Comments
-
I put this on a resource on a page that I do Solarwinds checks from. It will tell you what nodes are not responding to SNMP for more than 2 hours. You can use it, or use bits of it to fit your need. NCM backups have pretty much nothing to do with SNMP, so a bit confused on that. NCM inventory uses SNMP though… SELECT…
-
Changing credentials is harder than adding a new one to the devices, migrating to it, then removing the old credential. That way nothing should ever fail…
-
Check your scheduled reports maybe?
-
Didn't wait long enough! Changed the timeframe I was looking at from 1 hour to 15 minutes, and it appears to be working like a champ!!
-
There is a built in section in the Netflow Settings for IP address groups. You can create your own groups and add your IP ranges, single IPs and subnets. One group can have multiple ranges or whatever. Then, in Netflow Traffic Analyzer Summary page, click on the "Flow Navigator" in the left side. Go down to "IP Address…
-
Have you looked to see if there is an OID that corresponds to this value that you can poll instead? Much easier than parsing that table if it exists… Set up a Custom Poller at that point and go that route.
-
At that point you're just using SW as a SIEM, if it was a low # of logging entries, you might find the built-in logging to be sufficient, but I wouldn't want to do DC's without their SEIM product. Security Event Manager I think? But, you could just as easily use any other SIEM, like Splunk or whatever.
-
Not quite sure what you're asking? If you're talking about backing up configuration archives, you should back up what is in the "Config Archive Folder Locations" to wherever you want? You'll want to set up a windows job to actually copy them, you'll have to probably set up a service account so permissions are correct for…
-
40,000 lines? If I had to guess I'd say Forticr*p? I don't believe there is a maximum lines setting, there is a minimum though. I think it will eventually time out if a config download is idle, but if its still transferring I think you'll be ok. I couldn't find a setting for it, but if it exists it would be under NCM…
-
Assign the devices to groups and restrict it that way? Group assignments can be done dynamically based on quite a few different things, make sure you look into that. The restrictions are implemented in the Users account under "Account Limitations", you should look through that to see if an easier way than creating a group…
-
Or, open a ticket and they'll help you with it…
-
You'd first have to enable the audit policies in event viewer on the DC to make sure that events are created for login success/failure, and audit credential validation for failure. Then you'd get events in Event Viewer that correspond to that. You could see them there, or if you're sending logs from the DC, you could…
-
Yea, I'm was off on Friday, so I missed that question, and have no chance to go back? Should at least be available for one business day after the mission closes…
-
I haven't, but I'll keep my eye out to see if I do..
-
Check out Orion.OLM.ProcessingRule and Orion.OLM.ProcessingRuleActions. Not totally sure how they relate or what else might be involved.
-
https://github.com/solarwinds/OrionSDK
-
The first one was too simple, considering I've been a member since then!! 😁
-
The limit will probably be on your database server rather than your SWOSH environment. With the old licensing if you pushed the limit on whatever server was receiving your flows, you had to purchase APEs (Additional Polling Engines). With the new licensing model you can deploy as many APE's as you want. Since the flows are…
-
I got it installed this morning and am seeing some stuff on the dashboard. A bit weak IMHO, but has some useful stuff. It has a "Routing Summary" with some good stuff, another one on "Routing Tables" that lumps all of your routing tables together. Kind of ugly, has to be a better way. Then a "Routing Neighbors" tab that…
-
Have you upgraded to the latest? Supposedly there is a new routing dashboard they just put in that is really nice. Haven't done it myself yet, in production at least.
-
"Always on availability" is an SQL concept. It depends on how available you want the data to be as to the number of nodes in the cluster? I've never actually seen anyone go to the trouble for a Solarwinds instance, It really depends on how critical the data is and how much you want to spend to get a little more…
-
No, you have to use either SWQL Studio, or put it in a resource. I personally have something similar in a resource in one of my pages. Easier than loading SWQL Studio. Edit a page, go to page settings, add a resource to one of the columns of the type "Custom Query". Then preview the page and make the title you want and put…
-
Wow, very little info here. But, wild guess. Problem with a rule on the firewall.
-
So, you want them both to be bad, or both to be good? You should note that there is a couple arrows in the middle of the link, pointing at each other. These are signifying that one side of the link is outbound from one interface, while the other side is showing outbound on the other side of the link. Neither interface…
-
Well, it depends on what you want in the alert. Using Variables, you can do things like have the name of the node dynamically change and have just one alert for a given trap. You can probably even have the name of the trap as a variable and stick that in there, and do one alert for all of them? However, trap names are…
-
Maybe one of these might help? https://documentation.solarwinds.com/en/success_center/whd/content/helpdeskconfigureoutgoingemailaccounoffice365.htm
-
I don't think we're having that issue? So you have configured the Netflow on the device to send to the VIP and not the primary poller, right? Do you have firewall rules that might prevent it? Are both of your HA pair on the same subnet?
-
Well, unless you have the HA device managed via an OOB interface, its probably not going to be managed well. That does depend on the brand and how they implement it though. If you do manage it through an OOB interface, you can always add the connections manually if they don't show up? Not sure how useful it is though.
-
Is SAML an option? Much easier to work with if so…
-
Configure the firepower device to ignore traffic like that from the SW server. Just pass it through.