Comments
-
I'd think of possibly starting with the base NPM/SAM combo with smallest license available and see if that covers most of what you need to monitor.
-
Maybe a quick and dirty way to get this is the following report from content exchange: At least as a starting point if you are not a DBA :}
-
Dumb question... what does EMEA mean?
-
Some of the partners are pretty good... Loop1 comes to mind.
-
I ran into this same problem when we also bought into RiverBed. Our solution was to send the flows to RiverBed and then have the RB appliances forward to Orion. SW should consider same options.
-
I would use something like plixer: Free NetFlow Forwarder or NetFlow Duplicator - Plixer.com Basically, it receives the UDP flow frames (NetFlow, IPFIX, sFlow, NetStream, jFlow, cflowd, etc.), changes the destination IP address while preserving the original source IP address and forwards the datagrams onto one or more…
-
Healthcare isn't easy these days.
-
Not yet but we are going with two SQL Server 2016SP1 for Orion and the flow database. I suppose we could try just one but I already have enough elements and APE's that I'm afraid all the flows are going to slow down the Orion database too much and made the UI performance worse than it already can be sometimes.
-
This new version of NTA is going back to using MS SQL Server after having us use this noSQL database for the past few versions. My big question is do we need two SQL Servers now or just one will suffice for Orion DB and the Flow DB? This is going to be pretty new for all of us.
-
Looks good to me! Palo Alto support has been a long time coming. We exclusively use Cisco ASA-X with firepower and Palo Alto f/w.
-
This is good I'm about to install a new Orion instance with SQL Server 2016 and SP1 slipstreamed in.
-
I export flows from my vswitches to NTA today. The hardest part is setting it up right in EXSi.
-
sorry for the duplicate post... thwack was fracked!^#^&$@^%@!$%@ Note: I deleted duplicate posts on 3/23~ Marie Note: Thanks Marie :}
-
Chris- I know it's a little more than a report but still excited about: * Endpoint-centric Traffic Analysis Resources - ability to see traffic analysis data related to a specific Orion node (non-NetFlow source). For example, the ability to open an Orion node details page for a Windows server and see the top conversations…
-
I know it's probably beyond the scope of just a new report but the: Endpoint-centric Traffic Analysis Resources - ability to see traffic analysis data related to a specific Orion node (non-NetFlow source). For example, the ability to open an Orion node details page for a Windows server and see the top conversations to/from…
-
I think I see what you are saying... how do you poll for or report depending on whether the Node is physical or virtual. In report writer I can't seem to find a property that returns either physical or virtual for a node either. It's obvious it must be in the database somewhere because as you said you see physical or…
-
Wow a very old NPM and a brand new one... Was someone in the middle of an upgrade or something? Could you give us some background on what the situation is? I'm a little confused what's happening and where you're at? Without knowing much you want to get on 11.5 not 10.3... If you are under support that will definately help.
-
Some other advantages: Developed in C++, which make it fast, small and effective. Portable and doesn't require any installation. Don't write anything to the Registry or to your profile folder. This means that you can use from a USB Flash drive, without leaving traces in the computer that you use. Can be used from…
-
This is one of those things that's just been there since like version 9.x I think.
-
These have come in handy for me.
-
These are pretty cool Larry!
-
that lights display is pretty crazy!
-
This could be a bug if the numbers are outright wrong. There's a new forum for feature requests in Thwack and the one for NPM is at: http://thwack.com/forums/57.aspx
-
You were routed to another company?
-
You wouldn't happen to have the windows firewalls running would you? Try turning them off and see if this fixes the problem. The admin guide lists all the ports you need enabled if you want to create a rule. I can't imagine how this could happen unless some ports are being blocked.
-
This outage report for last month is a custom sql report that does some of what you are talking about:
-
I'd try the posted UnDP above... if that doesn't work you need the OID's for what your looking for then test them with UnDP. If you come up with combo that works post it for everyone else with some information about the model etc. it works with. I found a ton of Eaton OIDs here if you can't find them from vendor: OID…
-
This may not be good that no one else has seen this before... Strange thing is it only happens on a few Alerts and the rest are fine. If I clear them they fire again and come back again with AHS in the links.
-
So is this happening to everyone when loading the latest version???
-
There's a few ways to look at your issue. Yes it's true that if a server reboots and comes up between polls that NPM won't register the outage as it doesn't see a lost poll. There's a few ways to report on the reboots... one is using APM, another is using an snmp agent on servers and sending trap when a server reboots or…