I setup threshold of processor and cpu in the DFM. For example, I changed "Processor utilization threshold" as 60%. LMS would send alart email if CPU of core switch is beyond it.But i have not received any alert for a long time,so I log on the core switch and type "show process cpu history". In " CPU% per minute (last 60 minutes)", I could find that beyond threshold was happened in this chart (maximum CPU% is beyond 60 %,but average CPU% is not).I want to know why I did not receive any alert.
BTW, I tried to decrease threshold as 1% only for test purpose. Lots of alert could come in.
If decreasing the threshold to 1% works, then DFM must not have seen the 60% CPU spike (either the due to the polling interval or a problem on the device).
It would be a good idea to repeat the test with a sniffer running on the DFM server filtering on SNMP traffic to the device. When the CPU spike occurs, wait for one more polling interval to pass (by default this is every four minutes), then check the sniffer trace to see what the device is advertising in terms of CPU utilization.
As you said, maybe the issue is from polling interval.The default settings is 4m.If one polling interval just passed 2m,DFM found a 60% CPU spike. I want to know if I could receive alert right now or I have to wait for 2m.
BTW,if this spike only lasted 15s, could not I receive any alert anymore?
Since DFM is poll-driven, i must be able to see the event via polling. If a four minute polling interval is too long, you can drop this. But be aware that setting it too low could have a CPU impact.
With CPU utilization, if the spike only lasted for 15 seconds, then DFM might very well not catch it. Perhaps you should consider using something like the Embedded Resource Manager, or a general CPU threshold, and trigger syslog messages which RME can then process.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...