- Community Home
- >
- Networking
- >
- Legacy
- >
- PCM
- >
- Re: PCM+ syslog policy issue
-
- Forums
-
- Advancing Life & Work
- Advantage EX
- Alliances
- Around the Storage Block
- HPE Ezmeral: Uncut
- OEM Solutions
- Servers & Systems: The Right Compute
- Tech Insights
- The Cloud Experience Everywhere
- HPE Blog, Austria, Germany & Switzerland
- Blog HPE, France
- HPE Blog, Italy
- HPE Blog, Japan
- HPE Blog, Middle East
- HPE Blog, Russia
- HPE Blog, Saudi Arabia
- HPE Blog, South Africa
- HPE Blog, UK & Ireland
-
Blogs
- Advancing Life & Work
- Advantage EX
- Alliances
- Around the Storage Block
- HPE Blog, Latin America
- HPE Blog, Middle East
- HPE Blog, Saudi Arabia
- HPE Blog, South Africa
- HPE Blog, UK & Ireland
- HPE Ezmeral: Uncut
- OEM Solutions
- Servers & Systems: The Right Compute
- Tech Insights
- The Cloud Experience Everywhere
-
Information
- Community
- Welcome
- Getting Started
- FAQ
- Ranking Overview
- Rules of Participation
- Tips and Tricks
- Resources
- Announcements
- Email us
- Feedback
- Information Libraries
- Integrated Systems
- Networking
- Servers
- Storage
- Other HPE Sites
- Support Center
- Aruba Airheads Community
- Enterprise.nxt
- HPE Dev Community
- Cloud28+ Community
- Marketplace
-
Forums
-
Blogs
-
Information
-
English
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
02-02-2012 04:51 AM
02-02-2012 04:51 AM
PCM+ syslog policy issue
Hi,
I have a PCM+ that´s working properly but i have problems with policies:
- I receive logs from network switches on the PCM+ syslog correctly but when i configure a policy based on these logs it can´t be triggered. The policy is well configured because when i apply it based on traffic activity threshold it works.
Can you help me?
Thank you,
- Tags:
- syslog
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
02-03-2012 11:28 AM
02-03-2012 11:28 AM
Re: PCM+ syslog policy issue
Hi,
Unfortunately PCM doesn't support policies based on data from syslog messages, only data from PCM events. PCM events are generated from the reception of SNMP traps from devices, so perhaps you can configure the switch(es) in question to send traps for whatever you're trying to capture out of the syslog ...?
The reason for this is that syslog formats vary wildly and parsing the various messages with any sort of accuracy for content that can then be plugged into a policy (e.g. IP addresses, port numbers, ifIndexes, etc.) is extremely error-prone. In contrast, SNMP traps can be parsed for their content by OID, meaning that PCM can always rely on finding the bits of data it needs without the guesswork and potential error involved in parsing a syslog string.
Regards,
SVB
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
02-06-2012 04:23 AM
02-06-2012 04:23 AM
Re: PCM+ syslog policy issue
Hi,
Thank you very much for your as¡nswer but, if i understand, you mean that if i have a switch that send logs to the PCM+ own integrated syslog I can´t configure a policy based on these log messages?
So, how can i do to configure a policy that notify me if a port or link goes down?
Thank you,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
02-07-2012 09:38 AM
02-07-2012 09:38 AM
Re: PCM+ syslog policy issue
Ibon,
PCM collects syslog information so that it's centrally available, but because of the variability in syslog record content and format PCM does not process syslog messages as policy triggers.
If you want to trigger a policy to notify you of a particular event, such as a port changing state, you have to do so based on SNMP events. If the device can generate an SNMP trap for the event you're interested in - and I believe that the HP switches are capable of generating a trap for port up/down - then you can create a policy in PCM that will notify you via email or dialog box on the PCM console.
Regards,
SVB
Hewlett Packard Enterprise International
- Communities
- HPE Blogs and Forum
© Copyright 2021 Hewlett Packard Enterprise Development LP