Ahoj / Dobrý den všem,
chtěl bych se zeptat, zda někdo neví, jak napsat nebo co udělat v preprocessingu regex či jinou formu, abych byl schopen z SNMPtrapu vytáhnout severitu ( vytvořit Alert) a description.
Příklad
14:35:15 2021/02/02 PDU INFO:
messageid 0
receivedfrom UDP: [10.x.x.x]:64023->[10.x.x.x]:162
errorindex 0
community public
notificationtype TRAP
requestid 0
errorstatus 0
transactionid 28809
version 0
VARBINDS:
DISMAN-EVENT-MIB::sysUpTimeInstance type=67 value=Timeticks: (85974) 0:14:19.74
SNMPv2-MIB::snmpTrapOID.0 type=6 value=OID: SNMPv2-SMI::enterprises.14604.2.2.0.1058
SNMPv2-SMI::enterprises.14604.2.2.2.3.0 type=4 value=STRING: "Event Viewer Events - Event Viewer Events"
SNMPv2-SMI::enterprises.14604.2.2.2.4.0 type=4 value=STRING: "Tue, 02 Feb 2021 14:35:08 Central Europe Standard Time"
SNMPv2-SMI::enterprises.14604.2.2.2.5.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.6.0 type=4 value=STRING: "czcommcell.proact.local"
SNMPv2-SMI::enterprises.14604.2.2.2.7.0 type=4 value=STRING: "czcommcell.proact.local"
SNMPv2-SMI::enterprises.14604.2.2.2.8.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.9.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.10.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.11.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.12.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.13.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.14.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.15.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.16.0 type=4 value=STRING: "0"
SNMPv2-SMI::enterprises.14604.2.2.2.17.0 type=4 value=STRING: "Detected Criteria: Event Viewer Events , Event ID: 349906 , Monitoring Criteria: (Severity greater than or equal to Information
, Severity: Information , Job ID: Not Applicable , Event Date: Tue Feb 2 14:34:16 2021 , Program: EvMgrS , Client: czcommcell.proact.local , Description: User [admin] has logged off. Machine: [czosrcvcs01]."
SNMP-COMMUNITY-MIB::snmpTrapAddress.0 type=64 value=IpAddress: 10.34.1.15
SNMP-COMMUNITY-MIB::snmpTrapCommunity.0 type=4 value=STRING: "public"
SNMPv2-MIB::snmpTrapEnterprise.0 type=6 value=OID: SNMPv2-SMI::enterprises.14604.2.2
||
V
************************************************** ************************************************
Chtěl bych, aby mi ukázal Alert - Info, že přišlo Severity: Information (nevím jak)
+ description ( jsem schopen si to vytáhnoout pomocí regex)
"Detected Criteria: Event Viewer Events , Event ID: 349906 , Monitoring Criteria: (Severity greater than or equal to Information
, Severity: Information , Job ID: Not Applicable , Event Date: Tue Feb 2 14:34:16 2021 , Program: EvMgrS , Client: czcommcell.proact.local , Description: User [admin] has logged off. Machine: [czosrcvcs01]."
Díky za Radu
chtěl bych se zeptat, zda někdo neví, jak napsat nebo co udělat v preprocessingu regex či jinou formu, abych byl schopen z SNMPtrapu vytáhnout severitu ( vytvořit Alert) a description.
Příklad
14:35:15 2021/02/02 PDU INFO:
messageid 0
receivedfrom UDP: [10.x.x.x]:64023->[10.x.x.x]:162
errorindex 0
community public
notificationtype TRAP
requestid 0
errorstatus 0
transactionid 28809
version 0
VARBINDS:
DISMAN-EVENT-MIB::sysUpTimeInstance type=67 value=Timeticks: (85974) 0:14:19.74
SNMPv2-MIB::snmpTrapOID.0 type=6 value=OID: SNMPv2-SMI::enterprises.14604.2.2.0.1058
SNMPv2-SMI::enterprises.14604.2.2.2.3.0 type=4 value=STRING: "Event Viewer Events - Event Viewer Events"
SNMPv2-SMI::enterprises.14604.2.2.2.4.0 type=4 value=STRING: "Tue, 02 Feb 2021 14:35:08 Central Europe Standard Time"
SNMPv2-SMI::enterprises.14604.2.2.2.5.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.6.0 type=4 value=STRING: "czcommcell.proact.local"
SNMPv2-SMI::enterprises.14604.2.2.2.7.0 type=4 value=STRING: "czcommcell.proact.local"
SNMPv2-SMI::enterprises.14604.2.2.2.8.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.9.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.10.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.11.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.12.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.13.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.14.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.15.0 type=4 value=STRING: "Not Applicable"
SNMPv2-SMI::enterprises.14604.2.2.2.16.0 type=4 value=STRING: "0"
SNMPv2-SMI::enterprises.14604.2.2.2.17.0 type=4 value=STRING: "Detected Criteria: Event Viewer Events , Event ID: 349906 , Monitoring Criteria: (Severity greater than or equal to Information
, Severity: Information , Job ID: Not Applicable , Event Date: Tue Feb 2 14:34:16 2021 , Program: EvMgrS , Client: czcommcell.proact.local , Description: User [admin] has logged off. Machine: [czosrcvcs01]."SNMP-COMMUNITY-MIB::snmpTrapAddress.0 type=64 value=IpAddress: 10.34.1.15
SNMP-COMMUNITY-MIB::snmpTrapCommunity.0 type=4 value=STRING: "public"
SNMPv2-MIB::snmpTrapEnterprise.0 type=6 value=OID: SNMPv2-SMI::enterprises.14604.2.2
||
V
************************************************** ************************************************
Chtěl bych, aby mi ukázal Alert - Info, že přišlo Severity: Information (nevím jak)
+ description ( jsem schopen si to vytáhnoout pomocí regex)
"Detected Criteria: Event Viewer Events , Event ID: 349906 , Monitoring Criteria: (Severity greater than or equal to Information

Díky za Radu
. Díky za Váš/Tvůj čas
Comment