Hello,
Thre´s a way to ignore/filter some event log like this (flooding, in this case):
8h 30m 57s GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
....
14h 30m 37s GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
4d 14h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
4d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
5d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
7d 8h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
7d 20h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
8d 2h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
8d 8h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
8d 14h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
8d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
9d 8h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76
10d 8h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
....
some servers share same loopback address (dns anycast).
regars,
--
Alexandre Jeronimo Correa / CEO
alexandre@onda.net.br / Office +55 34 3351 - 3077ONDA INTERNET
+55 34 3351-3077
Av. Benedito Valadares, 217 – Centro – Sacramento – MG - BR
http://www.onda.net.br
_______________________________________________
observium mailing list
observium@observium.org
http://postman.memetic.org/cgi-bin/mailman/listinfo/ observium