Need Help with cli applet variables

Unanswered Question
Aug 10th, 2012

I want to create just one applet to monitor all my vpn tunnels ( I cannot use .tcl scripting, it bombs on sending emails to our old SMTP server, but applets work fine).

Here is what I have ....

event manager applet VPN-Down

event syslog occurs 1 pattern ".*%CRYPTO-5-SESSION_STATUS:.*Crypto.*tunnel.*is.*DOWN.*192.168.1.1.*"

action 0 cli command "enable"

action 1.0 syslog msg "VPN is down"

action 2.0 cli command "show crypto isakmp sa | incl 192.168.1.1"

action 3.0 mail server "10.150.0.10" to "user@motive.com" from "user@motive.com" subject "VPNt is down" body "$_cli_result"

How do I work this so I can pull the ip address (192.168.1.1) from the syslog match as a variable and then run the appropriate commands?

Any help would be awesome.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 0 (0 ratings)
mtimm Fri, 08/10/2012 - 11:05

What version of code are you running? 

The output of the command executed via 'action cli' is placed into the $_cli_result variable (see "Table 1 EEM Built-in Variables for action cli Command"):

http://www.cisco.com/en/US/docs/ios/netmgmt/command/reference/nm_01.html#wp1190982

Can can then use that variable and run it through a regexp if you are using EEM version 3.0 or later:

http://www.cisco.com/en/US/docs/ios/netmgmt/command/reference/nm_01.html#wp1139025

Mike

louisbohls Fri, 08/10/2012 - 11:12

I am a little confused.  How does that take the IP address out of the syslog message and assign it to a variable?

louisbohls Fri, 08/10/2012 - 13:33

See I would like to match an event more generically like....

event syslog occurs 1 pattern ".*%CRYPTO-5-SESSION_STATUS:.*Crypto.*tunnel.*is.*DOWN.*

Does this event detection match store itself in a variable? (like _event_type_string)

If so, I can then run the "action regex" against that output?

mtimm Fri, 08/10/2012 - 19:42

Yeah that's a better way of handling it but again, you need to have the action regex available in the version of IOS you are using.

For the syslog event detector the captured syslog message is saved off into the $_syslog_msg variable.  See:

http://www.cisco.com/en/US/docs/ios/12_4t/12_4t2/ht_eem.html#wp1064180

Also see the following for the variable being used in an applet but in a different way than you want to:

http://www.cisco.com/en/US/docs/ios/12_4t/12_4t2/ht_eem.html#wp1053112

Mike

mtimm Fri, 08/10/2012 - 19:43

??  How is this helpful?  If it is a duplicate post at the very least point to the other post please.

louisbohls Fri, 08/10/2012 - 20:04

My fault.  I linked the opther post to this.  Thanks for all the help.

Leo Laohoo Sat, 08/11/2012 - 18:10
 If it is a duplicate post at the very least point to the other post please.

Hello.

Hover your cursor above the OP's name and you'll see the duplicate post. 

Actions

Login or Register to take actions

This Discussion

Posted August 10, 2012 at 10:26 AM
Stats:

Related Content

Discussions Leaderboard