Re: SNMP Trap Monitoring in Nagios XI
Posted: Thu Oct 01, 2020 12:26 pm
I restarted the service manually.
Below is what I see in the /etc/snmp/snmptt.conf
None of them end with the 202 oid.
#
EVENT coldStart .1.3.6.1.6.3.1.1.5.1 "Status Events" Normal
FORMAT Device reinitialized (coldStart)
#EXEC qpage -f TRAP notifygroup1 "Device reinitialized (coldStart)"
SDESC
A coldStart trap signifies that the SNMPv2 entity, acting
in an agent role, is reinitializing itself and that its
configuration may have been altered.
EDESC
#
#
#
EVENT warmStart .1.3.6.1.6.3.1.1.5.2 "Status Events" Normal
FORMAT Device reinitialized (warmStart)
#EXEC qpage -f TRAP notifygroup1 "Device reinitialized (warmStart)"
SDESC
A warmStart trap signifies that the SNMPv2 entity, acting
in an agent role, is reinitializing itself such that its
configuration is unaltered.
EDESC
#
#
#
EVENT linkDown .1.3.6.1.6.3.1.1.5.3 "Status Events" Normal
FORMAT Link down on interface $1. Admin state: $2. Operational state: $3
#EXEC qpage -f TRAP notifygroup1 "Link down on interface $1. Admin state: $2. Operational state: $3"
SDESC
A linkDown trap signifies that the SNMP entity, acting in
an agent role, has detected that the ifOperStatus object for
one of its communication links is about to enter the down
state from some other state (but not from the notPresent
state). This other state is indicated by the included value
of ifOperStatus.
EDESC
#
#
#
EVENT linkUp .1.3.6.1.6.3.1.1.5.4 "Status Events" Normal
FORMAT Link up on interface $1. Admin state: $2. Operational state: $3
#EXEC qpage -f TRAP notifygroup1 "Link up on interface $1. Admin state: $2. Operational state: $3"
SDESC
A linkUp trap signifies that the SNMP entity, acting in an
agent role, has detected that the ifOperStatus object for
one of its communication links left the down state and
transitioned into some other state (but not into the
notPresent state). This other state is indicated by the
included value of ifOperStatus.
EDESC
#
#
#
EVENT authenticationFailure .1.3.6.1.6.3.1.1.5.5 "Status Events" Normal
FORMAT SNMP athentication failure
#EXEC qpage -f TRAP notifygroup1 "SNMP authentication failure"
SDESC
An authenticationFailure trap signifies that the SNMPv2
entity, acting in an agent role, has received a protocol
message that is not properly authenticated. While all
implementations of the SNMPv2 must be capable of generating
this trap, the snmpEnableAuthenTraps object indicates
whether this trap will be generated.
EDESC
~
Regarding the logs I do see that they are coming in as normal in
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip> - Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.12.51.77.95.83.79.65.82.70.95.68.70.84:3M_SOARF_DFT enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip> - Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.7.73.78.71.95.68.83.83:ING_DSS enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip>- Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.13.83.73.83.95.83.79.65.82.70.95.68.70.84:SIS_SOARF_DFT enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
and criticals are coming in as criticals.
Wed Sep 30 16:52:43 2020 .1.3.6.1.4.1.4184.2.0.2 Critical "Fatal" <server ip> - Received trap "oplGenericV2Trap" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.5.1.0:EN92 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:RELOAD - Alert process reload by user request. enterprises.4184.2.5.4.0:2020-09-30 16:52:43 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:55:13 2020 .1.3.6.1.4.1.4184.2.0.2 Critical "Fatal" <server ip>- Received trap "oplGenericV2Trap" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.84.50.52.49.53.72.48.65.72.70:ICOT2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.84.50.52.49.53.72.48.65.72.70.11.80.82.69.67.89.83.69.95.51.77.50:PRECYSE_3M2 enterprises.4184.2.5.1.0:IN13 enterprises.4184.2.5.2.0:4 enterprises.4184.2.5.3.0:DOWN, Interface is not operational- ERROR status for Connection. enterprises.4184.2.5.4.0:2020-09-30 16:55:12 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
But the notifications log doesn't show the OK logs and also doesn't appear to be consistant regarding the information being received.
Below is what I see in the /etc/snmp/snmptt.conf
None of them end with the 202 oid.
#
EVENT coldStart .1.3.6.1.6.3.1.1.5.1 "Status Events" Normal
FORMAT Device reinitialized (coldStart)
#EXEC qpage -f TRAP notifygroup1 "Device reinitialized (coldStart)"
SDESC
A coldStart trap signifies that the SNMPv2 entity, acting
in an agent role, is reinitializing itself and that its
configuration may have been altered.
EDESC
#
#
#
EVENT warmStart .1.3.6.1.6.3.1.1.5.2 "Status Events" Normal
FORMAT Device reinitialized (warmStart)
#EXEC qpage -f TRAP notifygroup1 "Device reinitialized (warmStart)"
SDESC
A warmStart trap signifies that the SNMPv2 entity, acting
in an agent role, is reinitializing itself such that its
configuration is unaltered.
EDESC
#
#
#
EVENT linkDown .1.3.6.1.6.3.1.1.5.3 "Status Events" Normal
FORMAT Link down on interface $1. Admin state: $2. Operational state: $3
#EXEC qpage -f TRAP notifygroup1 "Link down on interface $1. Admin state: $2. Operational state: $3"
SDESC
A linkDown trap signifies that the SNMP entity, acting in
an agent role, has detected that the ifOperStatus object for
one of its communication links is about to enter the down
state from some other state (but not from the notPresent
state). This other state is indicated by the included value
of ifOperStatus.
EDESC
#
#
#
EVENT linkUp .1.3.6.1.6.3.1.1.5.4 "Status Events" Normal
FORMAT Link up on interface $1. Admin state: $2. Operational state: $3
#EXEC qpage -f TRAP notifygroup1 "Link up on interface $1. Admin state: $2. Operational state: $3"
SDESC
A linkUp trap signifies that the SNMP entity, acting in an
agent role, has detected that the ifOperStatus object for
one of its communication links left the down state and
transitioned into some other state (but not into the
notPresent state). This other state is indicated by the
included value of ifOperStatus.
EDESC
#
#
#
EVENT authenticationFailure .1.3.6.1.6.3.1.1.5.5 "Status Events" Normal
FORMAT SNMP athentication failure
#EXEC qpage -f TRAP notifygroup1 "SNMP authentication failure"
SDESC
An authenticationFailure trap signifies that the SNMPv2
entity, acting in an agent role, has received a protocol
message that is not properly authenticated. While all
implementations of the SNMPv2 must be capable of generating
this trap, the snmpEnableAuthenTraps object indicates
whether this trap will be generated.
EDESC
~
Regarding the logs I do see that they are coming in as normal in
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip> - Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.12.51.77.95.83.79.65.82.70.95.68.70.84:3M_SOARF_DFT enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip> - Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.7.73.78.71.95.68.83.83:ING_DSS enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:46:09 2020 .1.3.6.1.4.1.4184.2.0.2 Normal "Status Events" <server ip>- Received trap "oplGenericV2Trap_Ok" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70.13.83.73.83.95.83.79.65.82.70.95.68.70.84:SIS_SOARF_DFT enterprises.4184.2.5.1.0:IN07 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:ACTIVE and the Alert process is monitoring this interface. enterprises.4184.2.5.4.0:2020-09-30 16:46:09 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
and criticals are coming in as criticals.
Wed Sep 30 16:52:43 2020 .1.3.6.1.4.1.4184.2.0.2 Critical "Fatal" <server ip> - Received trap "oplGenericV2Trap" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.80.50.52.49.53.72.48.65.72.70:ICOP2415H0AHF enterprises.4184.2.5.1.0:EN92 enterprises.4184.2.5.2.0:1 enterprises.4184.2.5.3.0:RELOAD - Alert process reload by user request. enterprises.4184.2.5.4.0:2020-09-30 16:52:43 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
Wed Sep 30 16:55:13 2020 .1.3.6.1.4.1.4184.2.0.2 Critical "Fatal" <server ip>- Received trap "oplGenericV2Trap" with variables "enterprises.4184.2.1.2.1.2.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:Cerner OPENLink 24.1-05 enterprises.4184.2.1.2.1.5.23.67.101.114.110.101.114.95.79.80.69.78.76.105.110.107.95.50.52.46.49.45.48.53:1 enterprises.4184.2.2.2.1.1.13.73.67.79.84.50.52.49.53.72.48.65.72.70:ICOT2415H0AHF enterprises.4184.2.3.2.1.1.13.73.67.79.84.50.52.49.53.72.48.65.72.70.11.80.82.69.67.89.83.69.95.51.77.50:PRECYSE_3M2 enterprises.4184.2.5.1.0:IN13 enterprises.4184.2.5.2.0:4 enterprises.4184.2.5.3.0:DOWN, Interface is not operational- ERROR status for Connection. enterprises.4184.2.5.4.0:2020-09-30 16:55:12 enterprises.4184.2.5.8.0:0 enterprises.4184.2.5.9.0:0"
But the notifications log doesn't show the OK logs and also doesn't appear to be consistant regarding the information being received.