When an event triggers a new alarm or an event is associated with an existing alarm.
When you acknowledge an alarm, the status changes from New to Acknowledged.
An alarm can be in these statuses:
Auto-clear from the device—The fault is resolved on the device and an event is triggered for the same. For example, a device-reachable event clears the device-unreachable event. This in-turn, clears the device-unreachable alarm.
Manual-clear from Prime Infrastructure users: You can manually clear an active alarm without resolving the fault in the network. A clearing event is triggered and this event clears the alarm.
If the fault continues to exist in the network, a new event and alarm are created subsequently based on the event notification (traps/syslogs).
This might be the reason, I believe.
Please refer the following link for better understanding.
Transferring Crash file from standby: Login to the Active WLC in HA.
From CLI: (Cisco Controller) >transfer upload datatype crash (Cisco
Controller) >transfer upload filename (Cisco
Controller) >transfer upload mode tftp (Cisco Controller) >transfer
This is the start of a display filter cross reference between Wireshark
and OmniPeek. The 1st installment is a table of advanced filters. More
filters will be added as time allows. It is a living doc, so check back
for changes every so often Please feel f...