Ad Widget

Collapse

snmptrap multi trigger

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • wuhaohust
    Junior Member
    • Jan 2025
    • 10

    #1

    snmptrap multi trigger

    Hi,

    I am using snmptt to handle with the traps and then monitoring with zabbix7.0.5, I can see traps are received by zabbix and I created some triggers and they are working as expected. Now the problem is that I want to get alert for every different individual trap (traps with same content just create 1 alert), as there are mass different traps ,to manually create trigger for each trap is not a good idea. I attend to do it with a single trigger with multipul model
    Click image for larger version

Name:	image.png
Views:	137
Size:	130.3 KB
ID:	501958

    For example, in trigger name, I use {{ITEM.VALUE}.regsub(".*".*"\s+(\d+\.\d+\.\d+\.\ d+)\s-\s*(.*)","\2")} to get the trap content . But we get two alerts for below two traps, is it possible to only get 1 alert if the trap content is the same, new alert only be triggered when trap content is different? Such link up traps are just for testing , real traps are differentClick image for larger version

Name:	image.png
Views:	80
Size:	48.4 KB
ID:	501959
    Click image for larger version

Name:	image.png
Views:	76
Size:	58.7 KB
ID:	501960

  • ISiroshtan
    Senior Member
    • Nov 2019
    • 324

    #2
    You can look towards Global event correlation to close duplicate triggers.
    This way you will have only one open alert per uniqueness criteria you set (tho still multiple alert will be visible if you would check the alert history)

    Comment

    • wuhaohust
      Junior Member
      • Jan 2025
      • 10

      #3
      Originally posted by ISiroshtan
      You can look towards Global event correlation to close duplicate triggers.
      This way you will have only one open alert per uniqueness criteria you set (tho still multiple alert will be visible if you would check the alert history)
      Thanks for your advise. I tried with event correlation , the setting is as below:
      Click image for larger version

Name:	image.png
Views:	65
Size:	90.9 KB
ID:	502050



      But we still got two alerts,with same tags (host and eventid), can you pls help to check ?

      Click image for larger version

Name:	image.png
Views:	81
Size:	96.5 KB
ID:	502049

      Comment

      • ISiroshtan
        Senior Member
        • Nov 2019
        • 324

        #4
        Condition A, you matching old "eventid" vs new "errorid"... is there a reason for it? does not sound like they would be matching....

        Comment

        • wuhaohust
          Junior Member
          • Jan 2025
          • 10

          #5
          Originally posted by ISiroshtan
          Condition A, you matching old "eventid" vs new "errorid"... is there a reason for it? does not sound like they would be matching....
          my mistake..... I corrected the setting,but issue still there. The functionality will only allow correlation based on event tags of events generated by different triggers ? In my case, the events are triggered by the same trigger

          Click image for larger version  Name:	image.png Views:	1 Size:	97.3 KB ID:	502100
          Click image for larger version  Name:	image.png Views:	1 Size:	116.4 KB ID:	502101
          Last edited by wuhaohust; 22-04-2025, 08:09.

          Comment

          • ISiroshtan
            Senior Member
            • Nov 2019
            • 324

            #6
            It should work just fine when events from same trigger. More like it should not care the trigger if nothing is set about it in correlation conditions. Weird that it is not working, as I don't really see any errors atm.
            I would assume values of host tag is exactly same and you dont want to show it, but any chance you can show values of errorid tag of both events?

            Comment


            • wuhaohust
              wuhaohust commented
              Editing a comment
              errorid value for old/new event are the same ----- "errorid: Error ID = 71724 : Fewer ethernet ports operational" , and actually I also use it in the event summary , you can see the alert summary are the same, and they are from the same host
          Working...