ScienceLogic AI Platform
Recently active
Hey, I am wondering if there is an API logic to get all devices aligned to a snippet performance dynamic application ? regardless of whether they are collecting any data or not.
There's been a number of times where we have come across customers who have BGP peers that are not in use or sporadically in use, but they do not wish to remove it from their configs. As a result we get perpetual alerts, but we cannot suppress them as the event suppressed would prevent all bgp peers from alerting. Anyone have thoughts on some ways to single out peers that can be ignored on a per device level? Side note: We are using Powerflow and ServiceNow so we can possibly do something in the path as well. ServiceNow could take care of it, but doesn't help with the peers that flap.
Hi All, I'm new to the Low Code tools/DA builder. I just created a new DA using the DA Builder, and uploaded to my stack. I also have the Low Code Tools Powerpack v101 installed on my system. I'm seeing the following error when I try to run the DA and it seems like I'm possibly just missing some snippet or module and I was wondering if I'm missing something simple:54. Running Snippet 3586 55. Error encountered while executing snippet. Error explanation: App: 3847, Snippet: 3586 threw exception: No module named apps.errors (ImportError: No module named apps.errors File "<string>", line 1, in <module>) 56. Snippet 3586 execution failed.
I was just using the DA builder and realized that the "Component Identifiers" field doesn't contain "Device Name %N" as a field.
Has anyone run into an issue where a few MAC addresses are being read by the snmp handler `snmp_walk` method as gibberish? Non-MAC address string data is returned on some interfaces that seems to be some form of unicode. This is an example when running the SNMP walk from bash: IP-MIB::ipNetToMediaPhysAddress.2.10.250.123.5 = STRING: 24:2a:4:f0:7a:c7 This is the same OID when read by the python SNMP handler: ('.1.3.6.1.2.1.4.22.1.2.2.10.250.123.5', '$*\x04ðzÇ') I've tested the python2.7 execution environment, and the 3.6 env from the Cisco base pack 214. Thanks! Joe
I want users default page when they login to be a Dashboard in AP2, however, in the user preferences (classic EM7) I cannot see any AP2 Dashboards. Is there a way to force this?
Anybody had any success with this?Going direct to message collectors works as expected. When we put a load balancer in the middle it does not work.As per SL1 documentation, the traffic is being forwarded from the load balancer with the original source IP. However, the source port is different (no mention about that in the documentation) and this is where I think the problem lies as the backend server is sending the tcp acknowledgements back to the source IP but to a different port (the port the LB has forwarded the traffic on).Makes sense that we also need to passthrough the source port being used, but this is not a configuration that has been used before (other apps being managed by the load balancer are mainly https with x-forwarder) and there is a reluctance to configure without evidence that this is correct. Surprising how little information there is out on the internet about configuring LB (unless my googling is not up to scratch :-) )Would be good to know how others have the
Hi All,Do we have any ways under Action Policy by which we can configure so that Parent/Root's IP address can be populated at the time of DB alerts (MSSQL, Oracle etc.)
Rotation of password by Cyberark and the timespan defined with "CacheRefreshInterval" is causing issues with the polling interval of SL1 DAs.With CyberArk, the SL1 can source credential data from CyberARK. Respecting security policies, Cybersecurity recommends changing of password to the SL1 IDs. CyberARK can only specify a time frame during which the passwords can be changed. Within the collectors on the Cyberark agent setup CacheRefreshInterval is set up with 1500 secs (25 mins) to refresh the local cache with the Cyberark every 25 mins.As Cyberark can change the password at any minute or secs of time, SL1 still waits for CacheRefreshInterval to refresh the password. As polling frequencies are default set with 5 minutes(with password change happening at the 4th minute), often SL1 still reaches the server with old password and cause account lockouts.Is there a known way to tackle this issue?
Hello everyone Thank you!
We're looking at enabling Syslog output to a central repository from PowerFlow at an application level. We've already got this running fine at an OS level and SL1 at an application level.Has anybody setup logging for PowerFlow? We're specifically interested in any login type data and also code changes. I've been through as much doc as I can find on the topic, such as:https://docs.sciencelogic.com/pdf/sciencelogic_powerflow_2-1-1.pdfhttps://docs.docker.com/engine/logging/drivers/syslog/https://support.sciencelogic.com/s/article/10819It doesn't appear straight forward to link log files in /var/log/iservices to their respective Docker services.I'm just looking for validation as much as anything, that Docker level logging of the contentapi and gui processes would be the way forward to capture all relevant security related information, and that all other processes can be ignored.
Is there a way to prevent users seeing all public dashboards, so that the user can only see the dashboards related to their organisation. The only way I can think at the moment is to make all dashboards private or org assigned.
How many network adapter is supported. Currently we have migrating between datacenters and due to ACI we cannot have vrf leaking. So we need 3 network adapters to cover all requirements. can someone advice? Currently we have 2 just for info.
“If the server is in a hung state, is there any way we can trigger an event?”
We are planning to upgrade our agents to v146. What are the potential issues in data collection, alerting we might face during the upgrade process.
Tomorrow we'll be performing the upgraded from Aurora 2 to 3? Any gotchas that you can share? I'm already on 12.1.2-p. Thanks!
Hi - We have a requirement to use TLS 1.3 for syslog on a message collector. Is there a way to verify TLS 1.3 is supported? I have configured TLS on a OL7 message collector using this document https://docs.sciencelogic.com/pdf/sciencelogic_sysadmin_12-1-0.pdf and can verify TLS 1.2 is working. TLS 1.3 is not working on a OL7 collector. Thanks
Hi All,We have some custom SNMP DA where we are seeing missed polls , the same SNMP oid is working fine with OOB DA without missed polls. There is no network issue.Anyone facing this issue ?
We are currently facing a scenario where the IP address of our Meraki devices changes upon reboot, which subsequently triggers a DFA alert. To streamline our operations and reduce manual intervention, we are exploring the possibility of capturing these IP changes and updating them automatically in SL.Meraki assets are onboarded through SNMP.
Hi all,We are in the process of setting up SL1 to monitor a mix of Azure and on-prem VMWare devices.The Azure subscription monitors repeatedly error with:"Azure: Network Failure on App: ARMVMPerformance, Message: HTTPSConnectionPool(host='management.azure.com', port=443): Max retries exceeded with url:Failed to establish a new connection: [Errno -2] Name or service not known',)),".We have 14 subscriptions setup and some don't show the error at all, some show it weekly and 1 shows it every 15 minutes generating 1000's of critical alerts a month.SL1 support/PS say it is down to a DNS issue: We have checked with the ENG Team and it looks like a random DNS issue where it can't resolve "management.azure.com" from the collector and it looks transient. The error message points to a failure to resolve the hostname when the config da’s are run.However we use the same DNS server for all collectors and some subscriptions don't see the error. I can also do successful nslookups/pings/nmaps from the
Situation: A map is created and includes network devices which automatically displays layer 2 and layer 3 (including CDP and LLDP) relationships when they are available. The user has the configuration option to filter these out. The layer 4 transport protocol is not displayed. See OC7 model below.Desired outcome: The user is able to switch between layer 3 and layer 4 protocols.
Hi is there a way to create new ticket status just like we would do with other fields using Select Objects Editor feature? We currently have below options that came with the system, and i would like to add more. Is there a way to do that? Status. Status of the ticket. The choices are:Open. Ticket has been created.Pending. Ticket has been acknowledged.Working. Someone is working on the ticket.Resolved. Issue has been resolved.Regards,Tumelo
I'm trying to use GQL to extract detail about our event policies, as the API give very little detail.And as we have a SL hosted system, DB access is only available to us via the Web UI. I've been building the query up, but I'm getting lost on the eventPolicySuppressions.Here's the code:query Event_Policies { eventPolicy(id:4075) { id name editedBy {id user} dateEdited severity { id name } enabled source {name} regularExpression1 regularExpression2 regularExpressionSearch autoClearedEvents { id name editedBy {user} } eventPolicySuppressions { entity {__typename}} } }I only seem to be able to get the entity {_typename} (which is "device") or the entityType ("entityType": "device") as a result. There don't appear to be any other options being offered from the UI suggestions.Does anyone know how I can get the eventPolicySuppressions device or device groups information?Thanks,Richard
Which Dynamic Application is more efficient for File System UtilizationSL1 can trigger two different type of events for when a File System exceeds a threshold:File System exceeded events are generated via an Internal DA by SL1 and is executed every 5 minutesHost Resource Storage Utilization events are generated via a Discovered DA from the SNMP agent on the host and can be collected at 5, 10, or 15-minute intervalI am trying to determine which one make more sense to use on linux servers and is not as taxing the data collectors.
We're having problems with a few windows servers where after a day or two, the server no longer communicates with SL1 and reports the Major event "Device Failed Availability Check: Unknown". When checking the server, we see that the SiloAgent service is no longer running. Startup Type is set to Automatic. Restarting the service fails.We have tried reinstalling the agent only to find that after a day or two, the service fails to run. Anyone else experience this or have any suggestions on what we might do to resolve this?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.