Alerting from eventlog?
Hi there! Is it possible to create an alert from the evenlog?
Log message: 15d 20h 39m
FAILOVERhttp://jkpobservium01/device/device=1003/tab=port/port=155956/ Interface changed: [ifPhysAddress] '0025b3d7e06e' -> '0025b3d7e128'; [ifLastChange] '2015-04-21 20:47:50' -> '2015-06-02 16:17:43'
I want to know if my Cisco ASA:s does an failover.
Regards Fredrik
You could also use the status entity for this specific use case
Maarten
Sent from my iPhone
On 11 sep. 2015, at 10:15, Svensson Fredrik A <fredrik.a.svensson@rjl.semailto:fredrik.a.svensson@rjl.se> wrote:
Hi there! Is it possible to create an alert from the evenlog?
Log message: 15d 20h 39m
FAILOVERhttp://jkpobservium01/device/device=1003/tab=port/port=155956/ Interface changed: [ifPhysAddress] '0025b3d7e06e' -> '0025b3d7e128'; [ifLastChange] '2015-04-21 20:47:50' -> '2015-06-02 16:17:43'
I want to know if my Cisco ASA:s does an failover.
Regards Fredrik
_______________________________________________ observium mailing list observium@observium.orgmailto:observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
Well, I cant find anything to get a status from? No interface etc does go up/down. There have been an disqussion for some time ago about cisco ASA failover here, and there is no way for Observium to read failover state from the FW?
/ Fredrik
Från: observium [mailto:observium-bounces@observium.org] För Moerman, Maarten Skickat: den 11 september 2015 10:31 Till: Observium Network Observation System observium@observium.org Ämne: Re: [Observium] Alerting from eventlog?
You could also use the status entity for this specific use case
Maarten
Sent from my iPhone
On 11 sep. 2015, at 10:15, Svensson Fredrik A <fredrik.a.svensson@rjl.semailto:fredrik.a.svensson@rjl.se> wrote: Hi there! Is it possible to create an alert from the evenlog?
Log message: 15d 20h 39m
FAILOVERhttp://jkpobservium01/device/device=1003/tab=port/port=155956/ Interface changed: [ifPhysAddress] '0025b3d7e06e' -> '0025b3d7e128'; [ifLastChange] '2015-04-21 20:47:50' -> '2015-06-02 16:17:43'
I want to know if my Cisco ASA:s does an failover.
Regards Fredrik
_______________________________________________ observium mailing list observium@observium.orgmailto:observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
Since r6888 there is a status entity, to be honest it doesn;t work properly yet, but that is fixable once somebody figures out what's wrong with it. It's the best method right now to go with, as eventlog alerting doesn't seem to be on some roadmap anywhere.
Maarten -- Maarten Moerman | Mgr, Network Engineering | eBay Classifieds | +31-655122247 | mmoerman@ebay.com
From: observium <observium-bounces@observium.orgmailto:observium-bounces@observium.org> on behalf of Svensson Fredrik A <fredrik.a.svensson@rjl.semailto:fredrik.a.svensson@rjl.se> Reply-To: Observium Network Observation System <observium@observium.orgmailto:observium@observium.org> Date: Friday, September 11, 2015 at 10:57 AM To: Observium Network Observation System <observium@observium.orgmailto:observium@observium.org> Subject: Re: [Observium] Alerting from eventlog?
Well, I cant find anything to get a status from? No interface etc does go up/down. There have been an disqussion for some time ago about cisco ASA failover here, and there is no way for Observium to read failover state from the FW?
/ Fredrik
Från: observium [mailto:observium-bounces@observium.org] För Moerman, Maarten Skickat: den 11 september 2015 10:31 Till: Observium Network Observation System <observium@observium.orgmailto:observium@observium.org> Ämne: Re: [Observium] Alerting from eventlog?
You could also use the status entity for this specific use case
Maarten
Sent from my iPhone
On 11 sep. 2015, at 10:15, Svensson Fredrik A <fredrik.a.svensson@rjl.semailto:fredrik.a.svensson@rjl.se> wrote: Hi there! Is it possible to create an alert from the evenlog?
Log message: 15d 20h 39m
FAILOVERhttp://jkpobservium01/device/device=1003/tab=port/port=155956/ Interface changed: [ifPhysAddress] '0025b3d7e06e' -> '0025b3d7e128'; [ifLastChange] '2015-04-21 20:47:50' -> '2015-06-02 16:17:43'
I want to know if my Cisco ASA:s does an failover.
Regards Fredrik
_______________________________________________ observium mailing list observium@observium.orgmailto:observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
I did it that way
Name: ASA Failover Test: |status_event equals warning| |Device Match: ||hostname match blabla| |Entity Match: ||status_descr match *primary*|
Cheers, Andre
Thanks for the lead, Andre! I had to change the conditions to status_event equals alert and it works beautifully.
On Fri, Sep 11, 2015 at 2:03 PM, Andre Geißler andre@geisslermail.de wrote:
I did it that way
Name: ASA Failover Test: status_event equals warning Device Match: hostname match blabla Entity Match: status_descr match *primary*
Cheers, Andre
observium mailing list observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
I dont seem to get this working for me, where does the Status_event comes from?
Regards Fredrik
Från: observium [mailto:observium-bounces@observium.org] För Andrew Plas Skickat: den 12 september 2015 05:00 Till: Observium Network Observation System observium@observium.org Ämne: Re: [Observium] Alerting from eventlog?
Thanks for the lead, Andre! I had to change the conditions to status_event equals alert and it works beautifully.
On Fri, Sep 11, 2015 at 2:03 PM, Andre Geißler <andre@geisslermail.demailto:andre@geisslermail.de> wrote: I did it that way
Name: ASA Failover Test: status_event equals warning Device Match: hostname match blabla Entity Match: status_descr match *primary*
Cheers, Andre
_______________________________________________ observium mailing list observium@observium.orgmailto:observium@observium.org http://postman.memetic.org/cgi-bin/mailman/listinfo/observium
participants (4)
-
Andre Geißler
-
Andrew Plas
-
Moerman, Maarten
-
Svensson Fredrik A