Ad Widget

Collapse

How to find out which action made an alert to Zabbix Server?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • VuChi
    Junior Member
    • Jun 2018
    • 2

    #1

    How to find out which action made an alert to Zabbix Server?

    We are testing to deploy snmp traps on Zabbix. It works but we can't tell for which reason. For example , we turn a VPN tunnel from a Fortinet appliance down, it creates an alert. That's all we can see on Zabbix. If we look in the /tmp/zabbix_traps.tmp file we can only see, that the Action is from VPN:

    10:07:16 2018/06/11 .1.3.6.1.4.1.12356.101.2.0.302 event“ "„General" Hostname - ZBXTRAP IP-Address IP-Address severity:event“
    .1.3.6.1.4.1.12356.100.1.1.1.0:FGT60E4Q16049269 .1.3.6.1.2.1.1.5.0:Hostname .1.3.6.1.4.1.12356.101.12.3.2.0:91.217.214.116 .1.3.6.1.4.1.12356.101.12.3.3.0:91.217.214.81 .1.3.6.1.4.1.12356.101.12.3.4.0:vpn

    What else do we need to configure in order to see just like we use an snmp-Agent?

  • cvee.it
    Member
    • Nov 2010
    • 45

    #2
    VuChi,
    Not sure what you are asking.

    You successfully saw the SNMP trap go to your /tmp/zabbix_traps.tmp file, so then you need a trigger which corresponds to the trap in order to create the alert. But you also said it creates an alert, unless you meant it created the trap.

    You should consider enabling OID translation in the output to /tmp/zabbix_traps.tmp .

    Are you using SNMPTT ?



    Comment

    • VuChi
      Junior Member
      • Jun 2018
      • 2

      #3
      We did create a trigger (expression: {fwdeham01:snmptrap.fallback.diff(0)}>0 and {fwdeham01:snmptrap.fallback.nodata(600)}=0) so that when an action occurs, for example, vpn tunnel down, the fortinet appliance sends a trap to zabbix Server. We see then an alert in the Webpage that something is wrong with the appliance , but we can't tell what. We are using snmptt. And when we do a test :
      snmptrap -v 1 -c Community 127.0.0.1:10162 '.1.3.6.1.6.3.1.1.5.3' '0.0.0.0' 6 33 '55' .1.3.6.1.6.3.1.1.5.3 s "teststring000" In /tmp/zabbix_traps.tmp we can see:

      10:06:18 2018/04/13 .1.3.6.1.6.3.1.1.5.3.0.33 event“ "„General" localhost - ZBXTRAP 127.0.0.1 127.0.0.1 severity:event“ .1.3.6.1.6.3.1.1.5.3:teststring000

      Does it mean OID Translation is working?

      Someone suggests, I should try to use
      SNMP Trap Translator Convert MIB v1.4. Is it the right thing to do?

      Comment

      Working...