Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Unwanted traps still coming through

0 views
Skip to first unread message

Bronwyn

unread,
Dec 19, 2006, 7:00:23 AM12/19/06
to
Hello - We have ZfS v7 sp1 installed on an OES sp3 box that is
dedicated to this purpose. At the moment, we only have the MMS
components installed and are monitoring 17 W2K3 servers (with the
monitoring agent installed), and 4 Solaris 8 boxes (no agents and no
SNMP fwd'ing, ping only).

What I've been trying to do is filter the traps that come through from
the windows boxes to only those the customer is interested in. The
filters defined below are working pretty well to that end, with the
following exception: The customer has RSA services installed on each of
the domain controllers and the ACE client keeps writing [hundreds of]
security messages to the application event log (as errors, not
warnings) and these keep showing up in C1 in their hundreds. There
are only the two application errors that I want to filter out: event
ids 10022 & 10304. I have tried inserting an additional filter
:Filter5.EventID=!(10022,10304) - but this has no filtering effect on
the traps. Do you have any suggestions, please?

NTTRAP.INI*****************************************************************
[Available Filters]

Filter1.TrapType=system
Filter1.EventType=1

Filter2.TrapType=application
Filter2.EventType=1

Filter3.TrapType=security
Filter3.EventType=1

Filter4.EventID=(2,... [truncated] ...,5789)


[Actual Filters]
1=Filter1
2=Filter2
3=Filter3
4=Filter4
*****************************************************************
SITE MGMT SERVER Properties\Rules\Conditions\Alarms:
Severity = Critical or Major
Or if the Alarm state = Non-Operational
*****************************************************************

Thanks in advance,
Bronwyn.

Jared Jennings

unread,
Dec 19, 2006, 7:55:06 AM12/19/06
to
Bronwyn,

>There
>are only the two application errors that I want to filter out: event
>ids 10022 & 10304. I have tried inserting an additional filter
>:Filter5.EventID=!(10022,10304) - but this has no filtering effect on
>the traps.

I don't have any idea for a real fix, but what about creating a rule that
auto-handles the events. This way the events will be purged when the
automatic purge happens.

This should save your db keeping C1 usable.
--
Jared Jennings - Data Technique, Inc.
Novell Support Forums Sysop
My Blog and Wiki with Tips, Tricks, and Tutorials
http://jaredjennings.org

Bronwyn

unread,
Dec 20, 2006, 9:12:18 AM12/20/06
to
> but what about creating a rule that
> auto-handles the events. This way the events will be purged when the
> automatic purge happens.
>
> This should save your db keeping C1 usable

I'm not sure this solution is a good idea since this particular client
will be feeding C1 onto a wall mounted flatscreen so the support staff
can monitor alerts as they come in... ...the servers generating these
events would still end up in a constant state of alarm, since the purge
is only running nightly.

Would it be possible to discard these events before they're written to
the database, or somehow force them to become unknown ?

Jared Jennings

unread,
Dec 20, 2006, 12:14:25 PM12/20/06
to
Bronwyn,

>...the servers generating these
>events would still end up in a constant state of alarm, since the purge
>is only running nightly.

Hum, not that I know of.

Let me see if someone else has a suggestion.

Jared Jennings

unread,
Jan 4, 2007, 9:52:21 AM1/4/07
to
Bronwyn,

Just checking....But the service was restarted after you made the
changes.. Right?

Bronwyn

unread,
Jan 12, 2007, 12:30:42 PM1/12/07
to
Yes, it was...

Jared Jennings

unread,
Jan 22, 2007, 11:51:59 AM1/22/07
to
Bronwyn,

I have an updated file....that I would like you to try.. Were do you want
it sent too?

You can mail me directly at jaredljennings at gmail dot com .. If you
want... THe file will come from Novell.

Bronwyn

unread,
Feb 1, 2007, 5:28:22 AM2/1/07
to
On Jan 22, 4:51 pm, "Jared Jennings"

Hi Jared,

I received the two dlls from Novell and replaced them on two servers
in our prdouction environment (as per instructions received) and I can
report, unfortunately, that there has been no improvement.

I cleared all the relevant traps from Console One prior to
implementing the trial fix and today (6 days later) there are 500 odd
of them returned from the two servers patched.

Any other ideas on where to? Is it back to the drawing board?
Bronwyn

Jared Jennings

unread,
Feb 1, 2007, 11:43:38 AM2/1/07
to
Bronwyn,

>Any other ideas on where to? Is it back to the drawing board?

I will have to ask as I don't have a windows box to test this on...I will
get back with you on this.

Jared Jennings

unread,
Feb 1, 2007, 11:45:35 AM2/1/07
to
Bronwyn,

Actually, could you send me the nttrap.ini and any errors from event
viewer that might happen when the snmp service is restarted.

Send them to jaredljennings at gmail dot com

Jared Jennings

unread,
Feb 3, 2007, 10:36:53 AM2/3/07
to
Bronwyn,

>Filter2.TrapType=application
>Filter2.EventType=1

try moving this filter to the bottom of the config file.

Bronwyn

unread,
Feb 5, 2007, 6:10:51 AM2/5/07
to
sent files through as requested

Jared Jennings

unread,
Feb 5, 2007, 12:18:52 PM2/5/07
to
Bronwyn,

>
>sent files through as requested

Thanks, I will look at them.

Jared Jennings

unread,
Feb 22, 2007, 10:15:57 AM2/22/07
to
Bronwyn,

We see that you are filtering out events 10022 and 10304, are these the
only events that are making it past the filter or are other events making
it through?

Also, could you send me a Windows Event log, which should include these
events.

Bronwyn

unread,
Feb 23, 2007, 5:26:46 AM2/23/07
to
On Feb 22, 3:15 pm, "Jared Jennings"

Yes - all the 'filtered' events are making it through. I have sent
the event log to your account previously specified.

Jared Jennings

unread,
Feb 23, 2007, 11:46:49 AM2/23/07
to
Bronwyn,

>Yes - all the 'filtered' events are making it through.

Ouch.
Received the email. Looking at it.

Jared Jennings

unread,
Mar 2, 2007, 10:02:20 PM3/2/07
to
Bronwyn,

Just to make sure..Because we are having trouble duplicating this issue.

You copied the updated agent files into ZFS_AGNT\ntagent\bin and
the ini file is in ZFS_AGNT\ntagent\ini

Bronwyn

unread,
Mar 12, 2007, 4:37:25 AM3/12/07
to
On 3 Mar, 03:02, "Jared Jennings" <jaredljenning...@SPAMmyrealbox.com>
wrote:

Hi Jared - yes, I do have the files in the locations above. Are you
using the filter I sent through? Could you send me your ini?

Regards,
Bronwyn.

Jared Jennings

unread,
Mar 12, 2007, 6:34:37 PM3/12/07
to
Bronwyn,

At this point, I think it's best that you open a SR. I am unable to test
this at this time and it would take to long for me to play the middle man
for you between Novell.

Sorry I couldn't help more.

0 new messages