Hello all! I've been looking through searches on here for someone that may be having the same issue I'm having, and decided to post. I am trying to set up an alert in the trap manager that will take a portion of the trap detail and trigger an email to be generated. The traps are coming in from a CISCO ASA firewall, via the syslog. This means taht the Trap Type is "CISCO-SYSLOG-MIB:clogMessageGenerated". I am trying to get an email sent when the IP address 192.168.1.1 is seen in the Trap Details.
Currently my Orion is sending emails for other alerts, so the mail setup and mail server are fine. The Trap Rule is setup with * in almost all the fields (General, DNS Hostname, Community String..) In the conditions box I am using "CISCO-SYSLOG-MIB:ClogMessageGenereated contains 192.168.1.1" Alert Actions are to send an email with the default values in the subject and body. I am getting a lot of traps with that ip in the details, but nothing seems to be triggering an email. Am I doing something incredibly stupid here, and just not seeing it? Any help would be greatly appreciated! Thanks.
Orion 9
Xtort