Forum Discussion
smp_86112
Cirrostratus
Jul 29, 2008Custom SNMP Traps - clarify "match string" usage
Reference the article posted by deb a few days ago:
http://devcentral.f5.com/Default.aspx?tabid=63&articleType=ArticleView&articleId=256
After reading this article, I...
Deb_Allen_18
Jul 30, 2008Historic F5 Account
The example you give is from the pre-configured alert.conf file, and there is no need to duplicate it in the user_alert.conf. I think the different uses of the 2 conf files might be what is confusing you.
alertd receives a message from syslog-ng which contains both an alert code and a message string. alertd looks in bigip_error_maps.dat to find an alert definition which matches the alert code or message string. Once a map is found, it performs the action matching the definition in the user_alert.conf (or alertd.conf).
Is that right?
Not exactly. alertd looks in bigip_error_maps.dat to find the alert code, and if found, uses the corresponding alert name to map back to the alert definition in alert.conf. This is the way many pre-configured alerts are defined. The system will also match on any match strings explicitly defined in either conf file and execute the defined alert action.
The error map files are not intended to be modified or supplemented in any way, though, so custom traps are instead always defined in user_alert.conf, including the match string.
The message string sent by syslog-ng is the same one it received -- whatever the system sent to be logged.
hth
/deb
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects