Hi,
Tried searching and hope this is not a redundant question. In particular, Are there published numbers for sustained trap and syslog processing? It's understood your mileage may vary due to hardware and environment.
Reason I'm asking is we're probably one of the last shops still running IBM NetView 7.x under AIX. A few days ago we had a trap storm that pretty much flipped NetView on its back. The trap daemon appeared to not be dropping traps, but downstream processing was either delayed or intermittent. We weren't sure the same traps were hitting Orion, but they were. Our Orion instance managing a large number of network instances was taking the trap beating and asking for more. In fact, I used Orion's data during post mortem, and it sure beat grepping through trapd.log.
When IBM provided numbers for NetView AIX, sustained was defined as 'no time limit, number of traps per second with 0 dropped traps and no lost downstream trap processing'.
Thanks!