networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 2 posts ] 
Author Message
PostPosted: Mon Jun 25, 2012 8:21 am 
Offline
Senior Member
Senior Member

Joined: Wed Sep 01, 2010 9:46 pm
Posts: 372
Location: USA
Certs: CCNA R&S/Security, IPS Specialist, 642-642
The community recently had a few discussions related to syslog collectors, which got me thinking about what messages to create alerts on.

In the past, I've browsed the history of log data from certain devices to identify messages that need alerts. That method works well for the more common messages, but what about log messages that haven't been seen before because they occur only in rare events? It seems the most important alerts would be for log messages I might not have seen before.

How do you guys handle this? Do you create generic alerts for all messages with a certain level or higher? Do you browse through a list of all possible messages to pick out what seems important?


Top
 Profile  
 
PostPosted: Mon Jun 25, 2012 8:34 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Apr 29, 2010 6:12 pm
Posts: 2206
Location: Texas
Certs: CCNP, CCDP, CCIP
IMO, this is one of the hardest parts of standing up and maturing an NMS. You have to see alerts to properly classify and place those alerts. But like you said some you might only see once or twice in the next 10 years and you must be able to see/react to them.

My approach is to work off of the devices default severity levels and go from there. I also have all "unknown" alerts kicked up to a severity where someone is still paged/emailed. At first this can be a bit of a pain and if its spamming too much then you will need to spend a few months or more closely watching whats coming in and classifying them accordingly. Once everything calms down then you can switch back.

_________________
http://blog.movingonesandzeros.net/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group