We are getting some alarms from MplsVpn models which show the following in the event details:
"The condition of VPN WH-INET is Critical because 2 of 1 sites (200%) are down. "
The problem is the VPN mentioned in the event only has 1 site associated with it, not two.
The event id is 0x4940407.
Release: Any version of Spectrum
Component: Spectrum Events ad Alarms
The cause of the issue is on a previous alarm created by the 0x4940407 event, the alarm was cleared by the user instead of by Sppectrum when one of the following events are generated:
0x04940400
0x04940404
0x04940405
0x04940406
0x04940426
Manually clearing events that are cleared by system events can cause Spectrum to get confused.
Use the Event Configuration tool to make the 0x4940407 event non-user clearable and then restart the SpectroSERVER system to ensure the SpectroSERVER cache is cleared for any manually cleared alarms for the 0x4940407.
Please reference the "Event Configuration" section of the documentation for more information.
https://docops.ca.com/ca-spectrum/10-3-0/en/managing-network/event-configuration