Ad Widget

Collapse

"High bandwith usage" triggered. but the alert does not include average values

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • elyograg
    Member
    • Aug 2021
    • 37

    #1

    "High bandwith usage" triggered. but the alert does not include average values

    This is the text of the alert that I got this morning from zabbix monitoring my dd-wrt router with SNMP:

    Problem started at 09:24:17 on 2022.08.28
    Problem name: Interface vlan1(): High bandwidth usage (>90% )
    Host: orthanc.elyograg.org
    Severity: Warning
    Operational data: In: 160.71 Kbps, out: 499.1 Kbps, speed: 1 Gbps
    Original problem ID: 1008095
    Looking at the bandwidth graph I can see why it triggered -- because the trigger looks at averages. The problem I see here is that the alert shows the values at that time, not the average values that triggered the alert. Can I get the average in the alert? If so, can it be changed in the SNMP template that came with zabbix? Here is a list of zabbix packages installed on Ubuntu 22:

    elyograg@smeagol:/usr/local/src$ dpkg -l | grep zabbix
    ii zabbix-agent2 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - agent
    ii zabbix-apache-conf 1:6.2.1-1+ubuntu22.04 all Zabbix network monitoring solution - apache configuration for front-end
    ii zabbix-frontend-php 1:6.2.1-1+ubuntu22.04 all Zabbix network monitoring solution - PHP front-end
    ii zabbix-get 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - get
    ii zabbix-js 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - js
    ii zabbix-release 1:6.2-1+ubuntu22.04 all Zabbix official repository configuration
    ii zabbix-sender 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - sender
    ii zabbix-server-mysql 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - server (MySQL)
    ii zabbix-sql-scripts 1:6.2.1-1+ubuntu22.04 all Zabbix network monitoring solution - sql-scripts
    ii zabbix-web-service 1:6.2.1-1+ubuntu22.04 amd64 Zabbix network monitoring solution - web-service

    Click image for larger version

Name:	image.png
Views:	2947
Size:	23.1 KB
ID:	450531

    Another interesting thing: Looking at the dd-wrt config, vlan1 is assigned to switchports that have nothing plugged in. So I need to have a discussion with dd-wrt support about why SNMP shows nearly 1000 Mbps on a vlan that should never see any traffic at all.
    Attached Files
  • elyograg
    Member
    • Aug 2021
    • 37

    #2
    There is a bug in the DD-WRT web UI. All the switchports are actually assigned to vlan1 even though the UI says otherwise. And I know what caused the traffic, the alert from zabbix was completely legit.

    All that's left is figuring out whether the alert can show the average numbers instead of the traffic at the time of the alert.

    Comment


    • SocialDemocracyisAtrap!
      SocialDemocracyisAtrap! commented
      Editing a comment
      Hi all! to my knowledge most of the cheap SOHO devices that dd-wrt manages (routers, switches, aps) have only a single PHY even they have WAN and LAN and WIFI ports - they work is based on VLAN switching - so it might be just due to some snmp implementation as you noted below - just wanted to point that info as it is both interesting and devastating to know that a 5 port device in fact has only one port exposed to the microcontroller only understanding (or not ) the VLANs
  • cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807

    #3
    You are leaving out some details, like your trigger config... I assume you are using macros like {ITEM.VALUE} there? You should try expression macros in event name.. https://www.zabbix.com/documentation...ression_macros

    Comment

    • elyograg
      Member
      • Aug 2021
      • 37

      #4
      I left out the triggers because I did not set them up. They are set up by the Linux SNMP template that comes with Zabbix.

      Today I got another annoying series of alerts, for three interfaces on another wireless router (ASUS) I have for IoT stuff, also using the Linux SNMP template. This only does 2.4Ghz, and is in AP mode on a separate subnet. My main DD-WRT router only does 5Ghz WPA3.

      Problem started at 15:18:23 on 2022.10.15
      Problem name: Interface vlan1(): High bandwidth usage (>90% )
      Host: barad-dur.elyograg.org
      Severity: Warning
      Operational data: In: 45.45 Kbps, out: 23.54 Kbps, speed: 10 Mbps
      Original problem ID: 1059378


      This is very annoying because it thinks that the interface speed is 10Mbps, which means the device's SNMP is braindead and is reporting incorrect values to Zabbix. The device has gigabit network interfaces. The data rate that the graph shows is only about 20 Mbps. At least the other device running DD-WRT reports correct interface speeds.

      These new alerts also only display instantaneous values, but trigger on the average values.

      Comment

      • elyograg
        Member
        • Aug 2021
        • 37

        #5
        I figured out how to configure the net-snmp agent that I had manually installed on the ASUS router to report the interfaces as gigabit.

        Comment

        • Streamvision
          Junior Member
          • Nov 2022
          • 1

          #6
          Hi elyograg, Can you share what you did here?

          I have an issue where SNMP is reporting 10Mb ports but there is nothing even connected.​

          Comment

          • elyograg
            Member
            • Aug 2021
            • 37

            #7
            Streamvision Unfortunately I did not take any notes, and now I can't remember how to do it! I have since reinstalled that router and I am having the same problem again.

            Comment

            • b15turman
              Junior Member
              • Dec 2023
              • 1

              #8
              The solution is to modify the snmp.conf file and manually specify the interface speeds.

              https://superuser.com/questions/2864...widths-in-snmp

              After enabling SSH on DDWRT, I found the location of snmp.conf

              Click image for larger version

Name:	image.png
Views:	1694
Size:	5.1 KB
ID:	475764

              The I edited the snmp conf using vi /tmp/snmpd.conf

              Click image for larger version

Name:	image.png
Views:	1676
Size:	7.1 KB
ID:	475765

              Then I killed snmpd using kill -9 17680 (the PID from above) and launched SNMPD again (snmpd -c /tmp/snmpd.conf)



              Comment

              Working...