rjnicholson

Comments

  • He is talking about the Advanced Alert manager. You access this directly on the server that is hosting the NPM installation. Should be under.. Start>All Programs>SolarWinds Orion>Alerting, Reporting, and Mapping>Advanced Alert Manager. Once open find the Alert build for the Nodes, and open it up. Then you can see the…
  • If it's an advanced alert then it would be condition based. So you wouldn't assign it a specific device, but you would create conditions that match fields or properties, and then add a condition of what to alert upon, so the alert can cover 1 device or a group of devices. IE. This is one of my alerts using simple…
  • Keep track of your work and post your UnDP's that you create for other users to download and check out if you want. I would also post this information with the OID work you have done into a feature request for Nexus support. These are some great things that almost anyone running a Nexus switch would like to see, and be…
  • Also, keep in mind with SLT export only happens when an event occurs or is triggered by an ACL or another protocol that would generate an event. This will then be exported via NetFlow v9 transport, and any NetFlow software that supports v9 should be able to read it, but you will only have data populated when an event is…
  • This would be done by the Firewall guys. The commands I were refering to are Cisco based, but the underlying function is the same on any firewall. You just need a Firewall guy from your company to jump in one and watch the traffic you kick off when you try to poll out. He should be able to see the denied traffic and what…
  • Yes I use a higher frequency on my Production environment. That with Syslog and Event Traps it has made my Teams really proactive instead of reactive to issues. We also are going through a Huge SAP roll out to replace our current ERP system. I enjoy it because they are rolling out a full Linux environment now and getting…
  • HAHA thats a massive ammount of connection you have allowed there! I don't think there would be enough zombie systems to DDOS that many connections..
  • Might I suggest that you create an ACS account for NCM only that has no expiration, and have all your nodes use this account. ACS can lock it down so it can only run certain commands and functions. I do this for all my companies I have worked for and it takes a huge headache off of their shoulders using personal accounts.…
  • That's the one I was looking for, but couldn't find it. Thanks
  • Good call. Didn't think of adding them to the group, but since you can.. There ya go!
  • Sure it would be able to alert on BGP dropping. If you are creating Syslog alerts off of this you should be creating the alert of the Ajacency change message. This message should come from both sides of the router that you have BGP operating with since adajacency has to be up on both sides to pass BGP traffic, so a link…
  • I just want to add.. That's an intense amount of config files.. Even more so if they are mainly Cisco devices.. Firewall configs can get big, but router configs are generally not that big when you aren't including the routing table. They are only text files in the end. If it's for compliance then I would say you are WAY in…
  • This is why I only allow a singular admin account to be used to control functions of Orion. When someone builds stuff this way and leaves disaster can happen once that account is deactivated.
  • Use Custom Properties in the Editor on the main server. This will soon be integrated into the web console in a coming release, but for now you can use the stand alone Custom Property Editor. Add Custom Properties for the different groups and then populate the value for the nodes. Once done use this to filter. Way more…
  • I will have to dig more once I can get back to my work station, but the only thing that sticks out that I see differently is it looks like you are using Telnet, and I use SSH, but this shouldn't be an issue. Let me dig some more and run some test downloads to watch my logs as well.
  • Let me dig up my UnDP's I built for F5's and I will post them here. Maybe they will help you out quicker then digging on your own until 10.4 comes out.
  • I know but the original question was about using SFTP/SCP to do the automation with. Just was stating that again these tools can't be used only TFTP. I would check out NCM for this if really interested in doing this in a controlled fashion with automation. 
  • It's logging over 83,000,000. I take it since that is such a large number Orion can't read the value correctly with the variable input I'm guessing? Anyone able to clairify this? I have other Juniper devices that were throwing errors as well, but were way under this value and came through properly. Thats a ton of errors in…
  • Ya, that is a downside if you are a LAN environment using a ISP provider for your MPLS.. No control over the MPLS PE/CE router hurts!! We have the same issue, but luckily got the provider to give us SNMP and point syslogs for us to our IP's as well. It was a battle, but when you pay a provider enough money they should at…
  • Go to that actual device and see what it is. These are the events from the Group the device belongs to, and are only telling you that a member of the group is having an issue. It's not telling you what component/interface/volume that is causing spring084001_r.tcp to go into a warning state. Drill into that specific device…
  • What type of hardware though? If you spec for the environment this isn't an issue. NTA and its performance relates to what type of hardware power and resources that you have available for it.. Higher end setups and configurations like Deltona posted can certainly handle 100% Optimization and only seeing 3,000flows/sec. As…
  • You can manage SAM template creds under SAM Settings once you hit the SAM homepage from the SolarWinds Home Screen.. Goto SAM, and in the upper right you should see SAM Settings. Once in the Settings Tab for SAM the Panel label Global SAM Settings has a link the SAM credentials manager. Hope this helps. It will allow to…
  • You could be! I don't get to use the product until next year when I get my budget to buy it. I will probably do a POC on it as soon as I get close, but yes I think you could be on to something, but the bigger issue at the moment is how did this company not set up TCP timers to kill dormant connections. That just seems like…
  • It's a lot better and getting better each time. You now have access to the CPE editor from the manage nodes page which is nice, and you can still export your Properties to excel.. Mass edit and import them back in. Then you can even go a step further and you can select that property to have drop down menus and it will Auto…
  • I'm aware of the ways VNQM can write SLA transactions to a node, and have used the functionality a few times. The issue I was having was the telnet emulation that VNQM was doing was always wanting to pass "enable" to put me in privileged mode which for the PRI polling is not needed since the show commands used can be run…
  • I like to install my NPM and SAM together and I use 2 polling engines to separate Test/Dev and Production environments, and to keep my polling intervals at a higher frequency. I keep my SQL database on it's own server and connected to my Primary and Secondary Polling engines with a direct connect via cross over cable. I…
  • I recommend moving to the latest version of NCM. There have been significant changes from 7.0.2 to 7.1.1.
  • No problem I'm just glad I said something wrong before it caused somebody some pains!! Thanks for pointing this out to me as well. Next time I will be sure to double check the KB for information correlation!
  • YES!! You sir are the Genius of the day in my book.. Thank you !
  • I am seeing my SWJobEngineWorker2 dying on my secondary poller as well after a recent upgrade to SAM 5.2. I haven't seen the Alert Manager issue yet though, and I use mine daily. I have been able to restart the JobEngineWorker2 which is easy to spot since all polls from the poller won't write to the DB and I use the pre…