Management of some SNMPTD alarms. Message suppression is set to the defaults.
Alarms from SNPTD are getting merged into one unexpectedly.
We are getting high alarm counts for two alarms. One set of alarms is coming from a Secondary Relay which represents a different origin. Also the "FROM:" address may differ as we saw in some of the alarms and don't expect alarms be grouped and counted as the same alarm.
Cannot set the message suppression character number value higher since that will affect all alarms.
Example of alarms:
Enterprise (.1.3.6.1.4.1.11.2.17.1), Enterprise specific - 1 ##xxxxxx-###.<country>.<companyname>.<net> Data Protector Critical [Critical] From: xxxxxx \"##XXXX-NB08XXXXX_FS_ALL_ST_##\" Time: 12/10/2020 3:54:50 AM None of the Disk Agents completed successfully. Session has failed.
Environment
DX UIM 23.4.*
SNMPTD probe
Cause
Documentation Clarification / Guidance on how to group alarms and how they are suppressed.
Resolution
To group/ungroup SNMPTD alarms add a variable in the specific suppression key
STEPS:
Go to Generic tab > Set the suppression key (add $+Available Variable)
Alternatively a suppression key can be set profile-specific:
After applying this, the alarms will be no longer group if the chosen variable helps segregate the alarms (as the variables from the alarms will be different).
NOTES:
'SNMP Trap Monitor' displays all the available variables and in this case $6 was the trap 'message string' and that's what was used to group LIKE alarms.
It's best to use/browse the traps via the SNMP Trap monitor and then examine the trap itself to see all of the available trap variables and note their values and then take note of the variable number (#).
In the SNMP trap monitor details you can examine the variable # and the value of the variable.