How to Find a List of Minor Alarms in Spectrum
search cancel

How to Find a List of Minor Alarms in Spectrum

book

Article ID: 377262

calendar_today

Updated On:

Products

DX NetOps

Issue/Introduction

How do we see which alerts/events will generate minor (yellow) alarms in Spectrum?

I'm considering taking minor alarms out of notifier config, and just emailing major and critical.  but first I want to know what they all are, as this may not be as desirable as it sounds for reducing alarm/email "noise".

Resolution


Spectrum has over 19k Events that Map to Minor Alarms.

A small script can be used to list the pcause id along with the Alarm Titles

example

./minorAlarms.sh

#! /usr/bin/bash


SPECROOT=/usr/Spectrum
CSVENDOR=${SPECROOT}/SS/CsVendor


IFS=$'\n'


for pcause in $(grep -r " A 1" ${CSVENDOR})
do

   cause=`echo ${pcause} |cut -d "," -f 2`
   scause=`echo ${cause} | awk '{ print $1 }'`
   tcause=`echo ${scause} | tr -d '[:space:]'`
   ucause=`echo ${tcause} | sed 's/^..//'`


   echo ""
   echo "pcause: ${ucause}"

   find ${SPECROOT}/SG-Support/CsPCause -name "*${ucause}*" -exec head -n 1 {} \;

done



Note: The above is not perfect due to possible formatting differences for some EventDisp entries and some pcause files. This should be refined at some point
Note: This can be tweaked for Major or Critical by adjusting the grep for "A 2" or "A 3"


Example Output

pcause: 01030a
AUTHENTICATION FAILURE TRAP RECEIVED

pcause: 01030b
CONTACT LOST WITH EGP NEIGHBOR

pcause: 00010050
AN EXCESSIVE RATE OF DEVICE INTERFACE RECONFIGURATIONS

pcause: 010029
EXCESSIVE TIMEOUT VALUE

pcause: 01002a
EXCESSIVE TRY COUNT VALUE

pcause: 01002b
TRY COUNT VALUE NOT SET

pcause: 01002c
TIMEOUT VALUE NOT SET

pcause: 010120
SPECTROSERVER LICENSE WILL EXPIRE WITHIN 10 DAYS

pcause: 010256
THE INTERNAL LOG QUEUE OF EVENTS HAS OVERFLOWED

pcause: 01025f
TRAP RECEIVED WITH DUPLICATE VARIABLES

pcause: 010303
INVALID SNMP COMMUNITY STRING

pcause: 010304
DEVICE COUNT THRESHOLD EXCEEDED

pcause: 0001003c
MODEL COUNT EXCEEDED 80% OF MAXIMUM THRESHOLD

pcause: 010601
PORT SEGMENTED TRAP RECEIVED

pcause: 010604
PORT LINK DOWN TRAP RECEIVED

pcause: 010607
BOARD REMOVED TRAP RECEIVED

pcause: 010609
REDUNDANT ACTIVE PORT FAILURE

pcause: 01060c
DEVICE TRAFFIC THRESHOLD EXCEEDED

pcause: 01060d
DEVICE ERROR THRESHOLD EXCEEDED

pcause: 01060e
DEVICE COLLISION THRESHOLD EXCEEDED

pcause: 01060f
BOARD TRAFFIC THRESHOLD EXCEEDED

pcause: 010610
BOARD ERROR THRESHOLD EXCEEDED

pcause: 010611
NETWORK COLLISIONS HAVE OCCURRED

pcause: 010612
PORT TRAFFIC THRESHOLD EXCEEDED

pcause: 010613
PORT ERROR THRESHOLD EXCEEDED

pcause: 010614
DEVICE TRANSMISSION ERRORS

pcause: 010615
PORT TYPE HAS CHANGED

pcause: 010616
PORT LOCK STATUS CHANGE TRAP RECEIVED

pcause: 010636

pcause: 00010716
FAULT TOLERANT ALARMS NOT SYNCED TO PRIMARY

pcause: 010c20
DUPLICATE LANDSCAPE MODEL

pcause: 00010c04
CONTAINER ALARMS ROLLED UP

pcause: 0001025d
IFALIAS WRITE ERROR

pcause: 00010c1a
CONNECTION TO LANDSCAPE ON SECONDARY SERVER.

pcause: 00010c17
SNMP GET_NEXT LOOP DETECTED

pcause: 00010203
DIFFERENT TYPE MODEL

pcause: 00010db1
UNABLE TO IDENTIFY DEVICE

pcause: 00010e01
UNRESOLVED HOSTNAMES FOUND IN HOST SECURITY FILE

pcause: 00010e02
INSUFFICIENT USER SECURITY FOR MODEL PLACEMENT

pcause: 00010b01
NO ASSOCIATED AGENT MODEL

pcause: 00010b03
DUPLICATE EPI ADDRESS DETECTED

pcause: 00010b13
INVALID MODELING SCENARIO

pcause: 00010d57
THREE OR MORE DEVICES CONNECTED BY WA_SEGMENT

pcause: 00010111
INVALID PRIMARY ADDRESS

pcause: 00010110
NETWORK ADDRESS AND PRIMARY ADDRESS DIFFER

pcause: 0001000f
TOTAL LOAD THRESHOLD EXCEEDED

pcause: 00010e03
IN LOAD THRESHOLD EXCEEDED

pcause: 00010e04
OUT LOAD THRESHOLD EXCEEDED

pcause: 00010e08
PERCENT IN ERRORS THRESHOLD EXCEEDED

pcause: 00010e09
PERCENT OUT ERRORS THRESHOLD EXCEEDED

pcause: 00010e0a
PERCENT IN DISCARDS THRESHOLD EXCEEDED

pcause: 00010e0b
PERCENT OUT DISCARDS THRESHOLD EXCEEDED

pcause: 00010010
PACKET RATE THRESHOLD EXCEEDED

pcause: 00220004
PERCENT ERRORS THRESHOLD EXCEEDED

pcause: 00220005
PERCENT DISCARDS THRESHOLD EXCEEDED

pcause: 00010531
ONLINE BACKUP ERROR

pcause: 00010529
ONLINE BACKUP ERROR

pcause: 00010530
ONLINE BACKUP ERROR

pcause: 00010514
AN EXPECTED PROGRAM OR DIRECTORY IS EITHER MISSING OR HAS THE WRONG PERMISSIONS

pcause: 00010513
INSUFFICIENT DISK SPACE IN THE BACKUP DIRECTORY

pcause: 00010026
RESIDUAL ALARMS EXIST

pcause: 04820003
DSS RUNNING WITH MISMATCHED LANDSCAPE VERSIONS

pcause: 00010f10
SPECTROSERVER CPU CONTEXT SWITCH THRESHOLD EXCEEDED

pcause: 00010f11
SPECTROSERVER REALTIME CONTEXT SWITCH THRESHOLD EXCEEDED

pcause: 00010f12
ARCHIVE MANAGER CPU CONTEXT SWITCH THRESHOLD EXCEEDED

pcause: 00010f13
ARCHIVE MANAGER REALTIME CONTEXT SWITCH THRESHOLD EXCEEDED

pcause: 00010f18
SPECTROSERVER IH CPU THRESHOLD EXCEEDED

pcause: 00010f19
SPECTROSERVER IH REALTIME THRESHOLD EXCEEDED

pcause: 00010f20
GLOBAL COLLECTION CPU THRESHOLD EXCEEDED

pcause: 00010f21
^CGLOBAL COLLECTION REAL TIME THRESHOLD EXCEEDED

pcause: 00010f2c
FAULT ISOLATION EVENT CUSTOMISED

pcause: 0001021e
INTERFACE IS STALE

pcause: 0001022e
DEVICE PORT COUNT EXCEEDED THRESHOLD

pcause: 0001a105
IFSTACKTABLE ENTRY CROSS REFERENCE LOOP FOUND

pcause: 00010f46
EVENT LOOP DETECTED

pcause: 00010fa0
EVENT INTEGRATION ALARM

pcause: 00010f88
MODULE DEGRADED STATE DETECTED

pcause: 00010f8a
CHASSIS DEGRADED STATE DETECTED

pcause: 00010f82
COMMUNICATION ATTRIBUTES DIFFER ON PORT OR APPLICATION

pcause: 00010f22
MINOR THRESHOLD EXCEEDED

pcause: 00010f85
INCORRECT ALARM ATTRIBUTE TYPE

pcause: 10ff9
ACCESS POINTS CONNECTED TO WLC CONTROLLER EXCEEDED MINOR THRESHOLD\u000a\u000aSYMPTOMS:\u000a\u000aNumber of access points connected to WLC Controller exceeded the minor threshold limit.\u000a\u000aPROBABLE CAUSES:\u000a\u000aTotal number of access points connected to WLC Controller exceeded the minor threshold limit. Refer to the corresponding event message for more details.\u000a\u000aRECOMMENDED ACTIONS:\u000a\u000a1) Watch out for addition of new access points on this WLC Controller.\u000a2) Consider distributing access points to other WLC Controllers for better performance.\u000a3) Add a new WLC Controller before it reaches maximum supported limit.

pcause: 10ffd
WIRELESS CLIENTS CONNECTED TO WLC CONTROLLER EXCEEDED MINOR THRESHOLD\u000a\u000aSYMPTOMS:\u000a\u000aNumber of wireless clients connected to WLC Controller exceeded the minor threshold limit.\u000a\u000aPROBABLE CAUSES:\u000a\u000aTotal number of wireless clients connected to WLC Controller exceeded the minor threshold limit. Refer to the corresponding event message for more details.\u000a\u000aRECOMMENDED ACTIONS:\u000a\u000a 1) Watch out for further increase of clients connections on this WLC Controller.\u000a 2) Consider distribution of clients to other WLC Controllers.\u000a 3) Consider addition of a new WLC Controller before number of client connections reaches maximum supported limit.

pcause: 3e50001
Generic Application Gateway Demo Alarm.

pcause: 3dc0001
DUPLICATE EventAdmin MODEL DETECTED