Export Alarm/Event Data from Cisco Prime Infrastructure 2.1+

I am looking to export the current Alarm data for my CPI 2.1 deployment. This so we can go through and organize the data in excel and better configure alarm/events....currently getting 3k a week and we need to tighten what constitutes a critical event and some other parameters. We need the raw data in csv format so do some analytics on it. 
My issue is there is no reference in the admin/user guides to export alarm data. Also no button or option within the GUI. How can this be accomplished?

The supported method going forward is to have external tools interact with Prime Infrastructure via the REST API.
See the documentation on your Prime server for "GET Alarms":
     https://<your server address>/webacs/api/v1/data/Alarms?_docs
...or you can download a copy of the API Reference here.

Similar Messages

  • Change Interface availability threshold from Cisco Prime Infrastructure 2.0

    Dear Community,
    I’m working in Cisco Prime Infrastructure 2.0 and I’m having the following problem:
    I want to monitor the interfaces availability from all the devices of my network. But only makes sense send an email notification  for the most critical interfaces. I don´t want to receive an email notification every time anyone unplugs the network wire.
    How can I achieve this?
    I already tried to change the interface availability threshold from the Interface Health Threshold Template, but this one isn´t available to configure.
    The idea was to change the severity of the alarm so I could distinguish what type of alarm would send email notification.
    I also created a Custom SNMP Template that gets the ifOperStatus using the MIB IF-MIB. This also didn’t work because Prime Infrastructure doesn’t allow me to define thresholds to a Custom SNMP Template.
    Without threshold, no alarm, without no alarm, no email notification!
    Can you help?
    Regards,
    Daniel CJ

    Only on the HA pair which would be the secondary.
    High Availability (HA) RTU: If Cisco Prime Infrastructure is deployed in a high availability configuration with one primary and one secondary instance in an HA pair, then an HA RTU is required. You only need to purchase a single set of the regular licenses (for example, Base, Lifecycle, and so on) for the primary instance.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Collecting logs from Cisco Prime Infrastructure

    Hi ,
    I am currently working in integrating  Cisco Prime Infrastruture with the siem tool Qradar.
    Can any one help me out in below issues:
    1)How and where is the log stored in Cisco Prime.?
    2)Does the logs contains the logs of the devices that Cisco Prime manages?
    3)Is there any way to sent out the logs from Cisco Prime to a third party device.?

    Hi,
    1)How and where is the log stored in Cisco Prime.?
    /opt/CSCOlumnos/logs
    2)Does the logs contains the logs of the devices that Cisco Prime manages?
    AFAIK,
    In the prime infrastructure Syslogs are directly read from udp port 514 and then filtered
    , the non SEV1 and SEV2 syslogs will be dropped and will not be entered into db . The
    syslog messages will not be saved into log files .
    Till now PI support only SEV 0,1 and 2 syslog.
    3)Is there any way to sent out the logs from Cisco Prime to a third party device.?
    unfortunately , this feature is not there in PI so far.
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ****

  • Upgrade from Cisco Prime infrastructure verion 2.0 to 2.1

    Request you all to please let me know if i have to install point patch before upgrading the cisco prime infrastructure 2.0 to 2.1.

    After moving to 2.1, there is a 2.1.1 point patch currently available.
    You should install that and the latest device package (4.0 as of this posting).
    As always, the Release Notes are the best place to check the current available updates.

  • Cisco Prime Infrastructure 2.0 release date

    What is the release date for Cisco Prime Infrastructure ?  What are the improvement from 1.2 to 2.0 ?
    thanks
    Morgan                  

    It's currently due out 31 August 2013.
    I haven't seen the final release notes but it will incorporate a lot of the features currently in LMS 4.2 for wired infrastructure management that are currently missing in PI 1.x.
    I have heard it will not include Topology or template compliance reports and jobs at 2.0 - those features did not make the development cutoff date for 2.0 but they are projected for 2.1.

  • Cisco Prime Infrastructure 2.1 Custom Reports

    Hi, I need to generate a custom Guest User report from Cisco Prime Infrastructure 2.1. It needs to have a couple more fields added to the existing "Guest User Association" report.
    Is it possible to connect to the Cisco Prime Infrastructure Database and Generate custom reports? Is there any documentation on this?
    Thanks

    Programmatic access to PI's data is via the REST API.
    Check the help menu on your PI server to see documentation regarding the supported tables and fields that can be queried via that method.

  • Can i install Cisco prime infrastructure 1.3 with 1.1 license.

    Can i install Cisco prime infrastructure 1.3 with 1.1 license.To be more precise it will be fresh installation
    but the licenses I have is of 1.1.As per my overview from Cisco prime Infrastructure 1.2 NCS and NCS(WAN)
    has been bundled into one service.But both were seperate entities in Cisco Prime Infrastructure 1.1.

    It doesn't matter if you want to make a new installation or an upgrade. The questions is the license.
    The base license is necessary for network management nodes (devices). But to get updates for your system you need the additional to your Base License the Lifecycle License (which can be ordered for 12, 24 or 36 months).
    The Lifycycle License is also based on the number of managed devices. In your case 50 devices. So you have that License - congratulations!
    Otherwise order the Lifecycle License for 50 devices (L-N-PI12-50-M). This generates CON-PSUU-PI12LF50 for 12 months, list price 414,81$. Then Upgrade from 1.1 to 1.2, patch the system and upgrade to 1.3.
    Have fun,
    Chris

  • CISCO PRIME INFRASTRUCTURE NETFLOW TRAFFIC REPORT

    Hi,
    I have a report from cisco prime infrastructure, that I don´t know how to interpret,  because the fields in the report I don´t know what´s mean them,  the difference between them, what are optimal values, the worse values, etc.
    Can someone help me with this
    The name of the report is: FLEX NETFLOW TRAFFIC TQPQ
    The fields that I don´t know what are:

    hello,
    I also have a problem concerning the interpretation of the report that I got. if anyone knows how Cisco gets its premium reports, it will help me!

  • Upgradding Prime Infrastructure version 1.2 and LMS 4.x to Cisco Prime Infrastructure 2.0

    Hello,
    A customer currently have 2,500 Cisco Prime Infrastructure Lifecycle device license using Prime Infrastructure version 1.2 and LMS 4.x. the customer wants to upgrade to Cisco Prime Infrastructure 2.0.
    Does anyone know if it is possible to upgrade to version 2.0 without additional cost? the licenses from
    Cisco Prime Infrastructure 1.2 has to be upgraded or we need only to rehost the VUDI.
    Also could be possible to upgrade LMS 4.x to Cisco Prime Infrastructure 2.0?
    thanks!

    The two features you mention are two big missing ones. Another is full syslog capability. I don't believe CiscoView or day one support via package updates is included either.
    Another is less tangible - the depth of experience and documentation available for LMS vs. Prime Infrastructure (particularly the wired management features). I agree for wireless PI 2.0 looks good. Some new features are coming for wired that look promising but they are new as of PI 2.0 so I'm taking a wait and see on them.
    I hope to get 2.0 up in my lab in the next week or so and will hope to be pleasantly surprised but that's seldom the case with a major new release.

  • Cisco Prime Infrastructure and no new events / alarms since update to 2.2.1

    Hello,
    I have upgraded our Cisco Prime Infrastructure from version 2.1 to 2.2.1 (with a backup and restore). We have round about 700 APs and three 5208 Controller. So far everything seems to work really fine. The only problem is that there are no new alarms/events under "Monitor", "Alarms and Events".
    The last entries (events and alarms) are dated before the upgrade. Other informations (like client counts for example) are correct.
    Is there a known bug related to my problem? Can anybody help?
    Thanks

    I have done some research:
    I see the following problems in the log-package (downloaded from Prime):
    ===
    <msg time='2015-04-07T12:10:50.620+02:00' org_id='oracle' comp_id='rdbms'
     client_id='' type='UNKNOWN' level='16'
     host_id='rzprime' host_addr='xxx.xxx.xxx.xxx' module='JDBC Thin Client'
     pid='9499'>
     <txt>ORA-1652: unable to extend temp segment by 128 in tablespace                 TS_EVENTS 
     </txt>
    </msg>
    <msg time='2015-04-07T12:10:50.727+02:00' org_id='oracle' comp_id='rdbms'
     client_id='' type='UNKNOWN' level='16'
     host_id='rzprime' host_addr='xxx.xxx.xxx.xxx' module='JDBC Thin Client'
     pid='15177'>
     <txt>ORA-1652: unable to extend temp segment by 128 in tablespace                 TS_EVENTS 
     </txt>
    </msg>
    ===
    I think that there is a problem with a too small tablespace. But I can´t fix that. Anybody? ;)

  • Cisco Prime Infrastructure 1.4 SNMP Traps are not converted into Alarms

    Hi everybody,
    I just configured SNMP Traps on a Cisco Catalyst 3750-x to send to our Cisco Prime Infrastructure 1.4 Appliance.
    Now I forced the Switch to send some traps (Power off a Power Supply, Interface errdisable). The only events I see in Alarms & Events on PI is the same information message everytime:
    Configuration management event has been recorded in ccmHistoryEventTable.
    I think the forced traps should be converted into alarms? Why can't I see them?
    Thanks,
    Marc

    Ok, I started debugging as you said. I get the following output:
    Mar 13 09:28:13.711: SNMP: V2 Trap, reqid 11689, errstat 0, erridx 0
     sysUpTime.0 = 198609846
     snmpTrapOID.0 = ciscoSyslogMIB.2.0.1
     clogHistoryEntry.2.1688 = PM
     clogHistoryEntry.3.1688 = 5
     clogHistoryEntry.4.1688 = ERR_RECOVER
     clogHistoryEntry.5.1688 = Attempting to recover from bpduguard err-disable state on Gi1/0/13
     clogHistoryEntry.6.1688 = 198609844
    Mar 13 09:28:13.737: SNMP: Queuing packet to xx.xx.xx.xx
    Looks like the Switch is sending SNMP Traps from the ciscoSyslogMIB. Is this why PI can't show the Traps and convert it into a alarm?
    After this test I configured logging (syslog) to the PI. Now the errors are showed but still not converted into alarms. I just want to be notified by email when such errors occurs.
    Thanks,
    Marc

  • Cisco Prime Infrastructure 2.0 - no traps/info are pushed from devices

    Good evening,
    I have setup Cisco Prime Infrastructure 2.0 and,  though I have added manually my 4 network cores as devices without any  problem, I can't get a single trap or a single SNMP information to be  pushed into my Cisco Prime Infra.
    Here is my SNMP config on my core :
    snmp-server user *edited* *edited* v3
    snmp-server  group *edited* v3 noauth notify  *tv.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF0F
    snmp-server community *edited* RO
    snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
    snmp-server enable traps flowmon
    snmp-server enable traps transceiver all
    snmp-server enable traps call-home message-send-fail server-fail
    snmp-server enable traps tty
    snmp-server enable traps rf
    snmp-server enable traps memory
    snmp-server enable traps cpu_threshold
    snmp-server enable traps eigrp
    snmp-server enable traps ospf state-change
    snmp-server enable traps ospf errors
    snmp-server enable traps ospf retransmit
    snmp-server enable traps ospf lsa
    snmp-server enable traps ospf cisco-specific state-change nssa-trans-change
    snmp-server enable traps ospf cisco-specific state-change shamlink interface
    snmp-server enable traps ospf cisco-specific state-change shamlink neighbor
    snmp-server enable traps ospf cisco-specific errors
    snmp-server enable traps ospf cisco-specific retransmit
    snmp-server enable traps ospf cisco-specific lsa
    snmp-server enable traps flex-links status
    snmp-server enable traps fru-ctrl
    snmp-server enable traps entity
    snmp-server enable traps ethernet cfm cc mep-up mep-down cross-connect loop config
    snmp-server enable traps ethernet cfm crosscheck mep-missing mep-unknown service-up
    snmp-server enable traps ether-oam
    snmp-server enable traps aaa_server
    snmp-server enable traps flash insertion removal
    snmp-server enable traps l2tc threshold sys-threshold
    snmp-server enable traps power-ethernet police
    snmp-server enable traps rep
    snmp-server enable traps vswitch dual-active vsl
    snmp-server enable traps udld link-fail-rpt status-change
    snmp-server enable traps vtp
    snmp-server enable traps vlancreate
    snmp-server enable traps vlandelete
    snmp-server enable traps auth-framework sec-violation
    snmp-server enable traps dot1x auth-fail-vlan guest-vlan no-auth-fail-vlan no-guest-vlan
    snmp-server enable traps envmon fan shutdown supply temperature status
    snmp-server enable traps entity-diag boot-up-fail hm-test-recover hm-thresh-reached scheduled-test-fail
    snmp-server enable traps port-security
    snmp-server enable traps ethernet evc status create delete
    snmp-server enable traps energywise
    snmp-server enable traps ipsla
    snmp-server enable traps vstack
    snmp-server enable traps bfd
    snmp-server enable traps bgp
    snmp-server enable traps bulkstat collection transfer
    snmp-server enable traps cef resource-failure peer-state-change peer-fib-state-change inconsistency
    snmp-server enable traps config-copy
    snmp-server enable traps config
    snmp-server enable traps config-ctid
    snmp-server enable traps event-manager
    snmp-server enable traps hsrp
    snmp-server enable traps ipmulticast
    snmp-server enable traps isis
    snmp-server enable traps msdp
    snmp-server enable traps pim neighbor-change rp-mapping-change invalid-pim-message
    snmp-server enable traps bridge newroot topologychange
    snmp-server enable traps stpx inconsistency root-inconsistency loop-inconsistency
    snmp-server enable traps syslog
    snmp-server enable traps isakmp policy add
    snmp-server enable traps isakmp policy delete
    snmp-server enable traps isakmp tunnel start
    snmp-server enable traps isakmp tunnel stop
    snmp-server enable traps ipsec cryptomap add
    snmp-server enable traps ipsec cryptomap delete
    snmp-server enable traps ipsec cryptomap attach
    snmp-server enable traps ipsec cryptomap detach
    snmp-server enable traps ipsec tunnel start
    snmp-server enable traps ipsec tunnel stop
    snmp-server enable traps ipsec too-many-sas
    snmp-server enable traps errdisable
    snmp-server enable traps ethernet cfm alarm
    snmp-server enable traps vlan-membership
    snmp-server enable traps mac-notification change move threshold
    snmp-server enable traps vrfmib vrf-up vrf-down vnet-trunk-up vnet-trunk-down
    snmp-server host *ip-address-edited* version 3 noauth *edited*
    Basically all traps are enabled but absolutely nothing is showing up in my Prime Infra except that my 4 devices are "Reachable".
    Here is a show snmp on the same device :
    sh snmp
    Chassis: *S/N Edited*
    38554534 SNMP packets input
        0 Bad SNMP version errors
        14 Unknown community name
        0 Illegal operation for community name supplied
        0 Encoding errors
        38453185 Number of requested variables
        0 Number of altered variables
        17790703 Get-request PDUs
        20583581 Get-next PDUs
        0 Set-request PDUs
        0 Input queue packet drops (Maximum queue size 1000)
    38490708 SNMP packets output
        0 Too big errors (Maximum packet size 1500)
        0 No such name errors
        0 Bad values errors
        0 General errors
        38371069 Response PDUs
        13 Trap PDUs
    SNMP global trap: enabled
    SNMP agent enabled
    SNMP logging: enabled
        Logging to *edited*, 0/10, 13 sent, 0 dropped.
    Can anyone point out what is wrong or missing in my configuration? I can't seem to single it out myself.
    Thanks
    Jeremy

    Hi Jeremy,
    SNMP traps are shown in the events and alerts section of PI.
    SNMP config looks fine. Can  you run the SNMP debug (debug snmp packets ) .check the logs and see if the device is actually sending the TRAPS to the PI server.
    Thanks-
    Afroz
    [Do rate the useful post]
    ****Ratings Encourages Contributors ****

  • Cisco Prime Infrastructure 1.2 - web browser freezes when managing rogue APs alarms

    Hello all,
    has anybody faced a freezing problem when you click in Cisco Prime Infrastructure 1.2 down on alarm bar and then to Rogue AP alarms and then try to add an annotitation or change a rogue alarm to Friendly?
    I tried it on different PC, different browsers (Firefox 14.0.1. Chrome ...) and the problem is still there.
    Has anybody an idea?
    Thanks.
    Regards
    Karel

    I just tried it from my lab VM and had no problems.  I use Chrome and the browser does sometimes not refresh for a while but that is just when I start to  click around.
    Thanks,
    Scott
    Help out other by using the rating system and marking answered questions as "Answered"

  • Cisco Prime Infrastructure 2.0 Alarms (switch port down)

    We have a cisco Prime Infrastructure 2.0 managing switches, routers and AP.
    By default, when a port of a switch goes down, the cisco Prime Infrastructre generates a Critical Alarm for that. (this is a problem, because every phone of laptop disconnection will generate a critical alarm for me)
    I found out that if we go to Administration --> Alarm Severity --> Link down, I can change the Alarm from Critical to another type of alarm.(ex: warning)
    The problem is that I want to keep the Critical Alarm for my Uplinks ports and for some important switch ports, and I would like to make the alarm as warning for the normal user ports.
    I know that I can create Port Groupping and add ports to each group and apply monitoring templates on those groups. But This couldn't Help me solving my alarm problem.
    So I just need to know how to manage the alarms severity for each group of ports.
    Thank you

    Hi,
    Same problem here.
    I am using Cisco Prime Infrastructure 2.0 (evaluation version for 60 days). I want to deploy port monitoring for my trunk ports between switches and some other important ports e.g. servers. Basically I want to get alarms when these ports are down, there are errors on ports and etc.
    So in Design>Port Grouping I created User Defined group with important ports. In Deploy>Monitoring Deployment I selected Interface Health (default)>Deploy selected Port Groups and when selected port group I created.
    Now the rule shows Deployed: Yes and Status: Active. After that I just pulled out one port which was in monitored group, waited 5min as it is set in Interface Health (default) template, and nothing happened, and worse, alarms started to show up of other ports where regular users are connected (computers was turned off), which I do not want to see at all. I tried redeploy template, I even created my own template but still no desired result.
    Any suggestions how to make port monitoring work?

  • Including Interface Description in Cisco PRime Infrastructure Alarm Message

    Hi all,
    i succesfully configured a Cisco Prime Infrastructure 2.1 applliance to display an alarm and to send me an e-mail when switch uplink ports goes down.
    The text displayed in alarm message is :
    port 'interface_id' is down on device 'device_ip_address'
    I'd like to include in this text also the interface description so the text will display :
    port 'interface_id'  'interface_descriprion' is down on device 'device_ip_address' 
    Is this possible?
    Thankyou in advance

    Hi,
    i followed these steps :
    SWITCH SIDE
    - configured Prime Infrastructure as snmp-server host;
    - enabled snmp-traps for linkup and linkdown events globally;
    - disabled snmp-traps for linkup and linkdown on non relevant interfaces using the no snmp trap link-status command
    PRIME INFRASTRUCTURE SIDE
    - under "Deploy/Monitor Deployment" i deployed template "Interface Health"  for all the interested switches
    -  under "Administration/System Settings/Mail Server Configuration" configured my internal SMTP server to make Prime Infrastructure able to send e-mails
    - under "Operate/Alarms & Events" click on "Email Notifications" , then on "Switches and Hubs"
       - check the "critical" box ,  insert the destination e-mail address into the "To" field then click "Save"
     -  check the "switches and Hubs" box and then click Save
    As i know is possible to avoid to configure every single not-interesting port on the switches with "no snmp trap link-status" command (it's a bit annoying when you have tens of switches), using Port Grouping configuration on PI but i tried it without success.
    Hope this helps.
    Best Regards,

Maybe you are looking for