dock

    I have Leopard and the iCal icon on my dock shows the current date, whether or not the application is open, whether or not I shut down the computer. Another person in the office, with Panther, has iCal on her dock but the date does not update each da

  • Lost the thumbnail of NEF files in open on a new Windows 7 system

    I just built a new system with windows 7x64 over an Intel i7.  Very fast and super easy to setup including a lot of old programs like Word Perfect and Lotus.  However on the new Elements 8 version in the open screen I no longer have the thumbnail of

  • Unable to remove Messenger App

    Hallo All, I've sifted through the forums and tried the remove through menu options but it doesn't seem to work. I have a Nokia 5700 bought off of Amazon.com, I am in an area that apparently isn't supported by the version 1 of the MSN Messenger clien

  • Victor4018

    Mi iPad tiene no tiene sonido, y sale efectos sonoro, ya lo restaure en la mañana funciona pero en la noche, se preséntale problema