1752788 Members
5776 Online
108789 Solutions
New Discussion

IMC Syslog Template for STP

 
dany_
Occasional Collector

IMC Syslog Template for STP

Hey guys, 

i´m trying to get alarmed if there are any messages like "cst root changed to XY" .  -> sometimes a part of the network switch the root and we dont now why. 

So i want to get informed if there are any of those problems. 

If i browse the Syslog of IMC, i see logs like "stp: CST Root changed from 32768: (this device) to 0: 2c59e5-70c100" 

-> How to get the alarm to those messages? 

I searched syslog to alram but didn´t find a machting template for this. 

If i have to create a new template, what´s the right syntax for this? 

 

Thanks 

Dany

 

 

4 REPLIES 4
drk787
HPE Pro

Re: IMC Syslog Template for STP

Hi Dany,

IMC uses system- and user-defined rules to determine which of the Syslog events received by IMC
should be considered alarms. IMC includes system defined rules that, upon installation, generate
alarms based on Syslog entries received by IMC.

You can also create rules that generate alarms based on Syslog events received by IMC. You can
create these from scratch or you can copy an existing system defined rule and modify it to meet your
needs. You also have the ability to enable and disable system- and user-defined rules. The following
information explores the use of Syslog to alarm rules

 

1. Navigate to Syslog to Alarm.
a. Click the Alarm tab from the top tabular navigation system.
b. Click Syslog Management on the left navigation tree.
c. Click Syslog to Alarm under Syslog Management on the left navigation tree.
IMC displays all Syslog to Alarm rule entries in the Syslog to Alarm Rule list displayed in
the main pane of the Syslog to Alarm window.

You may refer to page 688 of the below admin guide for more information.

https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=c05367532

Thank You!
I am an HPE Employee

Accept or Kudo

IvoVelikov
HPE Pro

Re: IMC Syslog Template for STP

Hello,

I just want to add, that in the process of creating Syslog to Alarm, you may not be able to see a syslog that matches your creteria. You need to add a rule, in order to add a rule you need to select a suitable syslog templete (one of the required fields you need to fill in). If there is no suitable syslog template, you need to create one, navigate to Alarm - Syslog Management - Syslog Template and click add. Then you have the oppotunity to create a matching content.

Regards


I work for HPE

Accept or Kudo

RPapaux
Valued Contributor

Re: IMC Syslog Template for STP

Hello,

Alternatively you can also enable your network devices to send STP related SNMP traps (if not yet done).

Then you must look IMC trap recipient, select the traps you are interested in, and convert these traps to Alarms with the appropriate severity level.

So you can basically achieve the same result, without building a syslog template.

Ray

 

 

dany_
Occasional Collector

Re: IMC Syslog Template for STP

Hi guys ,

thanks for your support!

i just found traps for my problem:

MSTP Root Bridge Change and RSTP Root Bridge Change.

That worked for me.

 

Thanks

Dany