Discussion:
[opennms-discuss] Yikes! High Threshold for ifOutOctets * 8 / 1000000 / ifHighSpeed * 100
Aaron Scamehorn
2008-12-10 18:39:18 UTC
Permalink
Hello,

I just upgrade to opennms-core-1.7.0-0.11467 and I am being flooded with
Notifiactions for the following event:
High Threshold for ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 on node
XXX

A Threshold has been exceeded on node: XXXX, interface:192.168.32.252.
The parameter ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reached a
value of 2337.147088 while the threshold is 90.0. This alert will be
rearmed when ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reaches 75.0.



I've received hundreds in the first hour. Seems like the threshold of
90 is way to low, or I'm way to high at 2337.147088 . What exactly is
this a threshold for?



Thanks,
Aaron
Dillon Mills
2008-12-10 19:45:42 UTC
Permalink
Hi everyone,
So, I am monitoring mostly a large number of Cisco devices, but I always have on my OpenNMS home page a listing of "Web Servers" showing with outages. I'm not sure why the https server doesn't respond some of the time on my switches, but really I don't care about that service anyway - we don't use the web interface and I don't want it to show as a "Node with Outages" on my OpenNMS home page, or be factored into my 24-hour availability numbers.

Is there a way to tell it to unmanage that service (I guess that's what I want to do?) on all my Cisco-discovered devices automatically? Or do I have to narrow it down more than that? Can I say somehow, all the things in *these* IP ranges, don't bother monitoring their http/s servers? I don't want to turn off the http/s polling in capsd completely, as we plan to use this to monitor servers in the future.

Any ideas would be welcome, thanks!


------------------------------------------------------
Dillon Mills
Network Systems Architect
University of San Diego
***@sandiego.edu<mailto:***@sandiego.edu>
Aaron Paxson
2008-12-10 21:21:48 UTC
Permalink
choose Admin, then choose Manage/Unmanage services. Then, remove the
checkmarks from the services you want monitored.
That should read, "Then remove the checkmarks from the services you
DON'T want monitored"
Aaron Paxson
2008-12-10 21:20:27 UTC
Permalink
I have always made a point to disable the HTTPS and/or HTTP server on
my Cisco devices if I don't use it. The more services running, the
more at-risk you are with vulnerabilities.

Anyway, just my two cents.

The easiest way, but the most time consuming, is to go to each node,
choose Admin, then choose Manage/Unmanage services. Then, remove the
checkmarks from the services you want monitored.

If you want a more automated approach, you can do an update to the
database directly. I'll let the Guru/SQL guys come up with that one.
There may be dependencies that I'm not aware of.

Aaron
Post by Dillon Mills
Hi everyone,
So, I am monitoring mostly a large number of Cisco devices, but I always
have on my OpenNMS home page a listing of "Web Servers" showing with
outages. I'm not sure why the https server doesn't respond some of the
time on my switches, but really I don't care about that service anyway – we
don't use the web interface and I don't want it to show as a "Node with
Outages" on my OpenNMS home page, or be factored into my 24-hour
availability numbers.
Is there a way to tell it to unmanage that service (I guess that's what I
want to do?) on all my Cisco-discovered devices automatically? Or do I have
to narrow it down more than that? Can I say somehow, all the things in
*these* IP ranges, don't bother monitoring their http/s servers? I don't
want to turn off the http/s polling in capsd completely, as we plan to use
this to monitor servers in the future.
Any ideas would be welcome, thanks!
------------------------------------------------------
Dillon Mills
Network Systems Architect
University of San Diego
------------------------------------------------------------------------------
SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada.
The future of the web can't happen without you. Join us at MIX09 to help
pave the way to the Next Web now. Learn more and register at
http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/
_______________________________________________
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss mailing list
To *unsubscribe* or change your subscription options, see the bottom of this
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
--
Aaron J. Paxson
---------
***@gmail.com
http://aaron.thepaxson5.org
Dillon Mills
2008-12-12 21:21:01 UTC
Permalink
-----Original Message-----
Sent: Friday, December 12, 2008 1:22 AM
Subject: Re: [opennms-discuss] Limiting collection of services on specific typesof devices
Dillon,
what I did is simply create a Package "Webservers" in poller-configuration.xml; moving the poller packages from >"Default" to that package and adding the webservers I want to monitor in in the "include" part of this package >(<specific xmlns="">xxx.xxx.xxx.xxx</specific>); and yes, you can also set an "include" range.
As result the Webserver services are detected, but set as "not monitored" in the WebUI, hence don't go into the SLA >calculation if down.
Hope this helps,
Christoph
Ah... yes, that's probably a very good solution -- since I have defined IP space separation between "network" and "servers", I *could* just make two packages instead of having one Default that fits them all. I believe I'd have to delete the nodes and let them be re-discovered to have the new package apply to them? Good idea, thanks!
-----Original Message-----
Sent: Wednesday, December 10, 2008 1:20 PM
To: General OpenNMS Discussion
Subject: Re: [opennms-discuss] Limiting collection of services on specific types of devices
I have always made a point to disable the HTTPS and/or HTTP server on
my Cisco devices if I don't use it. The more services running, the
more at-risk you are with vulnerabilities.
Anyway, just my two cents.
The easiest way, but the most time consuming, is to go to each node,
choose Admin, then choose Manage/Unmanage services. Then, remove the
checkmarks from the services you want monitored.
If you want a more automated approach, you can do an update to the
database directly. I'll let the Guru/SQL guys come up with that one.
There may be dependencies that I'm not aware of.
Aaron
Oh believe me, I'm not happy that all the switches are running those services either :) We're in the planning stages of implementing CiscoWorks, hopefully when that's up I can just turn off all those services en masse instead of individually... the idea of logging into *hundreds* of devices and changing the configurations is not something I'd like to have to do :)

I like where you're going with the direct database query -- I may investigate that rather than re-discover everything like I think I'd have to do in the above suggestion. Thanks!
Hi everyone,
So, I am monitoring mostly a large number of Cisco devices, but I always
have on my OpenNMS home page a listing of "Web Servers" showing with
outages. I'm not sure why the https server doesn't respond some of the
time on my switches, but really I don't care about that service anyway - we
don't use the web interface and I don't want it to show as a "Node with
Outages" on my OpenNMS home page, or be factored into my 24-hour
availability numbers.
Is there a way to tell it to unmanage that service (I guess that's what I
want to do?) on all my Cisco-discovered devices automatically? Or do I have
to narrow it down more than that? Can I say somehow, all the things in
*these* IP ranges, don't bother monitoring their http/s servers? I don't
want to turn off the http/s polling in capsd completely, as we plan to use
this to monitor servers in the future.
Any ideas would be welcome, thanks!
------------------------------------------------------
Dillon Mills
Network Systems Architect
University of San Diego
------------------------------------------------------------------------------
SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada.
The future of the web can't happen without you. Join us at MIX09 to help
pave the way to the Next Web now. Learn more and register at
http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/
_______________________________________________
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss mailing list
To *unsubscribe* or change your subscription options, see the bottom of this
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
--
Aaron J. Paxson
---------
***@gmail.com
http://aaron.thepaxson5.org

------------------------------------------------------------------------------
SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada.
The future of the web can't happen without you. Join us at MIX09 to help
pave the way to the Next Web now. Learn more and register at
http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/
_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/index.php/Mailing_List_FAQ

opennms-discuss mailing list

To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
C***@mt.com
2008-12-12 09:22:15 UTC
Permalink
Dillon,



what I did is simply create a Package "Webservers" in
poller-configuration.xml; moving the poller packages from "Default" to
that package and adding the webservers I want to monitor in in the
"include" part of this package (<specific
xmlns="">xxx.xxx.xxx.xxx</specific>); and yes, you can also set an
"include" range.



As result the Webserver services are detected, but set as "not
monitored" in the WebUI, hence don't go into the SLA calculation if
down.



Hope this helps,



Christoph



From: Dillon Mills [mailto:***@sandiego.edu]
Sent: Mittwoch, 10. Dezember 2008 20:46
To: General OpenNMS Discussion
Subject: [opennms-discuss] Limiting collection of services on specific
typesof devices



Hi everyone,

So, I am monitoring mostly a large number of Cisco devices, but I always
have on my OpenNMS home page a listing of "Web Servers" showing with
outages. I'm not sure why the https server doesn't respond some of the
time on my switches, but really I don't care about that service anyway -
we don't use the web interface and I don't want it to show as a "Node
with Outages" on my OpenNMS home page, or be factored into my 24-hour
availability numbers.



Is there a way to tell it to unmanage that service (I guess that's what
I want to do?) on all my Cisco-discovered devices automatically? Or do
I have to narrow it down more than that? Can I say somehow, all the
things in *these* IP ranges, don't bother monitoring their http/s
servers? I don't want to turn off the http/s polling in capsd
completely, as we plan to use this to monitor servers in the future.



Any ideas would be welcome, thanks!





------------------------------------------------------

Dillon Mills

Network Systems Architect

University of San Diego

***@sandiego.edu
Aaron Paxson
2008-12-10 23:14:51 UTC
Permalink
Hi Aaron!

There was another post on this mailling list 7 days ago. Look for the
subject "Threshold" on Dec 4 (I think).

That post discusses that the traffic was on a High-Speed port (i.e.
greater than 100Mbs).

What is that threshold for? It's the bandwidth utilization for
outbound traffic. If it hits 90%, the high-threshold is triggered,
and won't be reset until it falls below 75%.

Again, I think it's expecting to be a slower interface (hence the high
percentage). Check out the previous post to the mailling list.
Hopefully, it will help.

Aaron P.



On Wed, Dec 10, 2008 at 12:39 PM, Aaron Scamehorn
Post by Aaron Scamehorn
Hello,
I just upgrade to opennms-core-1.7.0-0.11467 and I am being flooded with
High Threshold for ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 on node XXX
A Threshold has been exceeded on node: XXXX, interface:192.168.32.252. The
parameter ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reached a value of
2337.147088 while the threshold is 90.0. This alert will be rearmed when
ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reaches 75.0.
I've received hundreds in the first hour. Seems like the threshold of 90 is
way to low, or I'm way to high at 2337.147088 . What exactly is this a
threshold for?
Thanks,
Aaron
------------------------------------------------------------------------------
SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada.
The future of the web can't happen without you. Join us at MIX09 to help
pave the way to the Next Web now. Learn more and register at
http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/
_______________________________________________
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss mailing list
To *unsubscribe* or change your subscription options, see the bottom of this
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
--
Aaron J. Paxson
---------
***@gmail.com
http://aaron.thepaxson5.org
Aaron Scamehorn
2008-12-10 22:05:54 UTC
Permalink
Here is another; this one is on a VLAN:

High threshold exceeded for SNMP datasource ifOutOctets * 8 / 1000000 /
ifHighSpeed * 100 on interface 192.168.33.1, parms: ds="ifOutOctets * 8
/ 1000000 / ifHighSpeed * 100" value="6184.048952" threshold="4000.0"
trigger="3" rearm="75.0" label="Fa0/1.253"
ifLabel="Fa0_1_253-00233323d829" ifIndex="1"

As you can see, I've increased the threshold from 90 to 4000.

________________________________

From: Aaron Scamehorn [mailto:***@cogcap.com]
Sent: Wednesday, December 10, 2008 12:39 PM
To: General OpenNMS Discussion
Subject: [opennms-discuss] Yikes! High Threshold for ifOutOctets * 8
/1000000 / ifHighSpeed * 100


Hello,

I just upgrade to opennms-core-1.7.0-0.11467 and I am being flooded with
Notifiactions for the following event:
High Threshold for ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 on node
XXX

A Threshold has been exceeded on node: XXXX, interface:192.168.32.252.
The parameter ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reached a
value of 2337.147088 while the threshold is 90.0. This alert will be
rearmed when ifOutOctets * 8 / 1000000 / ifHighSpeed * 100 reaches 75.0.



I've received hundreds in the first hour. Seems like the threshold of
90 is way to low, or I'm way to high at 2337.147088 . What exactly is
this a threshold for?



Thanks,
Aaron
Loading...