I was curious when I upgrade a LEM appliance does it also update the connectors to the most recent versions or does this need to be done separately?
Does upgrading an appliance also upgrade the connectors?
Re: Trying to change the threshold for the top 10 disk space list view.
There is no way within the product today for drives to be named simply buy their drive letter and not include the label without editing the volume name and removing the volume label manually as you're already are doing.
Volume thresholds for linear gauges on the Orion web console can be changed globally by going to "Settings -> Orion Thresholds" as pictured below.
Creating alerts for specific volumes is farily straightforward. Below is an example for alerting on a single volume when it exceeds less than 5% of available space.
Here's another example that shows how to do this same type of alert for multiple volumes. More can be added to this trigger condition as needed.
You can also do this node based as well as the example below demonstrates.
Re: Need Help configuring a Disk Usage alert
This looks more of an issue of the testing than the alert message.
What are you putting for your test node/interface/volume?
Remember that it takes the variables from the table of what you specify. So if you have InterfaceID but are alerting from a node, it'll just display ${InterfaceID}.
Also, remember that custom variables are specificed as being either node or interface properties. Not both. Look to see if you can edit it with "edit node" or "edit interface" option.
Lastily, remember that testing ignore conditions and restrictions and goes straight to actions. This means that you can't really test to see if your alert conditions with test alerts, only the information when it sends is correct (so it won't catch that =95.0... makes your alert very unlikely to fire).
Re: Trying to change the threshold for the top 10 disk space list view.
To change the threshold, go to settings -> Orion thresholds. But this is a global setting for all drives,.
For your advanced alert question. This is possible but you would either need to make a different alert for each server, or make different conditions that match each server and set the thresholds. It would probably be easier to use custom properties and match the servers with these values. Example, small, medium, large.
I am not sure about your 2nd question. Maybe someone else knows of a shortcut.
Zak Kahl
Loop1 Systems
How do you show value in a SIEM?
I am curious how folks out there show value in a SIEM solution to managers and/or customers?
Best way to implement "group" alerts?
As the Network Admin I have NPM set up to alert me when just about any piece of equipment I care about goes down or runs into problems. That's working great. Now I have a need to alert OTHER people when a specific set of nodes go down, reboot, etc. What's the best way to accomplish this? I basically need: When a device in group1 has an alert, send an email to user1. When a device in group2 has an alert, send an email to user2, etc.
Any insights?
Re: Best way to implement "group" alerts?
You can setup a custom node property called “Email Alert” and put in the email address of the person you want alerted for that node. Then in your advanced alerts for the email address field in the alert you can add the variable for that Custom Node Property. Then when there is an issue with that node it will send an alert to the email address you have specified in the field for that node.
I realize this doesn’t do it by group but it could accomplish the same goal.
SolarWinds is currently working on a product called Alert Central which will allow you to do advanced alert routing such as you are talking about.
Hope this helps!
Re: Request report for open unused ports in switch
Have you seen Request report for open unused ports in switch from the Report Lab and the queries provided by njoylif and Bedrich? Bedrich's format worked best for us. You can tweak the port types as needed.
Re: Alert date and time display
${DateTime} variable was broken in NPM 10.2 and 10.3 and date is reported as 1/1/2013 06:00PM. In pre-10.2 versions, ${DateTime} was reported in long form; '${DayOfWeek}, ${MonthName} ${DD}, ${YYYY} ${Time}'. I was told it would be fixed in 10.4 (Case # 360826 - ${DateTime} variable has changed) but we are still running 10.3.1 so I can't confirm it is fixed in 10.4. Any feedback on if it is fixed would be appreciated. Thanks.
Hope this helps.
Re: Switching automatically between NPM tabs
My default browser is Chrome, however, I also can use Firefox.
Re: Queries regarding Orion SDK
What's the difference between choosing Orion (v3) or Orion (v2)?
Also if suppose I want to connect to NPM through SDK, so what does this
exactly means? Is it that we will use a script that will make query the NPM
database using SWIS?
Also, if above is true then where can this script run? only on Orion server
or can we also run it on any other UNIX host also? And how to run it on
Orion, can we schedule it or it has to be run manually?
Can you please point me to any script that connects to NPM and pulls out
information?
Sorry some of the above question might seem silly, but I am very new to it.
Thanks in advance
On Fri, Jan 4, 2013 at 9:52 PM, tdanner <
Re: How to set topology data polling interval ?
This setting applies to both L2 and L3 topology pollers. It is stored on per node basis in NodeSettings table. Setting name is "Core.TopologyPollInterval". You just need to create a new row with matching NodeID, SettingName and Value (in minutes).
There is also a Orion-wide setting available in Settings table with SettingID "SWNetPerfMon-Settings-Default Node Topology Poll Interval". It might be also edited in GUI on Polling Setting page and it applies to all nodes, which have no custom "Core.TopologyPollInterval" specified in NodeSettings table.
Re: SNMPv3 Trap / Trap Viewer
Hmm, that should be correct. Are you able to collect a WireShark capture containing a couple of incoming traps from affected device and open a support ticket?
Accessing Device "Primary IP" field in NOC view (or other device list)
I would love to be able to add the "Primary IP" field from each of my Device properties to my NOC view which shows the status of devices on the network in a list format.
I just don't seem to be able to find it in the field chooser.
Am I just being blind? Is there a way I can access this field in some sort of list view of my devices?
Kind Regards,
Andrew McKenzie
Re: Alert date and time display
WMI Calls Over VPN
When I tested Patch Manager, I successfully deployed third party patches to computers connected to our network via VPN. However, now it seems that WMI calls cannot be made to computers connected via VPN. This is prohibiting third party updates from reaching these machines. Does anyone know how to fix this? Any help would be appreciated
Re: Best way to implement "group" alerts?
Re: Queries regarding Orion SDK
Install the SDK on a desktop system and read the documentation, including the examples.
The SDK is for the use of a programmer who understands REST/CRUD/SOAP -- the documentation is fairly clear on what it does.
I would advise installing it on a workstation and running any program you write against a development/test instance.
v2/v3: there are some verbs that only work on v3.
yes it can query the NPM database (examples included in the SDK)
the programs that use the SDK can tun anywhere with a network connection, on any platform, that can reach the Orion server. I run my [perl] programs on a RHEL linux system. If you've a powershell programmer, java programmer then they could get their programs to work on their platform of preference.
Re: Need Help configuring a Disk Usage alert
When you are sending your test email alert, are you selecting a Volume in the Test Fire Alert window as well as the node? If you are only selecting a Network Node and do the test, then you get a reply like you did.
Re: Not getting Trap emails
Try changing "Conditions tab: BGP4-MIB:bgpTraps.0.1 contains *established*" to "Conditions tab: BGP4-MIB:bgpTraps.0.1 is equal to *", that way you should get an email for all the BGP traps that come in. See if that works. Also check if you have you SMTP Server details filled in in the Edit E-Mail/Page Action section. Within the Trap Viewer rule, you have to set what the SMTP server is.
I use Syslog Viewer instead to alert me of BGP neighbour changes.
For Message Type Pattern I look for BGP-5-ADJCHANGE
Then in the email message I send
Subject: BGP Neighbour Change on ${Node.Caption}
Message: ${MESSAGE}
Hope that helps.