Re: Unformatted Traps received; have MIB compiled
Freddi Guerrero <[email protected]> Thu, 9 Aug 2018 13:42:05 +0000
| Newsgroups | gmane.network.opennms.general |
|---|---|
| Message-ID | <CY1PR14MB02997AC17F28D3ADB34B2863A3250@CY1PR14MB0299.namprd14.prod.outlook.com> |
No prob thanks for helping and pointing me in the right direction! Thank you, Freddi Guerrero Sent via Outlook Mobile<https://aka.ms/blhgte> ________________________________ From: Seibold, Michael <[email protected]> Sent: Thursday, August 9, 2018 4:47:37 AM To: General OpenNMS Discussion Subject: Re: [opennms-discuss] Unformatted Traps received; have MIB compiled Hi Freddy, sorry, I’m „out of resources“ (time) at the moment. I would suggest you - Take a look at the events generated from other systems and how the event-oid is treated there - Compare the original mib of those events and the one you took here - Compare the eventfiles for both of them There should be a difference there, maybe a missing dot “.” at the end of an OID or something like this, which leads to the misinterpretation in OpenNMS. Probably it’s just a little change in the MIB and compile/generate events again to fix the problem, or a little fix with the OID or something like this in the event-file -Michael Von: Freddi Guerrero <[email protected]> Gesendet: Donnerstag, 9. August 2018 01:30 An: General OpenNMS Discussion <[email protected]> Betreff: Re: [opennms-discuss] Unformatted Traps received; have MIB compiled Michael thank you so much for your help here. Here is the requested output: opennms=> select * from events where eventid=70973112; -[ RECORD 1 ]-----------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- eventid | 70973112 eventuei | uei.opennms.org/generic/traps/EnterpriseDefault nodeid | 15191 eventtime | 2018-08-08 15:54:35.891-06 eventhost | 138.91.249.83 eventsource | trapd ipaddr | 138.91.249.83 eventsnmphost | 138.91.249.83 serviceid | eventsnmp | .1.3.6.1.4.1,undefined,v2,6102,6,public eventparms | .1.3.6.1.4.1.6102.1.1=PROGNOSIS(OctetString,text);.1.3.6.1.4.1.6102.1.2.2=9(Int32,text);.1.3.6.1.4.1.6102.1.2.3=310045(Int32,text);.1.3.6.1.4.1.6102.1.2.4=Edge-SipIncReqsDropped(OctetString,text);.1.3.6.1.4.1.6102.1.2.1=[Glowpoint] Edge Server:[\LYNCEDGE-2V-HRC] Issue resolved with incoming requests being dropped by the Edge Server(OctetString,text);.1.3.6.1.4.1.6102.1.2.5=\LYNCEDGE-2V-HRC(OctetString,text);.1.3.6.1.4.1.6102.1.2.27=****************************************************************LYNC **************************************************************** Edge-SipIncReqsDropped(OctetString,text);.1.3.6.1.4.1.6102.1.2.26=(OctetString,text);.1.3.6.1.4.1.6102.1.2.28=(OctetString,text);.1.3.6.1.4.1.6102.1.2.29=(OctetString,text);.1.3.6.1.4.1.6102.1.2.30=(OctetString,text);.1.3.6.1.4.1.6102.1.2.31=(OctetString,text) eventcreatetime | 2018-08-08 15:54:35.905-06 eventdescr | <p>This is the default event format used when an enterprise specific event (trap) is received for which no format has been configured | (i.e. no event definition exists).</p> <p>The total number of arguments received with the trap: 12.</p> | <p>They were:<p> <p>.1.3.6.1.4.1.6102.1.1="PROGNOSIS" .1.3.6.1.4.1.6102.1.2.2="9" .1.3.6.1.4.1.6102.1.2.3="310045" .1.3.6.1.4.1.6102.1.2.4="Edge-SipIncReqsDropped" .1.3.6.1.4.1.6102.1.2.1="[Glowpoint] Edge Server:[\LYNCEDGE-2V-HRC] Issue resolved with incoming requests being dropped by the Edge Server" .1.3.6.1.4.1.6102.1.2.5="\LYNCEDGE-2V-HRC" .1.3.6.1.4.1.6102.1.2.27="****************************************************************LYNC **************************************************************** Edge-SipIncReqsDropped" .1.3.6.1.4.1.6102.1.2.26="" .1.3.6.1.4.1.6102.1.2.28="" .1.3.6.1.4.1.6102.1.2.29="" .1.3.6.1.4.1.6102.1.2.30="" .1.3.6.1.4.1.6102.1.2.31=""<p> | <p>Here is a "mask" element definition that matches this | event, for use in event configuration files:<br/> | <blockquote> | <mask><br/> | <maskelement><br/> | <mename>id</mename><br/> | <mevalue>.1.3.6.1.4.1</mevalue><br/> | </maskelement><br/> | <maskelement><br/> | <mename>generic</mename><br/> | <mevalue>6</mevalue><br/> | </maskelement><br/> | <maskelement><br/> | <mename>specific</mename><br/> | <mevalue>6102</mevalue><br/> | </maskelement><br/> | </mask> | </blockquote> | <p> eventloggroup | eventlogmsg | Received unformatted enterprise event (enterprise:.1.3.6.1.4.1 generic:6 specific:6102). 12 args: .1.3.6.1.4.1.6102.1.1="PROGNOSIS" .1.3.6.1.4.1.6102.1.2.2="9" .1.3.6.1.4.1.6102.1.2.3="310045" .1.3.6.1.4.1.6102.1.2.4="Edge-SipIncReqsDropped" .1.3.6.1.4.1.6102.1.2.1="[Glowpoint] Edge Server:[\LYNCEDGE-2V-HRC] Issue resolved with incoming requests being dropped by the Edge Server" .1.3.6.1.4.1.6102.1.2.5="\LYNCEDGE-2V-HRC" .1.3.6.1.4.1.6102.1.2.27="****************************************************************LYNC **************************************************************** Edge-SipIncReqsDropped" .1.3.6.1.4.1.6102.1.2.26="" .1.3.6.1.4.1.6102.1.2.28="" .1.3.6.1.4.1.6102.1.2.29="" .1.3.6.1.4.1.6102.1.2.30="" .1.3.6.1.4.1.6102.1.2.31="" eventseverity | 3 eventpathoutage | eventcorrelation | eventsuppressedcount | eventoperinstruct | eventautoaction | eventoperaction | eventoperactionmenutext | eventnotification | eventtticket | eventtticketstate | eventforward | eventmouseovertext | eventlog | Y eventdisplay | Y eventackuser | eventacktime | alarmid | 713280 ifindex | systemid | 00000000-0000-0000-0000-000000000000 From: Seibold, Michael <[email protected]> Sent: Wednesday, August 8, 2018 7:15 AM To: General OpenNMS Discussion <[email protected]> Subject: Re: [opennms-discuss] Unformatted Traps received; have MIB compiled Hi Freddi, It’s a long time since I debugged traps… so I don’t know where the problem comes from. But it is very common that either - The mib files provided are faulty - The snmp trap sender is faulty From your provided MIB header I assume that 6102 is the vendor ID: https://opmantek.com/network-management-system-nmis-supported-vendors-snmp.html · Integrated Research Ltd. (SNMP Enterprise OID .1.3.6.1.4.1.6102) So 6102 should not be interpreted as specific: Received unformatted enterprise event (enterprise:.1.3.6.1.4.1 generic:6 specific:6102). Now I’m not sure why opennms thinks this is the specific parameter. Can you send us the output from echo “select * from events where eventid=nnnnnnnn;” | psql where nnnnnnnn is the eventid of this unformatted trap? -Michael ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Please read the OpenNMS Mailing List FAQ: http://www.opennms.org/index.php/Mailing_List_FAQ opennms-discuss mailing list To *unsubscribe* or change your subscription options, see the bottom of this page: https://lists.sourceforge.net/lists/listinfo/opennms-discuss