Trap Director Sub View Fields and Numbers Expected Behavior
search cancel

Trap Director Sub View Fields and Numbers Expected Behavior

book

Article ID: 454035

calendar_today

Updated On:

Products

Network Observability Spectrum

Issue/Introduction

You need to understand the definitions and expected behavior of the Trap Management sub view fields and numbers within DX NetOps Spectrum when Director is enabled. 

e.g. Why are 7 traps received but only 3 processed.

Environment

Distributed SpectroSERVER system with Trap Director enabled.

Cause

 

 

Resolution

"Traps Processed" is the number of traps that are processed locally i.e.

  • placed on a device model locally if that device is modelled locally.
  • if a trap is received from an unmanaged device, when unmanaged trap handling is enabled, the trap is placed on the local VNM model.  

With Trap Director enabled, if the trap is forwarded, it is not Processed (locally) so "Traps received" equals the sum of "Alerts forwarded successfully"  and "Traps processed" as in the above image. 

The above example shows 4 traps were forwarded sucessfully to 4 different devices as the "Remote Forwarding Distributed Find Attempts" also equals 4.  If this were 4 trap sent to the same device, the find attempts would equal 1 as the ip would have been cached after the first find.

If unmanaged trap handling is disabled, the trap is NOT processed and the "Traps ignored" number increments.

Restarting the SpectroServer sets all Trap Director sub view numbers back to 0

Additional Information

If there are duplicate devices on the local trap director landscape and on a remote landscape, the trap will be processed locally and remotely in parallel, so that we will egt alerts on the remote landscape in that situation.  This could happen during e.g. the migration of devices from one server to another. Putting the local devices into maintenance will ensure alerts are only placed on the remote server.