SPECTRUM IM

Infrastructure Events and Alerts
Overview

Event Management and Correlation
Event Rules Condition Correlation Event Procedures Event Integration South-Bound-GW

Event Notifications

SSA 3.0: Service AND Event/Alert Umbrella
DACHSUG 2011

Infrastructure Events and Alerts

SPECTRUM generates an alarm when an event specifies that one should be created. Can be created also manually through Event Configuration Editor. abnormal condition exists in a model. imported via MIB Tools or created by editing the Event Configuration Files.What is an Event versus an Alarm?  Events An event is a SPECTRUM object that indicates that something significant has occurred within SPECTRUM itself or within the managed environment.  Alarms . . SPECTRUM can also generate an alarm based on the results of a SpectroWATCH violation.An alarm is a SPECTRUM object that indicates that a user-actionable. Typically. or as a result of SPECTRUM detecting an abnormal situation not based on an event (inference handler based).

Events in Spectrum Oneclick .

Alarms in Spectrum Oneclick ECE .

The dynamic varbind ID is 76620 (or 0x12b4c).Alarms information in Spectrum Oneclick  PCause code is specified for each alarm that displays the Probable Cause information for an alarm.  PCause files control what is displayed in the Probable Cause information.  PCause files are static. See Event Configuration User Guide.  The dynamic alarm title attribute can be populated with an Event Variable.pdf . event variables information. This allows for a single Probable cause to have a dynamic alarm title.

11.3.1. PROBABLE CAUSES: 1) A Trap from the firewall system was send 2) Firewall System has to high system usage RECOMMENDED ACTIONS: 1) Check the Event Message in the SPECTRUM Alarm Manager 2) Inform the Firewall Administrator 3) Check the thresholds on the Firewall System --------------------------------------------- .0) -------------------------------------------File: EventDisp > Maps Event to Alarm 0x00561001 Content: 0x00561001 E 50 A 1.0 0x561001 1. %Y .1.6.3.0(101.2620.%T"} . Event Message is: {S 101}.Device {m} of type {t} generated.1.1.U -----------------------------------------File: CsEvFormat/00561001 > Event Message Content: {d "%w.6.1.2620.1.Example: Trap Forwarding of external Managers and Event/Alarming in SPECTRUM Example: Checkpoint FW Manager File AlertMap > Maps Trap to Event 00561001 SS/CsVendor/<customer>_Checkpoint Content: 1.0x00561001.4.%d %m-.6.1.1.(event [{e}]) --------------------------------------------File: CsPCause/Prob00561001 > Alarm Message Content: FIREWALL STATUS ALARM SYMPTOMS: A Firewall System status is over the treshold.4.

Event Management and Correlation .

Spectrum Event Correlation  Fault Suppression  Downstream device fault suppression (including VPM)  Child (Port/Process) suppression  Port flapping  Other default EventRules based Correlations  Alarm De-duplication  Recurring events for the same field of the existing alarm.  Alarm Filtering  from alarm console. . Secondary alarms are just those with a lesser severity.

5.Extending Event Correlation  There are a number of ways that SPECTRUM Event Correlation capabilities can be updated and enhanced. 4. Simple Event Configuration updates This includes specifying which events generate/clear alarms and event variables to discriminate. 2. In addition. Event Procedures Complex expressions that allow for events to be manipulated at a very granular level. Events (or the be inferred. They are listed below: 1. You can also influence the automatic Faultisoltion Event and Alarming behavior . event and alarm descriptions can be modified and enriched. 3. including creating new event variables and asserting events on models other than the source (between different models(types)). Event Rules Event rules allow for events to be correlated on individual models (of the same modeltype). Condition Correlation Condition correlation allows for multiple events to be correlated across groups of models.

2.pdf . Settings in Component Details view of the VNM model See also for example Modeling and Managing Your IT Infrastructure Administrator Guide.Inductive Modeling Technology Setting Fault Isolation Parameters 1.

not to groups of models.Event Rules  Event Rules permit you to specify a more INTELLIGENT decision-making to indicate how an event is to be processed.  Event Rules available:  Event Condition  Event Pair  Event Rate  Event Series  Event Counter  Hearbeat  Single Event  Solo Event .  Event rules allow you to correlate multiple events on the same model.

1 (SPM-Test name) starts with AUA .EventCondition.2:2.9 0x0456000b E 20 R Aprisma. "0xfffffffa 1:1.{S \ \*###BOT_TEXT###quot;})". "regexp({v 1}. if var.3.3:3.9:9" EventDisp File .2. and deliver Var 1.Examples: Event Pair & Event Condition GUI ConditionEventRule for SPM Tests: Generate event(alarm) 0xfffffffa only.

Example: SPECTRUM Condition Correlation Editor LSP Alarms generate one MPLS Backbone Error Alarm Create Condition: left side (eg Error Backbone Error (type: counts) these but show as symptomes .

\ ReadAttribute( \ { C CURRENT_MODEL }. \ CreateEventWithAttributes( \ { V portModel }. Dann Check. mit denselben Varbinds wie der ursprüngliche Event. . \ { H 0x129fa } )). in der Schleife behandelt). falls der Port matched (hier z. wird ein neuer Event auf ihm generiert (0xbeecc002). \ { H 0xbeecc002 }.Example: Event Procedures (in EventDisp Files) # wenn Event beecc001 erzeugt wird.) des Devices. \ If( \ Equals( \ ReadAttribute( \ { V portMh }. ob ifIndex (0x11348) am Port derselbe ist wie Varbind 1 im Event. \ { V portMh }.h. CA) # Ziel: wenn dieser SPM-Event/Alarm auf dem Device erzeugt wird. hier dann IP Adresse) Dann. alle Ports (und Apps. (z. Falls der Port nichts matched. \ GetEventAttributeList()). dann soll auch ein Event/Alarm auf dem entsprechenden Port erzeugt und ausgewertet werden 0xbeecc001 E 50 P " \ ForEach( \ GetModelsByAttrValue( \ { H 0x10069 }. ifIndex). wird auch nichts gemacht (Nil()). führe folgende Procedure aus ( Johannes Kroupa .B. \ { U 0 }. \ Nil()))" Die Proc findet zuerst mal alle Modelle (GetModelsByAttrValue).. \ { H 0x11348 } ). \ { V dummyRetValue }. \ GetEventVariable( { U 1 } )). d. um den richtigen Port zu finden.B.

CA Event Integration (EI) .Architecture .

.

Southbound Gateway Non-SNMP. Vendor Specific EMS via Trap Vendor Specific EMS via XML double click . LogFiles (SYSLOGs !). Element Managers via XML. V. SNMP and CORBA etc.24 and others Events and Traps from different Sources For example Logfiles. DBs . Traps.

Event Notification .

alarm-processing applications and SANM (Policy Manager) work together in the alarm monitoring process.Alarm Notification CA Spectrum. .

thank you .