Re: Erratic traffic spikes in Cricket obscuring graphs
Michael Bunk <[email protected]> Fri, 31 Aug 2007 17:37:50 +0200
| Newsgroups | gmane.network.cricket.user |
|---|---|
| Message-ID | <[email protected]> |
Hello Michael, since all cricket does is to put the data into the rrdbs and all calculations with the values and drawing of the graphs is done by rrdtool, you have to look in the configuration of your rrdbs. I see your daily graph has missing values, which can lead to high derivaties using rrd-ds = counter. Probably you have to use another rrd-ds type or set an rrd-max value. Best regards, Michael Bunk Michael Tiarnaigh schrieb: > > Hi all. > > Just a quick query to see if anyone has found a quick and effective > solution to this. > > I am having an issue with some Cricket graphs, whereby a single > erratic spike at a given time (I’m not sure what causes such spikes to > be honest) obscures the rest of the data for that entire graph. For > instance, below is a typical case in point: > > > *Daily graph* > > > *Weekly graph* > > This is a ge interface on a router, and as you can see, the daily > graph is showing as normal, but because of a few ridiculous spikes in > the weekly graph, the scale is entirely thrown off, and as such, I > cannot see the correct data that I am interested in, as it is too > small to register. > > I have found one solution to correcting this, but it’s an extremely > time-consuming and tedious means of doing things. Basically, I dump > the contents of the back-end rrd file to an xml file (“rrdtool dump > ifName.rrd >> ifName.rrd.xml”), edit this file to find the time stamp > in question where the spike occurred and manually delete these entire > data rows. Save this file, and then do an rrd restore (“rrdtool > restore ifName.rrd.xml ifName.rrd”). This does solve the issue I > guess. It removes the spike, and as such, once I clear the > cricket-cache for these graphs, I can then see the correct data again. > The problem with this is that firstly, I lose the data for that time > period, and secondly, it is an extremely time consuming process. > > Has anyone found a quicker way of eliminating these ridiculous spikes, > or found a better work-around than the one I just described above? > > Thanks in advance for any help offered, > > **Micheal Tiarnaigh** > ------------------------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJAX and a browser. Download your FREE copy of Splunk now >> http://get.splunk.com/