LMS 4.2.3 Unidentified Trap Generic Trap:6 Specific Trap:1 EnterpriseOid:.1.3.6.1.4.1.9.9.41.2
Hi All,
We are seeing unidentified traps continuously on the LMS 4.2.3.
Unidentified Trap Generic Trap:6 Specific Trap:1 EnterpriseOid:.1.3.6.1.4.1.9.9.41.2
What are these traps and how to avoid the same. as these traps are coming from all the devices in the network.
Regards,
Channa
Hello Channa,
the 'Unidentified Trap' Alerts that you provided :
NOTIFICATION ORIGINATOR = Fault Management Module
The EnterpriseOid in this Alert tells me that this is the cisco syslog trap :
.1.3.6.1.4.1.9.9.41.2.0.1
clogMessageGenerated OBJECT-TYPE
-- FROM CISCO-SYSLOG-MIB
TRAP
VARBINDS { clogHistFacility, clogHistSeverity,
clogHistMsgName, clogHistMsgText, clogHistTimestamp }
DESCRIPTION "When a syslog message is generated by the device a
clogMessageGenerated notification is sent. The
sending of these notifications can be enabled/disabled
via the clogNotificationsEnabled object."
This tells me that you have configured this device with 'snmp-server enable trap syslog' , which means that every syslog message that is generated on the device will also be sent as an snmp trap.
Is there a specific reason why the sending of syslog messages as an snmp trap has been enabled on this device (and others) ?
To stop LMS generating an Alert for every syslog message I would recommend that you disable this device from sending syslog traps to LMS. If there are multiple devices sending syslog traps to LMS then the sending of these traps to LMS should be disabled on all such devices.
Thanks-
Afroz
***Ratings Encourages Contributors ****
Similar Messages
-
LMS 4.2.1 - unidentified traps in fault monitor
MY LMS, under fault monitor, shows many messages (actually hundreds), "Unidentified Trap Generic Trap:6 Specific Target:1 EnterpriseOid:.1.3.6.1.4.1.9.9.41.2"
This OID leads me down the CISCO-SYSLOG-MIB.my, to ciscoSyslogMIBNotification.
vestigaiton looks like this MIB actually doesn't do anything (other than generate a fault message on LMS).
Anyone have any ideas how I can get rid of this fault in LMS, such as adding the CISCO-SYSLOG-MIB.my to my LMS so that it can at least identify the OID being sent.
Along these lines, I have downloaded the above referenced MIB, and have tried in LMS to upload it, but the "upload MIB" functionality ONLY allows the loading of MIBS which already exist on LMS (only choose a server side path).
Any ideas would be aprpeciated.
JoeHi Joe,
check the below link for more results on Unidentified traps:
http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_device_fault_manager/3.1
/user/guide/TrapFwd.html#wpxref57860
It looks like "snmp-server enable traps syslog" is enabled on your devices, and this will appears as Unidentified trap , you can stop this by change the configuration on the Device , or disable the "InformAlarm" from the notification Group under : Admin > Network > Notification and Action Settings > Fault Notification Group From the following Link you can check the traps that will generate "INFORM ALARM" event :
I hope this will help
Thanks-
Afroz -
Trap syntax error in trap-schedule.dat alert; possibly SMC related
Receiving many ID xxxxxx daemon.alert events every hour. The message is:
[ID xxxxxx daemon.alert] syslog Nov 10 14:00:10 trap syntax error in trap-schedule.dat(200) at token '???'
followed immediately (same timestamp) with:
[ID yyyyyy daemon.alert] syslog Nov 10 14:00:10 trap *** aborting execution ***
I coudn't find anything on the web specifically for this message but several hits that looked similar seemed to indicate that this might be a problem in SMC. If it is not I apologize in advance.
System is an ldom:
Solaris 10;
SunOS clsol8 5.10 Generic_127127-11 sun4v sparc SUNW,T5140
Current situation is:
# /opt/SUNWsymon/sbin/es-validate
This script will help you in validation of Sun (TM) Management Center.
Validation Tool Version : 4.0
Host name : clsol8
Number of CPUs : 24
Platform : SUNW,T5140
Operating System : SunOS 5.10
Memory size : 2048 Megabytes
Swap space : 595480k used, 3727296k available
JAVA VERSION : "1.5.0_14"
Sun Management Center Production Environment Installation.
Following layers are installed : SERVER, AGENT, CONSOLE
Installation location : /opt/SUNWsymon
Sun Management Center installation status:
PRODUCT : Production Environment
INSTALLATION STATUS : Setup.
DATABASE SETUP : Setup.
COMPLETELY INSTALLED PACKAGES : SUNWescom,SUNWesbui,SUNWesbuh,SUNWenesi,
: SUNWesdb,SUNWesagt,SUNWessrv,SUNWessa,
: SUNWesjp,SUNWesaxp,SUNWesse,SUNWesclt,
: SUNWesjrm,SUNWmeta,SUNWenesf,SUNWesmdr,
: SUNWesgui,SUNWesweb,SUNWessvc,SUNWesasc,
: SUNWescix,SUNWsuagt,SUNWsusrv,SUNWesval,
: SUNWesmc,SUNWessms,SUNWessdv,SUNWescdv,
: SUNWlgsmc,SUNWeslac,SUNWesodbc,SUNWesmib,
: SUNWesken,SUNWesmod,SUNWesae,SUNWesaem,
: SUNWesmcp,SUNWesafm,SUNWescon,SUNWsucon,
: SUNWescli,SUNWesclb
<NOTE: I had to cut out a bunch of installed components to hit character limit>
Sun Management Center Add-Ons and Versions:
PRODUCT VERSION
Production Environment 4.0
Advanced System Monitoring 4.0_Build15
Sun Fire Entry-Level Midrange S 3.5-v6
Service Availability Manager 4.0_Build15
Performance Reporting Manager 4.0_Build15
Solaris Container Manager 4.0_Build15
Sun Fire Midrange Systems Platf 3.5-v6
System Reliability Manager 4.0_Build15
Sun Management Center Integrati 4.0_Build15
Workgroup Server 3.6
Generic X86/X64 Config Reader 4.0_Build15
Sun Management Center Patch installation details:
No Sun Management Center patch is installed.
Sun Management Center disk-space consumption:
PRODUCT APPROXIMATE DISK SPACE CONSUMED
Production Environment : 54452 kB
Advanced System Monitoring : 2391 kB
Sun Fire Entry-Level Midrange S : 1738 kB
Service Availability Manager : 1838 kB
Performance Reporting Manager : 3371 kB
Solaris Container Manager : 3688 kB
Sun Fire Midrange Systems Platf : 3270 kB
System Reliability Manager : 970 kB
Sun Management Center Integrati : 540 kB
Workgroup Server : 3707 kB
Generic X86/X64 Config Reader : 608 kB
TOTAL : 76573 kB
Database is located at : /var/opt/SUNWsymon/db/data/SunMC
Free space available on this partition is : 6493142 kB
Following locales are installed :
Information about upgrade from old versions is not available.
Sun Management Center Ports:
SUNMC COMPONENT PORT_ID
agent service 1161
trap service 162
event service 163
topology service 164
cfgserver service 165
cstservice service 167
metadata service 168
platform service 166
grouping service 5600
rmi service 2099
webserver_HTTP service 8080
webserver_HTTPS service 8443
You are currently running SNMPDX.
Sun Management Center Server Hosts definitions in domain-config.x:
SUNMC COMPONENT SERVER_HOST
agent service clsol8
trap service clsol8
event service clsol8
topology service clsol8
cfgserver service clsol8
cstservice service clsol8
metadata service clsol8
platform service clsol8
Sun Management Center Processes:
SUNMC SERVICE STATUS
Java Server Running.
Database services Not Running.
Grouping service Running.
Event-handler service Running.
Topology service Not Running.
Trap-handler service Not Running.
Configuration service Running.
CST service Not Running.
Metadata Services Running.
Hardware service Not Running.
Web server Running.
Sun Management Center Agent Running.
Platform Agent Not Running.
Privilege level for Sun Management Center users :
CATEGORY USERS
esadm : smcadmin
esdomadm : smcadmin
esops :
ALL USERS : smcadmin
server is local host
Web server package is installed correctly.
Web Server is up and responding.
Web Server servlet engine is up and responding.
I have also read that patching SMC has caused problems for some people so I don't really want to try that until I get some feedback.Hi Mike,
Tried your suggestion to rename the .dat and let SMC recreate it but I can't get the SMC database service to launch. So it looks like I am having trouble with the database. Any suggestions?
To back up, you nailed it with the loss of power - we lost both power supplies on a Sunday night with no warning and nothing in /var/adm/messages (since we send them to a loghost.) It was determined that chips within each power supply in the T5140 failed. So we replaced both power supplies and fired the server up. That is when we started getting the trap errors and only those two errors on clsol8.
I did check http://sun.com/msg/SMF-8000-KS but am not sure how that helps.
What I tried:
On clsol8 as root:
# cd /opt/SUNWsymon/sbin
# ls
{db-memconfig.sh es-details es-imagetool es-setup
db-start es-device es-inst es-start
db-stop es-dt es-keys.sh es-stop
es-apps es-gui-imagetool es-lic es-tool
es-backup es-guiinst es-load-default es-trapdest
es-chelp es-guisetup es-makeagent es-uninst
es-cli es-guistart es-platform es-validate
es-common.sh es-guistop es-restore esmultiip
es-config es-guiuninst es-run ports.config}
# ./es-stop -A
{Stopping metadata component
Stopping cfgserver component
Stopping topology component
Stopping event component
Stopping grouping service
Stopping trap component
Stopping java server
Stopping webserver
Stopping agent component
Stopping platform component}
<attempting Mike's solution suggestion>
# cd /var/opt/SUNWsymon/cfg
# ls
trap-schedule.dat
# mv trap-schedule.dat trap-schedule.dat.maybeCorrupted
# /opt/SUNWsymon/sbin/es-start -Ac
{Some of the SunMC services are in maintenace state.
Please check the corresponding SMF service log in /var/svc/log directory.
Please disable the services in maintenance state and re-start the services again.}
# svcs -vx
svc:/application/management/sunmcdatabase:default (SunMC database service)
State: maintenance since November 6, 2009 3:50:51 PM CST
Reason: Start method exited with $SMF_EXIT_ERR_FATAL.
See: http://sun.com/msg/SMF-8000-KS
See: /var/svc/log/application-management-sunmcdatabase:default.log
Impact: This service is not running.
svc:/application/management/sunmcwebserver:default (SunMC webserver service)
State: maintenance since November 12, 2009 2:45:50 PM CST
Reason: Start method failed repeatedly, last exited with status 103.
See: http://sun.com/msg/SMF-8000-KS
See: /var/svc/log/application-management-sunmcwebserver:default.log
Impact: This service is not running.}
# svcadm disable sunmcdatabase
# svcadm disable sunmcwebserver
# svcs -vx
# svcadm enable sunmcdatabase
# svcadm enable sunmcwebserver
# /opt/SUNWsymon/sbin/es-start -Ac
{Failed to successfully perform Database Startup.}
# svcs -vx
svc:/application/management/sunmcdatabase:default (SunMC database service)
State: maintenance since November 12, 2009 2:49:50 PM CST
Reason: Start method exited with $SMF_EXIT_ERR_FATAL.
See: http://sun.com/msg/SMF-8000-KS
See: /var/svc/log/application-management-sunmcdatabase:default.log
Impact: This service is not running.}
# cd /
# svcadm disable sunmcdatabase
# shutdown -y -g0 -i6
(after reboot, I logged into clsol8 and su'd to root)
# svcs -xv
svc:/application/management/sunmcdatabase:default (SunMC database service)
State: disabled since November 12, 2009 3:02:11 PM CST
Reason: Disabled by an administrator.
See: http://sun.com/msg/SMF-8000-05
Impact: 1 dependent service is not running:
svc:/application/management/sunmctopology:default}
# svcadm enable sunmcdatabase
# svcadm disable sunmcdatabase
# svcadm clear sunmcdatabase
svcadm: Instance "svc:/application/management/sunmcdatabase:default" is not in a maintenance or degraded state.
# svcadm refresh sunmcdatabase
# svcadm enable sunmcdatabase
# svcs -xv
svc:/application/management/sunmcdatabase:default (SunMC database service)
State: offline since November 12, 2009 3:09:25 PM CST
Reason: Start method is running.
See: http://sun.com/msg/SMF-8000-C4
See: /var/svc/log/application-management-sunmcdatabase:default.log
Impact: 1 dependent service is not running:
svc:/application/management/sunmctopology:default
# svcs -xv
svc:/application/management/sunmcdatabase:default (SunMC database service)
State: maintenance since November 12, 2009 3:10:30 PM CST
Reason: Start method exited with $SMF_EXIT_ERR_FATAL.
See: http://sun.com/msg/SMF-8000-KS
See: /var/svc/log/application-management-sunmcdatabase:default.log
Impact: 1 dependent service is not running:
svc:/application/management/sunmctopology:default
[ Nov 12 15:08:37 Leaving maintenance because disable requested. ]
[ Nov 12 15:08:37 Disabled. ]
[ Nov 12 15:09:07 Rereading configuration. ]
[ Nov 12 15:09:25 Enabled. ]
[ Nov 12 15:09:25 Executing start method ("/lib/svc/method/es-svc.sh start datab
ase") ]
execution of verifyDatabaseUp failed
exiting........................
[ Nov 12 15:10:30 Method "start" exited with status 95 ] -
What is generic & location specific bom & its difference
what is generic & location specific bom & its difference
MadanHi Madan,
The BOM which is created on Client level i.e. without Plant assignment would be a generic BOM which can be used in any plant by extending it that plant.
The BOM which is created using plant is Plant level BOM, which is specific to that plant i.e. that plant is the owner & creator of that BOM so that specific plant will be authorized & responsible to editing it.
Hope i have answered your question.
Regards
Rehman
Reward Points if useful -
Skylanders Trap Team - elusive Kaos trap
I have been on the hunt for the Kaos trap gem in area stores but when I stopped by my local Best Buy I was told that the item had been discontinued. Is that true? Should I strike Best Buy off my list of shops to check for this item?
Hi SandyM,
First, thanks for joining us here on the forums!
To be honest, it’s been pretty crazy trying to keep track of the availability of any given Skylanders figure, especially since some are significantly more limited than others. In regards to the Kaos Trap figure, I’m not sure if this has been discontinued. I’m leaning towards it potentially being available in the future since we still have it listed on BestBuy.com, which can be seen here.
Keep checking with your local store and more of these may show up in the future! You may also wish to frequently check BestBuy.com via the link above as well.
Thanks,
Brian|Senior Social Media Specialist | Best Buy® Corporate
Private Message -
The company I work for bought an Illustrator trapping plug in, and I'm having some issues with it. I'd like to make (or prefereably) obtain a test file that would be good to test overall trapping - any ideas?
Thanks in advance!
RAwesome,
It's just litho - I was thinking that there might be some 'universal' file that exists that would test out all trap functions. Any file you could give me would be greatly appreciated (just vector obviously)- it could be uploaded and downloaded from this forum.
Thanks Mike! -
Cisco WLC2125 Reporting Traps to a specific port
Hi all,
I am currently looking into reporting options for my Cisco WLC2125. From what I can see, I have two options, SNMP or Syslog however I would like to assign either Syslog or SNMP traffic via a specific port on the controller.
The reason is because i want to keep this traffic seperate to my wireless network.
My knowledge of controllers (and syslog and SNMP for that matter) but I can enter IP addresses for the servers however i cannot see how to assign this traffic to a specific port.
Is this possible? If so how?
Many Thanks,
-cNo, its not possible with a 2100. Best practices say you should only have one connection from a 2100 controller to the network, so all traffic to the network would go out that port.
https://supportforums.cisco.com/docs/DOC-11760 -
Restricted to generic papers - Specific canon papers grayed out?
I am attempting to print a "Profile Target Image" so that I can receive a Profile for my printer.
I'm using Photoshop CS4 and checked the "no color management" for Photoshop and have also disable color management for the printer.
I. I begin by checking the PRINT button on the Photoshop CS4 menu -
2. Than I check the "no color management" on the Print menu and click on the print button at bottom of Print Menu
3. Then I click on following: Layers than Quality & Media than Media Type. The generic papers are listed and are in black but the Canon's Specific papers are listed but are grayed out. Therefore, I can't choose any of Canon's papers as I set up parameters to print my Profit Target Image.
I'm new at this. What are I doing wrong? Would greatly appreciate any help you could provide.
RussRuss,
Sorry, I didn't fully explain in my first post.
When you print the target, you don't want to influence the output in any way by any kind of color management. And you've taken care of that by allowing neither the printer or PS to manage color.
But the system does control some mechanical parameters that you want to be the same for the profiling step as it will be when you are actually printing to your desired paper. Those parametes include printing resolution, whether printing will be bi-diretcional, print speed, "print quality" which is a combination of these kinds of factors, etc.
The program and the printer drivers try to be smarter than us (rather, the programmers of these try to prevent us from certain combinations of settings they they feel don't belong together) and present certain combinations of settings only. That's why you're getting the error message. You probably need to set Page Size correctly as the driver doesn't accept the paper type and the page size as valid combinations (the paper type probably doesn't come in the size you currently have set for Page Size).
Once you have that "error" cleared, set all the parameters in the Print Dialog just as you will when really printing. That means, selecting the correct printer name, all your desired settings in "Print Settings," "Printer Color Management" (off - none) and "Paper Configuration." You can save all these settings under a meaningful title in the Print dialog in "Presets." These are the printing conditions for your target file and for actual printing when using the profile generated from these conditions.
Hope that makes sense.
Rich -
Generic vs. specific userID in PI Interfaces
Hi All
We have many interfaces that are running between R3 and PI. Due to recent performance problems in R3 system, Basis team wants to differentiate between which application is causing and suggested to create Interface specific user id vs ALEMASTER which is used now.
Can anyone suggest if this is best practice to use PI Interface/application specific user id in PI channels or use a one channel with ALEMASTER. I know we have to create that many RFC destination and PI channels...which might bring down performance of the system connectivity.
Also for RFC channels we use logon groups with specific application servers on it.
Any inputs on this is appreciated.
Thanks,
Giridhar.Hi,
>>>Basis team wants to differentiate between which application is causing and suggested to create Interface specific user id vs ALEMASTER which is used now.
this is not an issue of PI user it's because:
- the receiving application don't have any source system identifiers
- the message which posts the transaction does not have any additional keys (like in IDOC function code etc.)
so don't change the user, change the error determination procedures in order to do it correctly
Regards,
Michal Krawczyk -
LMS 3.2.1 integration with Clarity NMS for snmp trap forwarding
Our client have integrated Clarity NMS to Ciscoworks LMS 3.2.1. So far they are receiving raw alarms/snmp traps but it lacks information/inventory of the originating device. Kindly see sample raw alarms below:
2420: 2011-11-25 12:10:46 Received trap ==> Received SNMPv1 Trap
Community=ciscoworks
Enterprise=1.3.6.1.6.3.1.1.5
Generip trap type=2
Specific Trap Type=0
Trap From=10.220.10.1
Trap ID=1.3.6.1.6.3.1.1.5.2
Trap Time=-1436283373
1.3.6.1.2.1.2.2.1.1.83=83
1.3.6.1.2.1.2.2.1.2.83=GigabitEthernet1/40
1.3.6.1.2.1.2.2.1.3.83=6
1.3.6.1.4.1.9.2.2.1.1.20.83=Lost Carrier
EndTrap
10933: 2011-11-24 11:57:53 Received trap ==> Received SNMPv1 Trap
Community=ciscoworks
Enterprise=1.3.6.1.4.1.9.1.291
Generip trap type=2
Specific Trap Type=0
Trap From=10.220.10.1
Trap ID=1.3.6.1.4.1.9.1.291.2
Trap Time=1628056965
1.3.6.1.2.1.2.2.1.1.8=8
1.3.6.1.2.1.2.2.1.2.8=E1 0/0/0
1.3.6.1.2.1.2.2.1.3.8=18
EndTrap
As you can see, those raw alarms doesn’t contain any information about the originating equipment or the physical card, port related information where those alarms were generated. Instead those alarms received are just NMS level alarms.
How do we resolve this so that the inventory of the equipment would be part of the trap to be received by Clarity from Ciscoworks.Hi,
Is the issue you have the source IP address of the forwarded trap? Per RFC it is the IP of the actual device sending the trap. The originating IP should be contained within the packet. I have included some additional information you may find helpful.
Q. What is the difference between SNMP Raw Trap Forwarding and SNMP Trap alert/event Trap Forwarding? Does DFM support both?
A. You can configure raw trap forwarding at DFM > Other configuration > SNMP Trap forwarding, and processed event/alert trap forwarding at DFM > Notification Services > SNMP Trap Forwarding. Processed trap is "when DFM receives certain SNMP traps, it analyzes the data found in fields (Enterprise/Generic trap identifier/Specific Trap identifier/variable−bindings) of each SNMP trap message, and changes the property value of the object property (if required)". Raw trap is the trap that the device forwards to DFM and DFM has yet to process it. For more information, refer to the DFM User Guide. Yes, DFM supports both ways of trap forwarding.
http://www.cisco.com/en/US/products/sw/cscowork/ps2421/products_qanda_item09186a0080a9b35b.shtml
DFM will only forward SNMP traps from devices in the DFM inventory. It will not change the trap format—it will forward the raw trap in the format in which the trap was received from the device. However, you must enable SNMP on your devices and you must do one of the following:
Configure SNMP to send traps directly to DFM
Integrate SNMP trap receiving with an NMS or a trap daemon
The versions of SNMP traps supported by DFM are described in SNMP and ICMP Polling. For information on forwarding processed and pass-through traps, see Processed and Pass-Through Traps, and Unidentified Traps and Events.
Pass-through traps are traps that DFM receives from devices that are not in the DFM inventory, and DFM has not processed. Forwarding these traps is controlled using Configuration > Other Configurations > SNMP Trap Forwarding. These traps are shown in the Alerts and Activities display because of their relevance to fault monitoring. Pass-through traps are displayed as follows:
As one of the following events:
> InformAlarm
> MinorAlarm
> MajorAlarm
With the device type and the device name from which it was generated.
If DFM does not know which device generated the trap, it ignores the trap. Pass-through traps will be cleared after a default interval of 10 minutes to one hour
http://www.cisco.com/en/US/docs/net_mgmt/ciscoworks_device_fault_manager/3.2/user/guide/dfm32ug_Book.html -
Unknown traps from EEM - parsing in Spectrum
I have a Cat6509 device sending EEM traps to our CA Spectrum monitoring system.
I've downloaded, compiled, and loaded the EEM MIB from Cisco, but some of the traps coming in aren't being parsed, as their OIDs don't map to the EEM MIB.
This is the "Unknown trap" that Spectrum sees:
Unknown alert received from device uwb485as0101.us.net.intra of type SwCiscoIOS. Device Time 288+16:21:43. (Trap type 1.3.6.1.4.1.9.10.91.6.2)
Trap var bind data:
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.2.397 Value: 71
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.3.397 Value: 0
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.4.397 Value: 0
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.5.397 Value: 0
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.7.397 Value: EEM Policy Director
OID: 1.3.6.1.4.1.9.10.91.1.2.3.1.11.397 Value: Output packet Drops on GigabitEthernet2/21 are incrementing by more than 10
(The text in the last line is just for testing, and isn't necessarily the actual message.)
The EEM MIB only goes up to 1.3.6.1.4.1.9.10.91.3, so Spectrum isn't handling this trap as we would like.
Thank you for any guidance you can provide.
JoeThis looks like a potential problem with your NMS. It looks like maybe it's building the trap OID incorrectly. The 6.2 looks like the generic trap number and specific trap number (i.e. cEventMgrPolicyEvent). Post a sniffer trace of the raw trap to confirm if the device is sending the wrong trap.
-
Unidentified Trap -unknown bug
An unknown bug which has OID as such:
EVENT ID = 00005CX
TIME = Thu 28-Jun-2012 16:32:13 SGT
STATUS = Active
SEVERITY = Informational
MANAGED OBJECT = Device_Hostnamexxxxxx
MANAGED OBJECT TYPE = Switches and Hubs
EVENT DESCRIPTION = InformAlarm::Component=xxxx.xxxx.com:
Unidentified Trap Generic Trap:6 Specific Trap:1
EnterpriseOid:.1.3.6.1.4.1.9.9.41.2;Description=Generic Trap:6 Specific Trap:1
VarBinds:{ .1.3.6.1.4.1.9.9.41.1.2.3.1.2.544239:LINEPROTO,
.1.3.6.1.4.1.9.9.41.1.2.3.1.3.544239:6,
.1.3.6.1.4.1.9.9.41.1.2.3.1.4.544239:UPDOWN,
.1.3.6.1.4.1.9.9.41.1.2.3.1.5.544239:Line protocol on Interface FastEthernet3/48,
changed state to down, .1.3.6.1.4.1.9.9.41.1.2.3.1.6.544239:975111759 };
NOTIFICATION ORIGINATOR = Fault Management ModuleSo what do we do about these alerts that often get triggered?
Unidentified Trap Generic Trap:enterpriseSpecific Specific Trap:1 EnterpriseOid:.iso.org.dod.internet.private.enterprises.cisco.ciscoMgmt.41.2
Description
Generic Trap:6 Specific Trap:1 VarBinds:{ .1.3.6.1.4.1.9.9.41.1.2.3.1.2.23652:LINK, .1.3.6.1.4.1.9.9.41.1.2.3.1.3.23652:4, .1.3.6.1.4.1.9.9.41.1.2.3.1.4.23652:UPDOWN, .1.3.6.1.4.1.9.9.41.1.2.3.1.5.23652:Interface FastEthernet1/0/39, changed state to up, .
on the interface I have configured "no snmp trap link-status," but I keep getting these info alarms. -
CSS not sending generic traps to trap host
My CSS is writing both generic and enterprise traps to the local traplog file, yet it is only forwarding the enterprise traps to the remote log?
YD01LB09# show log traplog tail 5
01/05/2005 12:45:12:Generic:Virtual Rounter 200 down on interface 7.32.172.15
01/05/2005 12:45:14:Enterprise:Service Transition:upstream_downstream -> down
01/05/2005 12:45:14:Enterprise:Service Transition:upstream_downstream -> alive
01/05/2005 12:45:14:Generic:Virtual Router 200 backup on interface 7.32.172.15
01/05/2005 12:45:18:Generic:Virtual Rounter 200 master on interface 7.32.172.15
01/05/2005 12:49:16:Enterprise:Service Transition:upstream_downstream -> suspended
01/05/2005 12:49:16:Generic:Virtual Rounter 200 down on interface 7.32.172.15
01/05/2005 12:49:18:Enterprise:Service Transition:upstream_downstream -> down
01/05/2005 12:49:20:Enterprise:Service Transition:upstream_downstream -> alive
01/05/2005 12:49:20:Generic:Virtual Router 200 backup on interface 7.32.172.15
01/05/2005 12:49:23:Generic:Virtual Rounter 200 master on interface 7.32.172.15
Remote Syslog
bash-2.00$ grep yd01lb09 contivity.*
contivity.Dec22:DEC 22 09:44:39 yd01lb09.net.rc.gc.ca 1/1 112 NETMAN-2: Enterprise:Service Transition:7.35.40.216:80 -> down
contivity.Jan02:JAN 2 04:02:45 yd01lb09.net.rc.gc.ca 1/1 113 NETMAN-2: Enterprise:Service Transition:7.35.38.213:80 -> down
contivity.Jan02:JAN 2 04:04:18 yd01lb09.net.rc.gc.ca 1/1 114 NETMAN-2: Enterprise:Service Transition:7.35.40.216:80 -> down
contivity.log:JAN 5 12:45:12 yd01lb09.net.rc.gc.ca 1/1 115 NETMAN-2: Enterprise:Service Transition:upstream_downstream -> suspended
contivity.log:JAN 5 12:45:14 yd01lb09.net.rc.gc.ca 1/1 121 NETMAN-2: Enterprise:Service Transition:upstream_downstream -> down
contivity.log:JAN 5 12:49:16 yd01lb09.net.rc.gc.ca 1/1 127 NETMAN-2: Enterprise:Service Transition:upstream_downstream -> suspended
contivity.log:JAN 5 12:49:18 yd01lb09.net.rc.gc.ca 1/1 133 NETMAN-2: Enterprise:Service Transition:upstream_downstream -> downHI,
have you configured both
snmp trap-type enterprise ...
(see
http://www.cisco.com/en/US/partner/products/hw/contnetw/ps789/products_configuration_guide_chapter09186a00800d6b32.html#xtocid19)
and
snmp trap-type generis ...
(see http://www.cisco.com/en/US/partner/products/hw/contnetw/ps789/products_configuration_guide_chapter09186a00800d6b32.html#xtocid16)
Kind Regards,
Joerg -
LMS 4.0 SNMP Traps Forwarding
Hello,
I have installed a new version of CiscoWorks LMS 4.0.
I would like to forward certain SNMP traps to another server. Not all traps but only the traps of devices which are down.
Is it possible to filter the traps and then forward the traps who match the filter to a server?
Thanks,
Best Regards,
JorisIf you enable trap forwarding in LMS, all traps received by LMS will be forwarded to the external NMS.
You can, however, look at NMSROOT/objects/smarts/conf/trapd/trapd.conf. You can modify this file to specify exactly what traps to forward. The comments in the file should help you figure out the syntax. However, direct modification of this file is not supported by TAC, so be sure to save a backup just in case. -
Hi all
By using snmp4j packege I have written a trap listener code for snmpV3, but am not able to catch any trap. In etherial i am getting snmp trap.
Could anyone please tell me whats wrong with my program...
public class V3trapListen {
public V3trapListen() { }
public synchronized void start(String address) throws Exception {
UdpAddress listenAddress = new UdpAddress(address);
ThreadPool threadPool = ThreadPool.create("DispatcherPool", 2);//1
MessageDispatcher mtDispatcher =
new MultiThreadedMessageDispatcher(threadPool,
new MessageDispatcherImpl());//2
// add message processing models
mtDispatcher.addMessageProcessingModel(new MPv1());
mtDispatcher.addMessageProcessingModel(new MPv2c());
mtDispatcher.addMessageProcessingModel(new MPv3());
// add default security models
SecurityProtocols.getInstance().addDefaultProtocols();
Snmp snmp = new Snmp(mtDispatcher);
CommunityTarget target = new CommunityTarget();
if(target != null) {
target.setCommunity(new OctetString("public"));
target.setAddress(listenAddress);
target.setVersion(SnmpConstants.version3);
} else {
System.out.println("Unable to create Target object");
System.exit(-1);
CommandResponder trapPrinter = new CommandResponder() {
public void processPdu(CommandResponderEvent e) {
PDU command = e.getPDU();
if (command != null) {
System.out.println("\n"+e.getPDU());
if (snmp.addNotificationListener(listenAddress, trapPrinter)) {
snmp.listen();
System.out.println("snmp.addNotificationListener returned TRUE ");
System.out.println("Waiting for [trap] on "+listenAddress.toString());
try {
this.wait();
catch(InterruptedException ex) {
System.out.println("Caught InterruptException: "+ex.toString());
catch(Exception ex) {
System.out.println("CaughtException: "+ex.toString());
} else {
System.out.println("snmp.addNotificationListener returned FALSE");
System.out.println("TestListener closing...");
regards
sanjayI use Ciscoworks LMS to send me emails when a given syslog arrives. (syslog, automated Actions)
It can also take SNMP TRAPS, not sure if it can actually send you email when it gets a specific TRAP, but i guess it can.
Any linux server with the right basic tools will also do the same.
castlerock SNMPc is a very good SNMP tool, and can search and email among other things.
Also gives you a Red,amber, green view and polls devices f.x. for a given service, like a TCP port.
highly customizable.
Maybe you are looking for
-
Digital or Digitized Signatures
Hey - Doing some research, as we're looking into having digital/electronic signatures perhaps for documents that require multiple signatures within the company - save money/etc. Has anyone ever looked into or discovered products that will also allow
-
Links get broken after adding photo gallery
I discovered a strange problem when creating a website with photo gallery. I have a menubar with static links to all pages of the website which worked perfectly. Now after adding a photo grid the links of the my menubar are not clickable at all. This
-
In the Master Item screen an item has been defined as having a zero input tax that is no tax has to be included in its total. However when the user is creating a PO it is ignoring the tax code and including the tax amount. Grateful if anyone can help
-
How does the macbook pro stack up to the competition?
Look at this - a 240gb HD! Catch up apple catch up! in the intel and compatible world you really need to offer more for less. Mac OS is much better than windows but the macbook pro is less hardware for more. That's part of the equation too. HP Pavili
-
I have an application that uses JTree I create the Jtree but I want to expand to see and select a node. I have the object of the node and the TreePath but I can't expand the tree using expandPath(), makeVisible(), scrollPathToVisible(path), etc. It s