Hi Jane,
Yes, I've been referring the great paper of yours. Thank you for sharing it.
The devices traps do have a few varbinds associated with them. However those are very specific to a trap. The "eventKey" fileld is empty in all traps. Essentially "eventClassKey" is the only field seem unique.
I've created python lists for the "ok", "critical" and "warning" eventClassKey's.
Not sure if evt.summary will be used for auto-clear besides for a duplicate. If it does, then as long as I refer the eventClassKeys, the events will be processed / auto-clear / closed as long as it gets matched.
The events gets sent to an EMS system. I've setup triggers to do the forwarding. In that script, I can pass on the $(evt/eventClassKey) as a "service". Even if there is different varbinds for the same
eventClassKey, I will have the same service listed separately on the EMS having different event summary. At least I hope it would work that way.
Do you think that would work?
I'm not sure how I can use "eventKey" here and how it will make it easier/simpler in any way ?
I was trying to examine the incoming trap using "tcpdump" and "wireshark" but for some reason I don't see trap severity, I think, better idea is to look into the DB to get the trap info. I'll have to look out the query etc.
to get that information.
Thanks