Missing Polled OSPF Alert despite Syslog OSPF Adjacency Down Event
search cancel

Missing Polled OSPF Alert despite Syslog OSPF Adjacency Down Event

book

Article ID: 442646

calendar_today

Updated On:

Products

VMware Smart Assurance Network Observability

Issue/Introduction

  • You have observed a discrepancy between Syslog event detection and polled alert generation for OSPF.

  • Syslog clearly indicates OSPF neighbor transition from FULL → DOWN due to BFD session down.

  • However, no corresponding polled alert (OSPF Down) was generated in SMARTS.

  • Syslog pipeline is working as expected.

  • Issue is specific to polled OSPF monitoring behavior Smarts NPM (OSPF).

Environment

All supported Smarts releases

Cause

This issue occurs when the duration of the OSPF event is significantly shorter than the configured polling interval.

  1. Device logs verify that the OSPF event was active for approximately #### seconds.
  2. The SMARTS polling interval for OSPF status is currently set to 4 minutes.
  3. Because the flap occurred and resolved entirely within a single 4-minute polling cycle, the monitoring logic did not detect the transient "DOWN" state during its active check.

Resolution

Smarts is working as expected. Verify SAM audit log to check if the polling logic is functional.