SPECTRUM IM. SSA 3.0: Service AND Event/Alert Umbrella DACHSUG 2011



Similar documents
CA Spectrum. Certification User Guide. Release 9.4

Metering PDU Manual DN DN-95602

IAC-BOX Network Integration. IAC-BOX Network Integration IACBOX.COM. Version English

CA Virtual Assurance/ Systems Performance for IM r12 DACHSUG 2011

AnyWeb AG / ITSM Practice Circle / Christof Madöry

Brauche neues Power Supply

(51) Int Cl.: G10L 15/26 ( )

Syslog Analyzer ABOUT US. Member of the TeleManagement Forum

mbits Network Operations Centrec

Virtual Address Mapping

NNMi120 Network Node Manager i Software 9.x Essentials

Diagnostics and Troubleshooting Using Event Policies and Actions

SolarWinds Certified Professional. Exam Preparation Guide

Kap. 2. Transport - Schicht

NMS300 Network Management System

OpManager MSP Edition

Vital Security Web Appliances NG-1100/NG-5100/NG How to Use Simple Network Management Protocol (SNMP) Monitoring

Dial-Up VPN auf eine Juniper

Upgrading Your Skills to MCSA Windows Server 2012 MOC 20417

Embedded Software Development and Test in 2011 using a mini- HIL approach

Best Practices: Modeling Virtual Environments in SPECTRUM

DATA is just like CRUDE. It s valuable, but if unrefined it cannot really be used.

WHITE PAPER OCTOBER CA Unified Infrastructure Management for Networks

CA Spectrum. Microsoft MOM and SCOM Integration Guide. Release 9.4

I-Q SCHACHT & KOLLEGEN QUALITÄTSKONSTRUKTION GMBH ISO 26262:2011. Liste der Work Products aus der Norm

WHITE PAPER September CA Nimsoft For Network Monitoring

J2EE-Application Server

FOR TEACHERS ONLY The University of the State of New York

CA Spectrum and CA Performance Center

Enhancements to idrac7 Alert Notification

LINGUISTIC SUPPORT IN "THESIS WRITER": CORPUS-BASED ACADEMIC PHRASEOLOGY IN ENGLISH AND GERMAN

(51) Int Cl.: H04L 29/06 ( ) H04L 12/26 ( ) H04M 3/22 ( ) H04M 7/00 ( )

CA Spectrum MPLS-VPN Manager

An Overview of SNMP on the IMG

It should be noted that the installer will delete any existing partitions on your disk in order to install the software required to use BLËSK.

Processing Dialogue-Based Data in the UIMA Framework. Milan Gnjatović, Manuela Kunze, Dietmar Rösner University of Magdeburg

AnyWeb AG

Search Engines Chapter 2 Architecture Felix Naumann

Installation Sophos Virenscanner auf Friedolins Linux Servern

CA Data Center Infrastructure Management r4.3: Administration Bundle

SNMP Monitoring and SWG MIB

Kapitel 2 Unternehmensarchitektur III

quick documentation Die Parameter der Installation sind in diesem Artikel zu finden:

RSA Authentication Manager

EWS930 SNMP WIZARD FOR CATVisor EMS SERVER

T H E P O W E R O F B U I L D I N G A N D M A N A G I N G N E T W O R K S. Operations

BPPM 9.5 Architecture & Scalability Best Practices 2/20/2014 version 1.4

Lab Configure IOS Firewall IDS

Upgrade-Preisliste. Upgrade Price List

Device Integration: Checkpoint Firewall-1

Nimsoft for Network Monitoring. A Nimsoft Service Level Management Solution White Paper

External Device Management - Using SNMP - Enabling the Next Wave of Connectivity

Pre Sales Communications

Exchange Synchronization AX 2012

Quick Installation Guide Network Management Card

Monitor Room Alert 7E With PageR Enterprise

BlackBerry Enterprise Server

Power Supply SNMP Interface User Manual for SRL versions

Jetzt können Sie den Befehl 'nsradmin' auch für diverse Check-Operationen verwenden!

CA Nimsoft Monitor. Probe Guide for Internet Control Message Protocol Ping. icmp v1.1 series

CA Spectrum. Alarm Notification Manager User Guide. Release 9.4

SAP Enterprise Portal 6.0 KM Platform Delta Features

Dokumentation über die Übernahme von. "GS-R-3" (The Management System for Facilities and Activities) "Sicherheitskriterien für Kernkraftwerke"

AppWall SIEM Integration Guide

Nokia Siemens Network NetAct For Juniper. Mobile Broadband Ethernet and IP Assurance

SNMP Management of KIV-19s using the. TELEGRID KIV-19 Remote SNMP Proxy (KRSP TM )

CA SPECTRUM. Redefining Network Fault Management. CA Network & Voice Management Solutions CA SPECTRUM CA ehealth CA ehealth for Voice

APPLICATION NOTES High-Availability Load Balancing with the Brocade ServerIron ADX and McAfee Firewall Enterprise (Sidewinder)

A10 Networks Load Balancer

How To Use Mindarray For Business

How to create Event Filters directly from the Event Viewer

Cisco IOS MPLS Management Technology Overview. Enabling Innovative Services. February Cisco Systems, Inc. All rights reserved.

HP OpenView Internet Services. SNMP Integration with HP Operations Manager for Windows White Paper

A FAULT MANAGEMENT WHITEPAPER

Vergleich der Versionen von Kapitel 7 des EU-GMP-Leitfadens (September 2012)

Microsoft Nano Server «Tuva» Rinon Belegu

Getting Started with. Avaya TM VoIP Monitoring Manager

WhatsUp Gold vs. Orion

Timebox Planning View der agile Ansatz für die visuelle Planung von System Engineering Projekt Portfolios

BlackBerry Enterprise Server Version: 5.0. Monitoring Guide

Integrating Trend Micro OfficeScan 10 EventTracker v7.x

The DANTE NOC Network Monitoring System

CA Spectrum and CA Service Desk

CA Spectrum. Cisco Device Management Guide. Release 9.4

EventTracker: Integrating Imperva SecureSphere

Microsoft Certified IT Professional (MCITP) MCTS: Windows 7, Configuration ( )

Technical Overview CM-16 Climate Monitor. Get yours direct at:

Monitor TemPageR 4E With PageR Enterprise

Software / FileMaker / Plug-Ins Mailit 6 for FileMaker 10-13

Citrix NetScaler Best Practices. Claudio Mascaro Senior Systems Engineer BCD-Sintrag AG

Starting Guide - Poseidon 3265 First steps for remote monitoring with Poseidon & GSM

Cover. White Paper. (nchronos 4.1)

.Trustwave.com Updated October 9, Secure Web Gateway SNMP Monitoring and SWG MIB

Kaseya 2. User Guide. Version 7.0. English

How To Teach A Software Engineer

Transcription:

SPECTRUM IM Infrastructure Events and Alerts Overview Event Management and Correlation Event Rules Condition Correlation Event Procedures Event Integration South-Bound-GW Event Notifications SSA 3.0: Service AND Event/Alert Umbrella DACHSUG 2011

Infrastructure Events and Alerts

What is an Event versus an Alarm? Events An event is a SPECTRUM object that indicates that something significant has occurred within SPECTRUM itself or within the managed environment. Can be created also manually through Event Configuration Editor, imported via MIB Tools or created by editing the Event Configuration Files. Alarms - An alarm is a SPECTRUM object that indicates that a user-actionable, abnormal condition exists in a model. Typically, SPECTRUM generates an alarm when an event specifies that one should be created. SPECTRUM can also generate an alarm based on the results of a SpectroWATCH violation, or as a result of SPECTRUM detecting an abnormal situation not based on an event (inference handler based).

Events in Spectrum Oneclick

Alarms in Spectrum Oneclick ECE

Alarms information in Spectrum Oneclick PCause code is specified for each alarm that displays the Probable Cause information for an alarm. PCause files control what is displayed in the Probable Cause information. PCause files are static, event variables information. The dynamic alarm title attribute can be populated with an Event Variable. This allows for a single Probable cause to have a dynamic alarm title. The dynamic varbind ID is 76620 (or 0x12b4c). See Event Configuration User Guide.pdf

Example: Trap Forwarding of external Managers and Event/Alarming in SPECTRUM Example: Checkpoint FW Manager File AlertMap > Maps Trap to Event 00561001 SS/CsVendor/<customer>_Checkpoint Content: 1.3.6.1.4.1.2620.1.1.6.0 0x561001 1.3.6.1.4.1.2620.1.1.11.0(101,0) -------------------------------------------- File: EventDisp > Maps Event to Alarm 0x00561001 Content: 0x00561001 E 50 A 1,0x00561001,U ------------------------------------------ File: CsEvFormat/00561001 > Event Message Content: {d "%w- %d %m-, %Y - %T"} - Device {m} of type {t} generated. Event Message is: {S 101}.(event [{e}]) --------------------------------------------- File: CsPCause/Prob00561001 > Alarm Message Content: FIREWALL STATUS ALARM SYMPTOMS: A Firewall System status is over the treshold. PROBABLE CAUSES: 1) A Trap from the firewall system was send 2) Firewall System has to high system usage RECOMMENDED ACTIONS: 1) Check the Event Message in the SPECTRUM Alarm Manager 2) Inform the Firewall Administrator 3) Check the thresholds on the Firewall System ---------------------------------------------

Event Management and Correlation

Spectrum Event Correlation Fault Suppression Downstream device fault suppression (including VPM) Child (Port/Process) suppression Port flapping Other default EventRules based Correlations Alarm De-duplication Recurring events for the same Alarm Filtering field of the existing alarm. from alarm console. Secondary alarms are just those with a lesser severity.

Extending Event Correlation There are a number of ways that SPECTRUM Event Correlation capabilities can be updated and enhanced. They are listed below: 1. Simple Event Configuration updates 2. Event Rules 3. Condition Correlation This includes specifying which events generate/clear alarms and event variables to discriminate. In addition, event and alarm descriptions can be modified and enriched. Event rules allow for events to be correlated on individual models (of the same modeltype). Condition correlation allows for multiple events to be correlated across groups of models. Events (or the be inferred. 4. Event Procedures - Complex expressions that allow for events to be manipulated at a very granular level, including creating new event variables and asserting events on models other than the source (between different models(types)). 5. You can also influence the automatic Faultisoltion Event and Alarming behavior

Inductive Modeling Technology Setting Fault Isolation Parameters 1. Settings in Component Details view of the VNM model 2. See also for example Modeling and Managing Your IT Infrastructure Administrator Guide.pdf

Event Rules Event Rules permit you to specify a more INTELLIGENT decision-making to indicate how an event is to be processed. Event rules allow you to correlate multiple events on the same model, not to groups of models. Event Rules available: Event Condition Event Pair Event Rate Event Series Event Counter Hearbeat Single Event Solo Event

Examples: Event Pair & Event Condition GUI ConditionEventRule for SPM Tests: Generate event(alarm) 0xfffffffa only, if var.1 (SPM-Test name) starts with AUA, and deliver Var 1,2,3,9 EventDisp File 0x0456000b E 20 R Aprisma.EventCondition, "regexp({v 1},{S \ \*\"})", "0xfffffffa 1:1,2:2,3:3,9:9"

Example: SPECTRUM Condition Correlation Editor LSP Alarms generate one MPLS Backbone Error Alarm Create Condition: left side (eg Backbone Error (type: counts) Error these but show as symptomes

Example: Event Procedures (in EventDisp Files) # wenn Event beecc001 erzeugt wird, führe folgende Procedure aus ( Johannes Kroupa, CA) # Ziel: wenn dieser SPM-Event/Alarm auf dem Device erzeugt wird, dann soll auch ein Event/Alarm auf dem entsprechenden Port erzeugt und ausgewertet werden 0xbeecc001 E 50 P " \ ForEach( \ GetModelsByAttrValue( \ { H 0x10069 }, \ ReadAttribute( \ { C CURRENT_MODEL }, \ { H 0x129fa } )), \ { V portmh }, \ { V dummyretvalue }, \ { U 0 }, \ If( \ Equals( \ ReadAttribute( \ { V portmh }, \ { H 0x11348 } ), \ GetEventVariable( { U 1 } )), \ CreateEventWithAttributes( \ { V portmodel }, \ { H 0xbeecc002 }, \ GetEventAttributeList()), \ Nil()))" Die Proc findet zuerst mal alle Modelle (GetModelsByAttrValue), d.h. alle Ports (und Apps..) des Devices. - in der Schleife behandelt). Dann Check, ob ifindex (0x11348) am Port derselbe ist wie Varbind 1 im Event, um den richtigen Port zu finden. (z.b. hier dann IP Adresse) Dann, falls der Port matched (hier z.b. ifindex), wird ein neuer Event auf ihm generiert (0xbeecc002), mit denselben Varbinds wie der ursprüngliche Event. Falls der Port nichts matched, wird auch nichts gemacht (Nil()).

CA Event Integration (EI) - Architecture

Southbound Gateway Non-SNMP, LogFiles (SYSLOGs!), DBs, V.24 and others Events and Traps from different Sources For example Logfiles, Traps, Element Managers via XML, SNMP and CORBA etc. Vendor Specific EMS via Trap Vendor Specific EMS via XML double click

Event Notification

Alarm Notification CA Spectrum, alarm-processing applications and SANM (Policy Manager) work together in the alarm monitoring process.

thank you