This topic is to discuss the following lesson:
This shows how to send one alert when the ping fails. But how would configure to send recurring alerts - for example every hour while the ping is failing ?
The EEM scripting language is quite detailed and powerful and is able to implement various configurations including periodically sending an update of the status of a specific value. This is done using the Watchdog periodic timer event. You can find out more about this at this Cisco link:
For a general command reference of EEM you can see the following link:
I hope this has been helpful!
Thanks for the replay. I discovered from reading the documentation and opening a Cisco TAC ticket that i cannot send multiple alerts on the back of one snmp trap. I will check with Solarwinds our monitoring system if there is a way to do this.
From Cisco TAC
there is no way to generate more than alert for the same event, because the alert is already triggered by the syslog, and if only one sysreport generated this will send only one alert,
That’s great info, thanks for sharing your experience. It is appreciated!
I am using EEM to track an IP SLA and in case it’s DOWN, I would want to send an SNMP-TRAP to NMS. IP SLA and Track works perfectly, however, the SNMP traps are not being sent. Please review my code and advise if I am missing something. Thanks.
rt-1#debug snmp packets SNMP packet debugging is on rt-1#sho run | s event snmp-server enable traps event-manager event manager applet TRACK_IP_DOWN event track 1 state down action 1.0 syslog msg "IP SLA 100 is down" action 2.0 mail server "smtp-1.local" to "networkadmins@local" from "no-reply@local" subject "IP SLA 100 is down" body "IP SLA 100 is not receiving ICMP echo replies anymore" action 3.0 snmp-trap strdata "SNMP: IP SLA 100 is not receiving ICMP echo replies anymore" rt-1#sho run | s snmp snmp-server community test RO snmp-server trap-source GigabitEthernet0/1 snmp-server location GNS3 Lab snmp-server enable traps event-manager snmp-server host 172.30.1.10 informs version 2c test snmp-server host 172.30.1.10 version 2c test
At first glance, there doesn’t seem to be a problem with your configuration. Reviewing the command reference of the action snmp-trap command in the following document doesn’t seem to indicate any problems with the specific config.
However you do state that
How have you determined this? Verify that the track 1 state is indeed being detected and is indeed changing its behaviour based on the desired functionality.
Once you’ve checked this, check to see if other SNMP traps are being sent to the SNMP server, ones that are not triggered by an EEM script to see that the server and client are indeed configured correctly. Check those out and get back to us with your results.
I hope this has been helpful!
Hello Laz for comment.
I finally found the problem.
EEM Action 3.0 never taken because it failed at action 2.0!!
We are probing/tracking an IP address with IP SLA and in case the track goes down, EEM sends an SNMP trap. So far so nice. Now, what I want to gather is to send somehow the RTT for each ping which our IP SLA performs to the NMS.
At the end, we should when track goes down receive a trap (which works perfectly) as well as storing all RTTs at the frequency of IP SLA (which I don’t know hot to gather the IP SLA rtt output)
Any idea please?
I think this will be difficult to retrieve from the
show ip sla output. Some ideas that come to mind:
- Monitor from the NMS. It seems LibreNMS supports it. Solarwinds and PRTG have something too.
- Use SNMP to fetch IP SLA statistics.
- Use netflow to monitor your IP SLA traffic.
- Use EEM to run something like
show ip sla statistics | redirect. This doesn’t give you a “per ping” output.
I liked the 3rd option (Netflow)