AnsweredAssumed Answered

Not able to clear the alarm in CA Spectrum.

Question asked by Madanraj-NPCI on Oct 11, 2018
Latest reply on Oct 26, 2018 by Madanraj-NPCI

Hi All,

 

Anyone can help me for the below request.

I am using spectrum 10.3 . in this we have configured the attack alarm for one device. the alarm is created but the clearing event is not working. 

 

alarm trigger event :

 

A "bigipDosAttackStart" event has occurred, from X device, named X.

A DOS attack start was detected.

bigipNotifyObjMsg = A NETWORK /Common/X DOS attack start was detected for vector Sweep attack, Attack ID 2004692455.

 

in this the attack id is unique .... the same attack id in clear event also.

 

Alarm clear event:

 

A "bigipDosAttackStop" event has occurred, from x, named x.

A DOS attack stop was detected.

bigipNotifyObjMsg = A NETWORK /Common/x DOS attack has stopped for vector Sweep attack, Attack ID 2004692455.

 

in this the start and stop events are not same .

in start event variable  - start was detected

and stop event variable -  attack has stopped

this is the only difference.

here i am attached the clear event configuration.

 

 

Thanks,

john.

Outcomes