Discussion Forums
Recently active
Multiple Parent Devices: we are trying to enable the Event Correlation on few devices Is it possible to create the same child device for multiple parent devices?
Hallo This is more of a PowerFlow discussion on the CMDB Sync pack. Currently the mapping of attributes is not restricting on what class have what attributes. It is mostly coming down to what we currently have it map within ScienceLogic. The fun of that is that the PF will come down to some weird attributes association with different class, even when that attributes does not exist. Example Blade and CPU counts are certainly not an attributes of wap_network Ci class, however PF will put that together and make the payload a bit bigger and send over to ServiceNow. Then it gets ignored. While that we also cannot see the Ignore on the PF Debug.{ "className":"cmdb_ci_wap_network", "values":{ "x_sclo_scilogic_monitored":true, "x_sclo_scilogic_id":"123456",&nbs
Hi all,I am currently trying to configure some Run book automation policies to enrich data in ServiceNow incidents, sending the RBA output into the Incident worklog, and have hit a bit of a road block on the best way to configure the RBA criteria.Background: We use a dedicated "ServiceNow: [Incident] - Add/Update" RBA for each organisation, which is triggered on event creation, to effectively "Auto Ticket" on all events for specific SL orgs (excluding masked and child rollup). Challenge: In my Enrichment RBA's I want to trigger using "and external ticket IS created", to ensure that I am only posting updates when there has been a ServiceNow incident created. However the OOTB ServiceNow Incident sync pack is updating the events external ticket ref field with various messages e.g. "Sync Successful", before the event is updated with the Incident Number.As soon as the Incident Create updates the events external ticket ref field, by Automation policy gets triggered (I assume becaus
Since upgrading to 12.2.x We have noticed our collector DB sizes increase quiet dramatically and appears to be down to the filestore storage_system_package table, which contains around 6gb. I would assume that anything in the filestore system_package table can now be truncated once deployment have been completed?
Hello Nexus Community Members, ScienceLogic offers training modules and certification programs in our learning portal. This training is a valuable way to learn more about our products and optimize your installation. We wanted to take a minute to call out two important Certifications that we offer: We have quite a few Nexus Community Members who have completed these courses. You can easily identify them in the community by a special badge next to their name. SL: Professional Certified SL Expert Certified This is helpful because when you engage with these members on different community-related topics you know that they have extensive product experience. Please visit our Training Site if you're interested in learning more about these certifications and other learning resources. Cheers, Nexus Community and SL Training Teams
This script is designed to retrieve and parse network interface information from a cisco device, and then optionally print this information in either a human-readable format or as a CSV file. Here's a breakdown of its objectives:Retrieve Interface Information:The script sends commands to a network device to get the interface details (sendget('show interfaces','#')).It captures the output of these commands (local output = before()).Parse the Output:The parse_interfaces function processes the output to extract relevant details about each interface, such as the interface name, description, IP address, MTU, encapsulation type, and packet statistics.Format the Information:The parsed information is stored in a table (interfaces).Print the Information:If enable_csv_print is set to 0, the script prints the interface details in a human-readable format.If enable_csv_print is set to 1, the script converts the interface details into CSV format using the 
I have worked with support on the UDP/TCP ports tab. How it works was not how I thought it would or should work. I thought it would list any open port on a server (this would be helpful) but it does not. Based on how we use the tool I would like this changed to be able to list all open ports and then have the system load all ssl certs assigned to those ports (it only does 443 today for ssl certs). We need an automated way to monitor SSL Certs.We built a custom dynamic app by port (one dynamic app per port number) to handle this but it is clunky and ssl monitoring should be something you address out of the box. Knowing what ports have an SSL cert and when it expires is as important as availability.
Hallo, I was advised by the support that this is "the way it should be" as Message collector are not log aggregator. in Version 12.1.x, the message collector will no longer record the syslog or snmp trap that is received by the MC in any of the capacity. These messages are being proceed on a memory buffer directly into the Event Engine into the Database. 1 - devices are sending syslog + trap to MC - we are able to confirm in tcpdump 2 - MC takes these packets and memory buffer it to somewhere and it get proceed by the mc event engine as ignore or proceed 3 - if proceed - we will see it on the DB 4 - if not proceed - we will see nothing on DB So now, we have no ability to know on the format or the actual message received by the message collector. There is currently no "known way" to redact this into a file or forward out to another syslog server as they are passthrough over the memory, at least we tried and no success. Docs indicated that the rsyslog
The default in SL1 is that collection for interface errors, discards and packets are disabled by default. We can enable collection of errors and discards with via template, but packets have to be enabled on a per-interface basis. Is there a way to change those system defaults? Those are incredibly valuable metrics for troubleshooting, and the fact that they're disabled by default is pretty frustrating. Thanks.
Hi Can we monitor NFS file/volume usage in SL1, if so which powerpack we can use. Kindly suggest.Regards,
Hello Nexus Community Members, We have placed the community in read-only mode for the next couple of days due to spam activity. Spammers tend to attack over the holidays and in order to protect our community members from unwanted messages we have placed the community in read-only mode until we can block the unwanted members and posts. Thank you for your patience, feel free to message me directly for any urgent requests. Best, Sara Leslie Nexus Community Manager
As the new year is upon us, we want to take a moment to express our heartfelt thanks for your partnership and trust in us. It’s been a privilege to work with you, and we are truly grateful for the opportunity to support your success. From our homes to yours, we wish you a joyous holiday season filled with warmth, happiness, and time spent with loved ones. Here’s to new opportunities, growth, and continued collaboration in the year ahead! Happy Holidays!
Hi All, Is there anyway in SL1 to run a specific DA alone in debug mode and see the poll summary against the aligned devices.
Is there a way to retrieve a list of vanished devices with GQL? According to all-mighty AI (CoPilot) there are couple of ways to do it, though none of those seems to work.So the question is if the AI is hallucinating? Or is that possible?
Would it be possible to change or set the severity of a trap event if it occurs at a specific time.e.g. Should it occur during business hours set/change it to a minor or should it occur after hours set/change it to another severity
Hello,One of our customer is using a lot of Custom Scripts, where we are monitoring their output by syslog. There is starting a problem, when script stuck or block. Then customer don't know about it. Is there any possibilities how to monitor, If these scripts are working? We have suggestion, that Custom Scripts can send also message like OK or KO. 2 Events will match these both. There should be an action (run book) for script is running like:em7_snippets.generate_alert(xtype = 1, xid=EM7_VALUES['%x'], message = 'script heartbeat')and not running with count like:if EM7_VALUES['%c'] >= 2: em7_snippets.generate_alert(xtype = 1, xid=EM7_VALUES['%x'], message = 'script is not running')There will be also 2 automation. For script heartbeat will be action for heartbeat every 5min (for example as schedules) and for some Device group.Second automation for not running will have action not running. I think, there will must be next two events which will be matched by
Hello Nexus Community Members, Have you had a chance to visit our User Groups? Most of our user groups are organized around topic, event, location or audience. They are all pertinent to ScienceLogic Products, Services and Customers. There are varying levels of privacy depending on the audience and content. Log In to the Nexus Community Click on the User Group you would like to Join Click on the Send Request to Join button If you think you would like to create and co-manage a user group with us, please message me directly and we can talk about the launch process and how this might benefit the community. Cheers, Sara
Hello Nexus Community Members, We want to continue to welcome new members- we look forward to working with you. @Pritam @Wiseman @AbsoluteBore @vugale @IvanP @Radhika @John4KBRSL1 @jimco @KyleTanaka @Jeff_Kinny Feel free to share your ideas and feedback so we can get you the most helpful resources and information. Cheers, Sara- Community Manager
Trying to create a DA that alerts when filesystem has x GB left rather than percentage left.This is valuable as setting current thresholds to 99% could still mean there is 100's GB still available, which for big filesystems this is not an issue.This information is available through the host resource oid's and I have created a threshold which is visible on the devices the DA is aligned to. However, this is a threshold for ALL filesystems rather than being able to specify for individual filesystems.Anyone with any ideas on how to get the same behavior as the internal filesystem thresholds where we can specify this threshold on individual filesystems?
When SL1 sends event to, in our case, using SL PF Incindent Sync to ServiceNow, other systems it quite often includes the sub-id information also in that message. Normally that is also used as correlation ID in ServiceNow. Example here what is seen in SN:So some events utilize other sub-id's than those ootb cpu/mem/disk/etc. We would also use that kind of feature in our own event policies to send numeric (or string) information in that field. But we have not yet found a place where we can control that. So how is that information sent to servicenow. What fields in event message are used for that info?
Hey, I am wondering if there is an API logic to get all devices aligned to a snippet performance dynamic application ? regardless of whether they are collecting any data or not.
There's been a number of times where we have come across customers who have BGP peers that are not in use or sporadically in use, but they do not wish to remove it from their configs. As a result we get perpetual alerts, but we cannot suppress them as the event suppressed would prevent all bgp peers from alerting. Anyone have thoughts on some ways to single out peers that can be ignored on a per device level? Side note: We are using Powerflow and ServiceNow so we can possibly do something in the path as well. ServiceNow could take care of it, but doesn't help with the peers that flap.
Hi All, I'm new to the Low Code tools/DA builder. I just created a new DA using the DA Builder, and uploaded to my stack. I also have the Low Code Tools Powerpack v101 installed on my system. I'm seeing the following error when I try to run the DA and it seems like I'm possibly just missing some snippet or module and I was wondering if I'm missing something simple:54. Running Snippet 3586 55. Error encountered while executing snippet. Error explanation: App: 3847, Snippet: 3586 threw exception: No module named apps.errors (ImportError: No module named apps.errors File "<string>", line 1, in <module>) 56. Snippet 3586 execution failed.
I was just using the DA builder and realized that the "Component Identifiers" field doesn't contain "Device Name %N" as a field.
Has anyone run into an issue where a few MAC addresses are being read by the snmp handler `snmp_walk` method as gibberish? Non-MAC address string data is returned on some interfaces that seems to be some form of unicode. This is an example when running the SNMP walk from bash: IP-MIB::ipNetToMediaPhysAddress.2.10.250.123.5 = STRING: 24:2a:4:f0:7a:c7 This is the same OID when read by the python SNMP handler: ('.1.3.6.1.2.1.4.22.1.2.2.10.250.123.5', '$*\x04ðzÇ') I've tested the python2.7 execution environment, and the 3.6 env from the Cisco base pack 214. Thanks! Joe
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.