SNMP Alerts are Duplicated

Hello,
I am running SCOM 2012 R2 UR4 and I have been trying to monitor my HP procurve switches.  I have been having an issue where the traps being sent to the server are just a port number and nothing else.  That has been somewhat fixed with a firmware
update on the switches.  But what I get now are 2 alerts.  One alert is just a number, not related to the port and another alert with a full description.  These are the 2 alerts:
Why am I getting this?

Event description appears to be different and it looks to me there are 2 similar rules triggering this.
You may like to check.
Blog: http://theinfraguys.com
Follow me at Facebook
The Infra Guys Facebook Page
Please remember to click Mark as Answer on the answer if it helps you in anyway

Similar Messages

  • SNMP Alert Destinations

    How does an SNMP alert destination configured within OSB actually submit its traps?
    For instance, I have an SNMP alert destination configured within OSB named "Dev", with SNMP trap enabled, and reporting/email/JMS disabled.
    I have services with SLA rules that are firing, and are generating SLA alerts, and are using this alert destination.
    In the underlying Weblogic domain, I have an SNMP Server Agent name "Dev" which points to the actual IP of the SNMP monitoring tool which receives the alerts, and the WL servers are generating alerts successfully for Weblogic - specific events, such as startup, shutdown, etc.
    But as yet, we don't see any of the OSB traps arriving. Presumably, the name of the Alert destination defined within OSB must match the name of the WL agent ( although the OSB docs are silent on this ).
    So I see SLA alerts in the console, but no sign of any SNMP traps being emitted as a result of the alert.

    But as yet, we don't see any of the OSB traps arriving. Presumably, the name of the Alert destination defined within OSB must match the name of the WL agent ( although the OSB docs are silent on this ).Not required.
    I have configured SNMP traps with OSB in Single Node and Cluster. If you are using unixes, you might want to check the ports being used. Unless we are under root we cannot use ports 0-1023 and this might be the problem.
    Thanks
    Manoj

  • Unable to set up SNMP alerts

    I'm trying to set up SNMP alerts in WL 8.1 and in the server log I see the following:
    ##<Apr 15, 2005 11:01:20 AM EDT> <Error> <SNMP Agent> <aan1> <dra> <SNMP Service Thread> <<WLS Kernel>> <> <000000> <There are multiple instances of SNMPAgentMBean ... This is an improper configuration>
    ####<Apr 15, 2005 11:01:20 AM EDT> <Error> <SNMP Agent> <aan1> <dra> <SNMP Service Thread> <<WLS Kernel>> <> <000000> <SNMP Agent will not be activated ... >
    I don't see anything that looks funny in the config.xml and don't know how multiple instances of that bean could be created. Does anyone have any experience with this that might help?
    Thanks in advance!
    Sue Shanabrook

    Hello sue,
    Take a look at your config.xml, maybe the SNMPAgentMBean's Name is not the same as the domain name, it should be the same.
    thanks,
    -satya

  • Snmp alerts for CPU utilization

    Hi,
    I want to enable snmp alerts on l2 and l3 switches to monitor CPU utilization.
    I have Opmanager which is acting as SNMP server.
    I have switches L2 and L3 which are running IOS 12.0, 12.1, 12.2
    Do all these IOS versions support SNMP alerts?
    And also I want to know the commands to be configured on switches for this.
    Regards
    skrao

    You can configure SNMP traps for CPU Thresholding Notification.
    http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455772.html
    You should be ok with the versions you list but check exact IOS version supports it at http://www.cisco.com/go/fn
    If you do not want to use traps then there are specific oids that can be polled for 1minute average (1.3.6.1.4.1.9.2.1.57) and also 5 minute average (1.3.6.1.4.1.9.2.1.58). I've used these in the past with no problems. These oids may have been superceeded so check for latest. You can always snmpwalk a device to check oids.
    The cisco SNMP navigator is helpful when it comes to oids.
    http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?local=en
    If you haven't got any SNMP configured yet on the switch check out http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Network%20Infrastructure&topic=Network%20Management&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1ddb4e54
    HTH
    --Phil

  • Need more info in snmp alerts

    Hello all: Here is a typical snmp message I receive:
    ================================================== =========
    The following alarm has occurred:
    Alarm generator : SNMP
    Alarm Category : CPQHLTH-MIB
    Alarm type : Fan Degraded ( 6035 )
    Alarm time : Tue Jul 24 10:29:44 EDT 2007
    Summary : The Fan Degraded on Chassis 0 ,
    Fan 2 .
    ================================================== =========
    A SNMP alarm has been generated by a device on the GR
    subnet.
    As you can, there is not much information. I really need to
    know the server which generated the error. How can I setup
    ZfS7 to do this??
    Thanks a bunch for the help, Chris.

    Yes, that is what I am looking for. THANKS VERY MUCH.
    >>> On 7/30/2007 at 8:07 PM, in message
    <[email protected]>, Steven
    Lim<s.lim_nospam@4me_curtin.edu.au> wrote:
    > Have a look in the autoexec.ncf and see if you can see
    > sys:\system\nma\nma5.ncf
    >
    > It loads
    > LOAD FLEXTRAP
    > LOAD NDPSMIB
    > LOAD NTREND
    > LOAD HOSTMIB
    > LOAD NWTRAP
    > LOAD SERVINST
    > LOAD NDSINST
    > LOAD NDSTRAP
    > LOAD MPKAGENT
    > LOAD MONDATA
    > LOAD NSSMIB
    > LOAD NWTRPAGT
    > LOAD DSTRPAGT
    >
    > but you must be loading them otherwise you wouldn't be
    > gettting anything
    > anyway.
    >
    > How do you receive the SNMP alert..via email? if so then
    > it's probably just
    > your rules for your site. Get properties of your site
    > server in the ZFS
    > namespace of ConsoleOne. This will open the ZFS MMS
    > snapins. Go to the Rules
    > pagetab. Edit the rule\s that send you the email.
    >
    > I use the following in the body of the message to show
    > me the information
    > that i want
    >
    > %-h [%n]%s
    >
    > have a look in the help to see what other options are
    > there but the one that
    > you want is %n which is the affected object\server.
    >
    > For the subject i use
    >
    > [%n] %t
    >
    > the square braces don't mean anything....i just use
    > those the encase the
    > server name.
    >
    > I've also renamed all my server objects in the atlas to
    > be just the common
    > name. It makes it all nice and short.
    >
    > hope that helps
    > "Chris Mosentine" <cmosentine@N0_$pam.vrapc.com> wrote in
    > message
    > news:46ADB66E.08CB.0032.0@N0_$pam.vrapc.com...
    >> How can I tell if I am running the NMA's. I am not all
    > that
    >> familiar with zfs.
    >>
    >> The servers are listed in the atlas.
    >>
    >> Thanks for the help, Chris.
    >>
    >>
    >>
    >>>>> On 7/26/2007 at 1:49 AM, in message
    >> <[email protected]>,
    Steven
    >> Lim<s.lim_nospam@4me_curtin.edu.au> wrote:
    >>> Is the server running ZFS NMAs?
    >>> Can you find it in the Atlas? That's where ZFS
    >>> monitoring gets the name from
    >>>
    >>> "Chris Mosentine" <cmosentine@N0_$pam.vrapc.com> wrote
    in
    >>
    >>> message
    >>> news:46A5DB58.08CB.0032.0@N0_$pam.vrapc.com...
    >>>> Hello all: Here is a typical snmp message I receive:
    >>>>
    >>>>
    >>>
    > ================================================== =======
    >>> ==
    >>>> The following alarm has occurred:
    >>>>
    >>>> Alarm generator : SNMP
    >>>> Alarm Category : CPQHLTH-MIB
    >>>> Alarm type : Fan Degraded ( 6035 )
    >>>> Alarm time : Tue Jul 24 10:29:44 EDT 2007
    >>>> Summary : The Fan Degraded on Chassis
    0
    >>
    >>> ,
    >>>> Fan 2 .
    >>>>
    >>>
    > ================================================== =======
    >>> ==
    >>>>
    >>>>
    >>>> A SNMP alarm has been generated by a device on the GR
    >>>> subnet.
    >>>>
    >>>>
    >>>>
    >>>> As you can, there is not much information. I really
    >>> need to
    >>>> know the server which generated the error. How can I
    >>> setup
    >>>> ZfS7 to do this??
    >>>>
    >>>> Thanks a bunch for the help, Chris.
    >>>>
    >>>>

  • Alerts are LOST somewhere in Action Override Stage...

    I have very, very strange statistics on my sensor. I cleared it few minutes ago and now it is as follows:
    SigEvent Preliminary Stage Statistics
    Number of Alerts received = 60
    Number of Alerts Consumed by AlertInterval = 0
    Number of Alerts Consumed by Event Count = 0
    Number of FireOnce First Alerts = 0
    Number of FireOnce Intermediate Alerts = 0
    Number of Summary First Alerts = 8
    Number of Summary Intermediate Alerts = 43
    Number of Regular Summary Final Alerts = 8
    Number of Global Summary Final Alerts = 0
    Number of Active SigEventDataNodes = 10
    Number of Alerts Output for further processing = 60
    SigEvent Action Override Stage Statistics
    Number of Alerts received to Action Override Processor = 60
    Number of Alerts where an override was applied = 0
    Actions Added
    deny-attacker-inline = 0
    deny-attacker-victim-pair-inline = 0
    deny-attacker-service-pair-inline = 0
    deny-connection-inline = 0
    deny-packet-inline = 0
    modify-packet-inline = 0
    log-attacker-packets = 0
    log-pair-packets = 0
    log-victim-packets = 0
    produce-alert = 0
    produce-verbose-alert = 0
    request-block-connection = 0
    request-block-host = 0
    request-snmp-trap = 0
    reset-tcp-connection = 0
    request-rate-limit = 0
    SigEvent Action Filter Stage Statistics
    Number of Alerts received to Action Filter Processor = 0
    Number of Alerts where an action was filtered = 0
    Number of Filter Line matches = 0
    Number of Filter Line matches causing decreased DenyPercentage = 0
    Actions Filtered
    deny-attacker-inline = 0
    deny-attacker-victim-pair-inline = 0
    deny-attacker-service-pair-inline = 0
    deny-connection-inline = 0
    deny-packet-inline = 0
    modify-packet-inline = 0
    log-attacker-packets = 0
    log-pair-packets = 0
    log-victim-packets = 0
    produce-alert = 0
    produce-verbose-alert = 0
    request-block-connection = 0
    request-block-host = 0
    request-snmp-trap = 0
    reset-tcp-connection = 0
    request-rate-limit = 0
    SigEvent Action Handling Stage Statistics.
    Number of Alerts received to Action Handling Processor = 1
    Number of Alerts where produceAlert was forced = 0
    Number of Alerts where produceAlert was off = 0
    Actions Performed
    deny-attacker-inline = 0
    deny-attacker-victim-pair-inline = 0
    deny-attacker-service-pair-inline = 0
    deny-connection-inline = 0
    deny-packet-inline = 0
    modify-packet-inline = 0
    log-attacker-packets = 0
    log-pair-packets = 0
    log-victim-packets = 0
    produce-alert = 1
    produce-verbose-alert = 0
    request-block-connection = 0
    request-block-host = 0
    request-snmp-trap = 0
    reset-tcp-connection = 0
    request-rate-limit = 0
    Per-Signature SigEvent count since reset
    Sig 60000.0 = 1
    Yes, single signature fired, but the number of "Preliminary Stage Alerts" was 60 !? What happened with other 59 alerts ???

    Only when the alert has at least one action will it be passed to the event action handler.
    So the other 59 alerts did not have any event action. Either no action was added directly from the signature definition, or the alerting type actions were removed because of summarization, or the actions were removed by filters.
    There are several signatures that are intentionally created without actions. These signatures are what we call meta component signatures. On their own they don't mean much and so we remove all actions and they do not generate alerts into the eventstore. They trigger internally in sensorApp but do not get written to the eventstore. These alerts are internally monitored by Meta signatures. When multiple component signatures are triggered, then a Meta signature may trigger and it is the Meta signature that would have a produce-alert event action and be written to the eventStore.
    With summarization the signature has a produce-alert action, but the summarizer routines see that the signature is being triggered multiple times with same addresses. The summarizer will allow through an alert on the first triggering. Later triggerings with the same address set will cause the summarizer to automatically remove the produce-alert action (and other alert causing actions). So the summarized alerts will not get written to the eventStore.
    NOTE: In your output this happened for at least 43 of these alerts.
    Filters may also be matching the alerts, and the filters may be removing the event actions.
    So if the event actions have all be removed (or none were ever added), then the alert will not be passed to the event action handler.
    In your output only 1 of the 60 alerts wound up with any actions needing to be executed.

  • Configuring SNMP Alerts

    Does anyone have any experience with configuring SNMP alerts on C-Series appliances?  I'm interested in receiving alerts when there's a certain amount of emails in the workqueue.  Is this possible?
    We experienced an issue the other day where we received an exorbitant amount of email at one time from one specific sender and the workqueue was backed up.  It would have been nice to receive alerts on this so we could more effectively eliminate the issue.  If anyone has another suggestion to receiving notification through SNMP alerts on a high amount of messages in the workqueue please let me know.  I'm open to other ideas.  I just thought this might be the most effective way.
    Thanks!
    Mike

    Thanks Viquar, maybe you can help me with the issue that I'm dealing with.
    We have roughly 4000 internal SMTP servers that send e-mail to the internet via our IronPort cluster.  These IPs are everything from USB temperature gauges to an Exchange org. with 20K mailboxes.   Every once in a while something goes haywire and a lot of e-mail gets generated internally.  Either a virus generating a lot of e-mail, an application getting stuck in a loop, or a user configuring an Outlook Rule to send all mail to an external address that is being bounced back to them.
    What I'm looking for is some kind of alert when e-mail volume or maybe e-mail rate goes through the roof.
    One of the things that I've been researching is implementing rate limiting on outbound e-mail by IP address.  The problem is that all of these 4,000 internal SMTP servers are allowed access due to a 10.* entry in our HAT today.  So to get rate limiting going I would have to identify all of those servers and then determine the rate that would be good for each of them that would allow normal traffic but stop at the right point when an issue is occurring.  Due to the work that would take I was hoping for something along the lines of an alert when overall mail rate on the IronPort cluster goes higher than X, not knowing what X is yet...   Probably configure it something high and then slowly change it to a lower setting until I started getting alerts.
    Anything like that exist?
    Jason Meyer

  • How do you remove items from the assets panel that are duplicated?

    How do you remove items from the assets panel that are duplicated?

    If you add an item to a slideshow, you'll usually see 2 entries for that image in the assets panel - one represents the thumbnail, and the other represents the larger 'hero' image.
    It sounds like you may have added the same image to your slideshow twice. You can select one of the hero images or thumbnail images in your slideshow and use the delete key to remove it. Then the extra 2 entries in the assets panel should disappear.

  • Events are duplicating in ical

    when my ical opens on imac, all events entered from my iphone or ipad are duplicated.  This has only started since updateing to Lion.  Nothing is duplicated on my iphone

    On your iMac turn off the 'On My Mac' calendar (s)

  • Photos - my photos are duplicated in Albums, Photo Stream and Events.  Does this take additional memory?

    I need instruction and not understanding Photos.  When I put photos from my Canon Camera through the Apple Connector - SD Card Reader, the photos are displayed in the Photo App.  They are duplicated in many areas:  Photos, PhotoStream, Albums, and Events.  Is this the way Apple does this?  Can I just have photos in one place in the app?  BTW: my PhotoStream setting is on on the iPAD4 and on my iPHONE 5.  Should I turn off?  If they are duplicated in all areas, are they taken up space on my iPAD?Please advise.
    Also, can I delete multiple photos on my iPAD4 without selecting each one?  I don't seem to see a Select All option.  Also, I am not sure when I see this dialogue box on the iPAD4, but it seems I only get Delete Everywhere instead of just Delete.  Why?  Is there a setting I need to know about.
    When I connect my iPAD4 through the hardwire to my PC, can I just create a folder and copy my photos on my iPAD4 to my PC.  They will not remove them from the iPAD4, correct?

    Basically within the photo app, there are sever views available, each having a different purpose, but only one file per image (at least I'm fairly certain that's how it works). Start off with the Photos section of the user guide (link below). It may not answer all of your questions, but will give you a good starting place.
    http://manuals.info.apple.com/en_US/ipad_user_guide.pdf

  • TS4118 My calendar entries are not duplicated in either iCloud, or iPad - but are duplicated on my iPhone.  How do I stop this, and also how do I delete the duplicates???

    My calendar entries are not duplicated in either iCloud, or iPad - but are duplicated on my iPhone.  How do I stop this, and also how do I delete the duplicates???

    mervrich,
    Use the "Troubleshooting iOS devices" link in iCloud: Troubleshooting iCloud Calendar.

  • Report Alerts are not shown on crystal server 2011

    Hi,
    I have created alerts on From date and To Date. The alert is shown when the difference between From Date and To Date is more than an year. It is shown properly in the crystal report designer. When I am uploading the same report to the server the alerts are not shown on the server.
    Can someone help me with the same.
    Thanks,
    Simran

    Hi Jawahar,
    I have uploaded the report in CMC using Add--> Local Document.
    For Alerts I have checked the Box 'Enable Alert'. Still I am not getting a Pop Up which I get in the crystal report designer. Is the Alert sent on Crystal Server by email? I have currently selected default setting in Configure Alert Notification.
    Regards,
    Simran

  • Alerts are not coming in Alert Inbox SLG1

    Hi Experts,
    We have SAP NW2004s PI/XI system.
    We have defined alert configuration step by step with following,
    http://help.sap.com/saphelp_nw04s/helpdata/en/3f/81023cfa699508e10000000a11402f/frameset.htm
    /people/michal.krawczyk2/blog/2005/09/09/xi-alerts--step-by-step
    And I have checked configuration through many other threads, but don't why alerts are triggered.
    Logging Entry is checked,
    TCODE - ALRTCATDEF ->choose Settings->configuration , make sure you have the logging parameter checked.
    TCODE - SICF - AlertInbox and other services are active.
    But, I am not getting alert in Alert Inbox or SLG1 transaction.
    Error message can see through SXMB_MONI.
    When I do testing with report 'RSALERTTEST', it shows entry in both SLG1 and AlertInbox.
    Do we need to setup anything from triggering side?
    Pease help with this, it is urgent.
    Thanks,
    SamV.

    Hi Jean,
    are you looking at the SXMB_MONI on the XI system?
    Yes, It shows Mapping Error there...
    did you put your user on that alert when you configured it?alerts are asociated to specific users.
    Can you please tell me detail, I didnt get it.
    Thanks,
    SamV.

  • ITunes university subscriptions are duplicating

    I noticed odd behavior yesterday.  iTunes courses to which I've subscribed and fully downloaded are starting to replicate.   The course will be listed twice in the left nav bar, and duplicate classes/documents will download.  This behavior is not consistent, with only a third of the 40 or so courses I have duplicating thus far.  The duplication isn't just one university.  I've seen it with MIT, Library of Congress, Yale.  Sometimes the course has the exact same name and artwork, othertimes the duplicated course source is given as 'unknown artist'.
    If I look in the iTunes library (under iTunes Media/iTunes U), only one folder for the course is given, but there are duplicated file names.  E.g.,
    01 Course Introduction.mp4
    1-01 Course Introduction.mp4
    with the same file size, but one will have a creation date of yesterday, and the other has one when I originally downloaded it.
    How do I get these courses (in case that is relevant):
    I find something interesting in iTunes U and subscribe to it.   Normally, only one class will download into iTunes.  I often have to then select the 'old materials' button to list other classes in the course, even though I have both download and keep as settings preferences for all episodes.  And normally I then select to download manually all of the older episodes from the little cloud download icon next to each one.
    If I delete one of the two courses listed, both courses disappear and are moved to the trash.  This is confirmed by looking in the trash at the episode names, and is consistent with iTunes removing the whole course folder from its library.  It appears that the duplicates happen when one file is added to the collection, or the modification date is changed on their server -- then the whole subscription duplicates.
    Puzzling that this didn't happen to ALL courses, but was pretty consistant by school.
    Is this because I am manually asking iTunes to download old materials?   Has anyone else seen this behavior?

    I am also seeing this issue. Any updates on this?

  • Adapter engine alerts are not working ..

    We have been using SAP PI 7.1 version  and SP08 and recently i have been configured XI alerts . When i have do IE errors alerts are recieving in Alert inbox as well as to mail but when i try to create error in Adapter engine iam not recieving any alert . I had been gone through most of the links but didnt get any and according to sap Note 913858 :
    Q10: I do not receive any alerts, but when I test the alert
    category using the report RSALERTTEST, an alert is delivered.
    - A10: In transaction ST22, search for dumps caused by the user
    XIRWBUSER stating that the authorization is missing for RFC
    calls or for the function group SXMSALERT. If this is the case,
    you probably have to regenerate the roles and profiles for the
    XIRWBUSER.
    But same procedure i have been followed but ST22 i couldnt able to see any dump and when try to run the program by giving alert category Adpater engine alerts are reaching inbox as well as to mail. I have tried each and every configuration but some thing is missing here couldnt able to find it.Anybody help me on this.
    Thanks,
    Aparna.

    Hi Gabriel,
    Thanks for reply. When i open the URL which was given by you i found below options .Could you please explain some more on this.
    Initialize aii.properties
    Execute function module RWB_PING on monitoring server
    Send test alert via Alert.sendTestAlert(true) with MsgID
    Send test alert via Alert.sendTestAlert(false) without MsgID
    Get AdapterTypes from SLD
    Get URL for Alert Monitor
    Set URL for MDT
    Get URL for MDT
    Clear URL for MDT
    Could you please explain how it is going to work
    Thanks,
    Aparna.
    Edited by: aparna_karnam on Feb 27, 2012 5:23 PM

Maybe you are looking for

  • 20" vs 22"

    does anyone have experience with the acrylic 20" and 22" displays? the 22" has lower dpi, I estimate like a 17" CRT screen? (which is what I have now), but seems to go cheaper than the 20" used. The 22" was also a version with "PanelLink"-DVI, is it

  • I want to buy my girlfrind in the uk a some songs from Itunes for her birthday on itunes usa can she redeme them?

    Hi, I want to buy a playlist from itune usa for my girlfriend in the uk. Can she redeme them? Thanks, Barbara

  • Share custom PDF settings

    This question was posted in response to the following article: http://help.adobe.com/en_US/acrobat/pro/using/WSb2f1a50375cd48d3-1f36d19412ada208ceb-7fff. html

  • Lenovo Vibe X2 missing language

    Recent update popped up, so I decided to install it. When I reboot my multilanguage was gone. Only English and Chinese language is available. Any solutions..? I have downloaded a new firmware, but I can't install via Flashtool.

  • Preserve file system during OS installation

    Hello all, I would like to know why every time I would like to preserve a file system, I would not be able to allocate all space in the system to be full used? Let's say, in a 8GB hard-disk, I want to preserve a slice 4, which is of size 1GB. After I