Monitoring External Events in NetCrunch

Using multiple tools to catch every SNMP trap or SYSLOG message might be hard. NetCrunch simplifies this task with the External Events window and lets you fine-tune your log and SNMP monitoring:

External Events - what are those:

External Events, as the name suggests, are types of events that aren't directly defined in NetCrunch, so there are no out-of-the-box alerts related to them. You can simply stream events into NetCrunch to see what comes, and then with a single click convert the selected ones into alerts.

All such unstructured messages and traps, even from nodes not yet in NetCrunch atlas, can be seen in the External Events tab. Currently there are two types of external events supported by NetCrunch:

  • SYSLOG messages
  • SNMP traps

The goal of the External Events view is to catch every Syslog Message and SNMP trap sent to NetCrunch and to show them to the user.

At first these aren't "alerts", just simple notifications in the External Events tab that shows all the information from this event that can be read by NetCrunch.

example_of_syslog

SYSLOG Message as an external event.

example_of_trap

SNMP Trap as an external event.

Defining alert for the External event:

Here's how you can define alerts for a SYSLOG Message or SNMP v1 or v2 Trap :

  1. Make sure that the trap or message is sent to NetCrunch by your device or system.
  2. Open the External Events tab, and switch to SNMP or SYSLOG.
  3. Find your event on the list and hover over the "monitored" column next to the event to make the set alert option appear. set_alert
  4. Click on the set alert option. If the device sending the message is not in the atlas (as is the case above), it will be automatically added to your Network Atlas.
  5. A window with alerting rules will appear, and it will be automatically filled with data gathered from the trap or syslog. Add a description to the alert and click OK.
  6. Set an alerting rule or choose one from the already defined ones.
  7. That's it! You can now see an icon confirming that this kind of external event is being monitored and you will be alerted every time such a trap or message is received. alert

For SNMP v3 traps we need authorization for the trap to be decoded. It's necessary to add an SNMP profile first and then add the trap to be monitored.

  1. If the trap was already sent, try to find it in the SNMP Traps external event list and click on set alert. Undecoded traps will look similar to the one on the screen below: snmpv3_trap

  2. You will be informed that the SNMP v3 notification profile is needed to decode the trap. Set the proper credentials for SNMP v3, and save the profile. snmpv3_profile

  3. Send the trap once again. Now it will be properly decoded and you will be able to set alerts on it (follow the same steps as for SNMP v1 and v2 traps above). snmp_v3_trap

external eventssnmpsyslogsyslog buffertraptraps bufferweb message

NetCrunch Network Monitoring

Network Maps, Dashboards, and Alerts.
Monitor anything. Network, cloud, config.