User Guide for Cisco Unified Operations Manager 1.1
Events Processed
Downloads: This chapterpdf (PDF - 378.0KB) The complete bookPDF (PDF - 7.82MB) | Feedback

Events Processed

Table Of Contents

Events Processed


Events Processed


Table D-1 lists all possible events you might see on a Monitoring Dashboard, along with the following:

Description —A summary of the event, including typical causes (if known).

Trigger —How Cisco Unified Operations Manager (Operations Manager) learns of the event : from normal polling, a threshold that was exceeded, a diagnostic test result, or a trap that was received. For a list of thresholds and events that they trigger, see Table 17-14.

Severity —The severity that Operations Manager assigns to the event: critical, warning, or informational.

Device Type —The devices, as classified in Operations Manager, on which the event can occur.

Event Code —The code used by Notifications to track changes to default Operations Manager event names using the Notification event customization feature. (For more information, see Customizing Events.)

Events listed in Table D-1 are displayed on:

The Alert Details page—Shows the majority of events generated. Event names correspond to those displayed in the Description column of the Alert Details page.

The Phone Activities display—Shows information about the IP phones in your network that have become disconnected from the switch, are no longer registered to a Cisco CallManager, or have gone into SRST mode. The following events cause activity to be displayed on the Phone Activities display:

PhoneRemoved

SRSTEntered

SRSTSuspected

The Service Quality Alerts display—Shows events generated as a result of traps received from Service Monitor. The following events cause activity to be displayed on the Service Quality Alerts display:

CriticalServiceQualityIssue

MultipleServiceQualityIssue

ServiceQualityIssue


Note The Cisco1040ProbeDown event is also generated as a result of traps received from Service Monitor. However, Cisco1040ProbeDown appears under Unidentified Trap.


Table D-1 Events that Operations Manager Supports 

Event
Description, Cause, Severity and Event Code

ActivePortThresholdExceeded

Description: Outbound busy attempts exceeded on Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2059.

ApplicationDown

Description: Application can run but is not running due to some problem in the application or device.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2001.

ApplicationPartiallyRunning

Description: The application can run but is waiting, due to some problem in the application or device (for example, lack of CPU resources).

Trigger: Polling.

Severity: Warning.

Device Type: Media Server.

Event Code: 2002.

AverageLatency_ThresholdExceeded

Description: The average latency for a node-to-node data jitter test exceeds the threshold set for the test.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4004

BackupActivated

Description: Backup port or interface has come online, indicating that the port or interface it backs up has gone down.

Trigger: Polling.

Severity: Warning.

Device Type: Host, Hub, Router, Optical Switch, or Switch.

Event Code: 1000.

CallManagerDown

Description: Cisco CallManager can run but is not running due to some problem in the application or device.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2006.

For Cisco CallManager Express, see CCMEDown.

CCMEDown

Description: The Cisco CallManager Express application is down. This could be due to some problem in the application or device.

Trigger: Polling.

Severity: Critical.

Device Type: Router.

Event Code: 2038.

For Cisco CallManager, see CallManagerDown.

CCMEEphoneDeceased

Description: The state of an ephone registered to Cisco CallManager Express changed to deceased.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2076.

CCMEEphoneLoginFailed

Description: An ephone login to Cisco CallManager Express was rejected or failed.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2078.

CCMEEphoneRegistrationFailed

Description: An ephone attempted to register with Cisco CallManager Express and failed.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2077.

CCMEEphoneUnregistrationsExceeded

Description: The number of ephones registered to Cisco CallManager Express was exceeded.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Router or VoiceGateway.

Event Code: 2075.

CCMEKeyEphoneRegistrationChange

Description: Registration status changed for a key IP ephone with respect to Cisco CallManager Express.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2080.

CCMELivefeedMOHFailed

Description: Music on hold (MOH) live feed failed on Cisco CallManager Express.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2074.

CCMEMaximumConferencesExceeded

Description: Maximum number of simultaneous three-party conferences supported was exceeded on Cisco CallManager Express.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2073.

CCMENightServiceChange

Description: Night service status changed on an ephone registered to Cisco CallManager Express.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Router or VoiceGateway.

Event Code: 2079.

CCMEStatusChange

Description: Cisco CallManager Express enabled state has changed.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2072.

CCMHttpServiceDown

Description: HTTP service cannot be used to communicate to all Cisco CallManagers in the cluster. Might be due to the following:

The web service for all Cisco CallManagers in the cluster is down.

The credentials (username, password) for at least one of the running web services were not found or are incorrect.

Trigger: Polling.

Severity: Critical.

Device Type: Cisco CallManager or Cluster.

Event Code: 2009.

CCMHttpServiceInaccessible

Description: Several successive attempts to contact a Cisco CallManager cluster have been unsuccessful. Might be due to the following:

Excessive number of requests on the Cisco CallManager.

Heavy load on the CPU or Cisco CallManager.

Trigger: Polling. (See Determining when to Issue a CCMHttpServiceInaccessible Event.)

Severity: Critical.

Device Type: Cisco CallManager or Cluster.

Event Code: 2010.

CCMLineLinkDown

Description: Attendant Console not receiving the line link state information from Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2089.

CiscoCCMAttendentConsoleHeartBeatExceeded

Description: Cisco CallManager Attendant Console heartbeat is below the threshold value.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2082.

CiscoMessagingInterfaceHeartBeatExceeded

Description: Cisco Messaging Interface heartbeat is below the threshold value.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2083.

CiscoTftpHeartBeatExceeded

Description: Cisco TFTP Service heartbeat is below the threshold value.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2081.

CiscoTranscoderAvailResourceLow

Description: Available Transcoder Resources is below the threshold value.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2084.

Cisco1040ProbeDown

Description: A Cisco 1040 has stopped responding to keepalives from Service Monitor.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Unidentified Trap (because Operations Manager does not monitor Cisco 1040.)

Event Code: 8004.

Note This event appears on the Alert Details page and can be generated only when you have a licensed copy of Service Monitor.

CodeRedStateEntered

Description: Cisco CallManager has entered Code Red State (call throttling mode).

Trigger: Polling.

Severity: Critical.

Device Type: Cisco CallManager or Cluster.

Event Code: 2048.

CodeYellowStateEntered

Description: Cisco CallManager has entered Code Yellow State (call throttling mode).

Trigger: Polling.

Severity: Critical.

Device Type: Cisco CallManager or Cluster.

Event Code: 2049.

ComponentDown

Description: A component within IPCC is down.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2039

CPALoginFailureThresholdExceeded

Description: The number of failed Cisco Personal Assistant logins that exceeded the limit.

Trigger: Exceeded the CPA Login Failure threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2086.

CPATransferFailedThresholdExceeded

Description: Number of times that Cisco Personal Assistant tried and failed to transfer a call.

Trigger: Exceeded the CPA Transfer Failed threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2087.

CPAVoicemailThresholdExceeded

Description: The number of times callers tried to access voice mail but failed, or the number of voicemail login failures that exceeded the limit.

Trigger: Exceeded the CPA Voice Mail threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2088.

cpuUtilizationExceeded

Description: CPU utilization of the voice service or the system cpu utilization that exceeded the limit.

Trigger: Exceeded the CPU Utilization threshold.

Severity: Warning.

Device Type: Media Server.

Event Code: 2085.

CriticalServiceQualityIssue

Description: Operations Manager has received a MOS violation trap from Service Monitor and MOS has fallen below the value set on the Event Settings page. See Configuring Service Quality Event Settings, page 19-9.

Trigger: Event settings. See Configuring Service Quality Event Settings, page 19-9.

Severity: Critical.

Device Type: Service Quality events pertain to the call destination, which might be a device (Voice Gateway) or a phone.

Event Code: 8002.

Note This event is displayed on the Service Quality Alert Details display. (See Using the Service Quality Alerts Display.) This event can be generated only when you have a licensed copy of Service Monitor.

CUEApplicationStatusChange

Description: An application on Cisco Unity Express has come online or gone offline.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router.

Event Code: 2063.

CUEBackupFailed

Description: Cisco Unity Express backup failed.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Router.

Event Code: 2068.

CUECCMConnectionLost

Description: Cisco Unity Express has lost connection with Cisco CallManager.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Router.

Event Code: 2066.

CUENTPIssue

Description: Cisco Unity Express is affected by a problem with NTP.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router.

Event Code: 2069.

CUEResourceExhausted

Description: A Cisco Unity Express resource has been exhausted.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Router.

Event Code: 2067.

CUESecurityIssue

Description: Cisco Unity Express is affected by a problem with security.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router.

Event Code: 2064.

CUEStorageIssue

Description: Cisco Unity Express is affected by a problem with storage.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router.

Event Code: 2065.

DataPhysicalDriveDown

Description: Drive down on Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2061.

DPAPortCallManager
LinkDown

Description: No connectivity between the DPA port and Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Voice Mail Gateway.

Event Code: 2013.

DPAPortTelephonyLinkDown

Description: No connectivity between the DPA port and Octel voice mail.

Trigger: Polling.

Severity: Critical.

Device Type: Voice Mail Gateway.

Event Code: 2014.

Duplicate

Description: Same IP address is configured on multiple managed systems.

Trigger: Polling (often during rediscovery).

Severity: Critical.

Device Type: Host, Hub, Router, Optical Switch, or Switch.

Event Code: 1001.

ExceededMaximumUptime

Description: A backup or dial-on-demand port or interface has been in the Up state for too long.

Trigger: Exceeded Maximum Up Time threshold.

Severity: Warning.

Device Type: Router, Optical Switch, or Switch.

Event Code: 1002.

ExcessiveFragmentation

Description: System memory is highly fragmented.

Trigger: Exceeded Memory Fragmentation Threshold.

Severity: Critical.

Device Type: Host, Router, Switch, or Optical Switch.

Event Code: 1003.

FanDegraded

Description: Fan condition is Degraded.

Trigger: Polling, or processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Media Server or Voice Gateway.

Event Code: 2015.

FanDown

Description: Fan condition is Down.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Media Server or Voice Gateway.

Event Code: 2016.

Flapping

Description: Port or interface is repeatedly alternating between Up and Down states over a short period of time. Operations Manager issues this event by monitoring the number of link downs received within the link window for a particular network adapter (using the Link threshold and Link Window parameters).

Trigger: Exceeded Link Trap Threshold for Link Trap Window; or processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Host, Hub, Router, Optical Switch, or Switch.

Event Code: 1004.

GatekeeperLostContact
WithCluster

Description: Voice gatekeeper lost registration with a Cisco CallManager cluster.

Trigger: Polling.

Severity: Critical.

Device Type: Gatekeeper.

Event Code: 2017.

GatewayLostContact
WithCluster

Description: Voice gateway lost registration with a Cisco CallManager cluster.

Trigger: Polling.

Severity: Critical.

Device Type: Digital Voice Gateway or Voice Gateway.

Event Code: 2018.

HardwareConferenceOutOfResources

Description: Hardware conference bridge registered with Cisco CallManager is out of resources.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2056.

HeartBeatThresholdExceeded

Description: Cisco CallManager heartbeat is over the threshold value.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2051.

HighAnalogPortUtilization

Description: Percentage utilization of an analog port has exceeded a threshold.

Trigger: Exceeded one of these thresholds:

FXS Port Utilization Threshold

FXO Port Utilization Threshold

EM Port Utilization Threshold.

Note You must enable polling for Voice Utilization Settings to monitor for this event.

Severity: Critical.

Device Type: Media Server or Voice Gateway.

Event Code: 4100.

HighBackplaneUtilization

Description: Utilization of the backplane's bandwidth exceeds the backplane utilization threshold.

Trigger: Exceeded Backplane Utilization Threshold.

Severity: Critical.

Device Type: Host, Router, Switch, or Optical Switch.

Event Code: 1005.

HighBroadcastRate

Description: Input packet broadcast percentage exceeds the Broadcast threshold. The input packet broadcast percentage calculates the percentage of total capacity that was used to receive broadcast packets.

Trigger: Exceeded Broadcast Threshold.

Severity: Critical.

Device Type: Host, Router, Switch, or Optical Switch.

Event Code: 1006.

HighBufferMissRate

Description: Rate of buffer misses exceeds the Memory Buffer Miss Threshold.

Trigger: Exceeded Memory Buffer Miss Threshold.

Severity: Critical.

Device Type: Host, Router, Switch or Optical Switch.

Event Code: 1007.

HighBufferUtilization

Description: Number of buffers used exceeds the Memory Buffer Utilization Threshold.

Trigger: Exceeded Memory Buffer Utilization Threshold.

Severity: Critical.

Device Type: Host, Router, Switch, or Optical Switch.

Event Code: 1008.

HighCapacityUtilization

Description: Percentage of voicemail minutes used in Cisco Unity Express exceeds the Capacity Utilization Threshold.

Trigger: Exceeded Capacity Utilization Threshold.

Severity: Critical.

Device Type: Router.

Event Code: 2045

HighCollisionRate

Description: Rate of collisions exceeds the Collision Threshold.

Trigger: Exceeded Collision Threshold.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1009.

HighDigitalPortUtilization

Description: Percentage utilization of a digital port has exceeded a threshold.

Trigger: Exceeded one of these thresholds:

FXS Port Utilization Threshold

FXO Port Utilization Threshold

EM Port Utilization Threshold

Note You must enable polling for Voice Utilization Settings to monitor for this event.

Severity: Critical.

Device Type: Media Server or Voice Gateway.

Event Code: 4101.

HighDiscardRate

Description: A HighDiscardRate event occurs when:

The input packet queued rate is greater than the minimum packet rate, and the input packet discard percentage is greater than the Discard Threshold. The input packet queued rate is the rate of packets received without error. The input packet discard percentage is calculated by dividing the rate of input packets discarded by the rate of packets received.

The output packet queued rate is greater than the minimum packet rate, and the output packet discard percentage is greater than the Discard Threshold. The output packet queued rate is the rate of packets sent without error. The output packet discard percentage is calculated by dividing the rate of output packets discarded by the rate of packets sent.

Trigger: Exceeded Discard Threshold.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1010.

HighErrorRate

Description: A HighErrorRate event occurs for input or output packets when both of the following thresholds are exceeded:

Error Threshold—Percentage of packets in error

Error Traffic Threshold—Percentage of bandwidth in use

Trigger: Exceeded Error Threshold and equaled or exceeded Error Traffic Threshold.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1011.

HighPortUtilization

Description: Percentage of port utilization exceeds a threshold.

Note You must enable polling for Voice Utilization Settings to monitor for this event.

Trigger: Exceeded one of these thresholds:

Voice Mail Port Utilization Threshold

PBX Port Utilization Threshold

Active InBound Ports Threshold

Active OutBound Ports Threshold

Severity: Critical.

Device Type: Media Server or Voice Mail Gateway.

Event Code: 4102.

HighQueueDropRate

Description: Number of packets discarded due to input or output queue overflow exceeding the Queue Drop Threshold. The input (or output) queue overflow is derived by dividing the number of packets designated to be sent (or received) that were discarded due to queue overflow, by the total number of packets in the queue.

Trigger: Exceeded Queue Drop Threshold.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1012.

HighResourceUtilization

Description: A hardware resource threshold has been exceeded.

Trigger: Exceeded one of these thresholds:

MOH Multicast Resources Active Threshold

MOH Unicast Resources Active Threshold

MTP Resources Active Threshold

Transcoder Conference Resources Active Threshold

Hardware Conference Resources Active Threshold

Software Conference Resources Active Threshold

Note You must enable polling for Voice Utilization Settings to monitor for this event.

Severity: Warning.

Device Type: Cisco CallManager or Cluster, Gatekeeper, Media Server, Router, or Voice Gateway.

Event Code: 4103

HighUtilization

Description: Current utilization exceeds the utilization threshold configured for this network adapter or processor.

Trigger: Exceeded one of these thresholds:

Utilization Threshold

Processor Utilization Threshold

Severity: Critical.

Device Type: Host, Media Server, Router, Switch, Optical Switch, or Voice Gateway.

Event Code: 1013.

IdeAtaDiskDown

Description: IDE/ATA drive down on Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2062.

InformAlarm

Description: An informational pass-through trap was generated.

Trigger: Pass-through trap. See Pass-Through SNMP Unidentified Traps.

Severity: Informational.

Event Code: 1014.

InsufficientFreeHardDisk

Description: Free disk space is low.

Trigger: Exceeded Free Hard Disk Threshold.

Severity: Critical.

Event Code: 2020.

Device Type: Media Server.

Also see InsufficientFreeMemory, InsufficientFreePhysicalMemory, InsufficientFreeVirtualMemory.

InsufficientFreeMemory

Description: System is running out of memory resources. Also reported if there has been a failure to allocate a buffer due to lack of memory.

Trigger: Exceeded Free Memory Threshold.

Severity: Critical.

Device Type: Host, Media Server, Router, Switch, or Optical Switch.

Event Code: 1015.

Also see InsufficientFreeHardDisk, InsufficientFreePhysicalMemory, InsufficientFreeVirtualMemory.

InsufficientFree
PhysicalMemory

Description: System is running out of physical memory resources.

Trigger: Exceeded Free Physical Memory Threshold.

Severity: Critical.

Device Type: Voice Gateway.

Event Code: 2021.

Also see InsufficientFreeHardDisk, InsufficientFreeMemory, InsufficientFreeVirtualMemory.

InsufficientFree
VirtualMemory

Description: System is running out of virtual memory resources.

Trigger: Exceeded Free Virtual Memory Threshold.

Severity: Critical.

Event Code: 2022.

Device Type: Media Server.

Also see InsufficientFreeHardDisk, InsufficientFreeMemory, InsufficientFreePhysicalMemory.

InterfaceOperationallyDown

Description: Interface is nonoperational.

Trigger: Polling.

Severity: Critical.

Device Type: Digital Voice Gateway, Media Server, or Voice Gateway.

Event Code: 2023.

Also see OperationallyDown.

IPCCNotification

Description: IPCC sent a notification.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Media Server.

Event Code: 2070.

JitterDS_ThresholdExceeded

Description: Jitter exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4008.

For more information, see Using Node-To-Node Tests.

JitterSD_ThresholdExceeded

Description: Jitter exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4007.

For more information, see Using Node-To-Node Tests.

LostContactWithCluster

Description: Voice gateway, voice gatekeeper, voice port, or voice interface lost registration with a Cisco CallManager cluster.

Trigger: Polling.

Severity: Critical.

Device Type: Voice Gateway (voice port, voice interface), Voice Mail Gateway (voice port), Digital Voice Gateway, Gatekeeper.

Event Code: 2035.

MajorAlarm

Description: Critical pass-through trap was generated.

Trigger: Pass-through trap. See Pass-Through SNMP Unidentified Traps.

Severity: Informational.

Event Code: 1016.

MinorAlarm

Description: Significant pass-through trap was generated.

Trigger: Pass-through trap. See Pass-Through SNMP Unidentified Traps.

Severity: Informational.

Event Code: 1017.

MOHConnectionLost

Description: Cisco CallManager music on hold connection lost.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2054.

MOHOutOfResource

Description: Cisco CallManager out of music on hold resources.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2052.

MTPOutOfResource

Description: Cisco CallManager out of media termination point resources.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2053.

MultipleServiceQualityIssue

Description: Operations Manager has generated a user-defined number of Service Quality Issue events in a user-defined number of minutes.

Trigger: Event settings. See Configuring Service Quality Event Settings, page 19-9.

Severity: Critical.

Device Type: Service Quality events pertain to the call destination, which might be a device (Voice Gateway) or a phone.

Event Code: 8003.

Note When this event occurs, Multiple Service Quality Issues is displayed in the status bar on the Service Quality Alert Details display. (See Using the Service Quality Alerts Display.) This event can be generated only when you have a licensed copy of Service Monitor.

MWIOnTimeExceeded

Description: MWIOnTime value exceeded the threshold.

Trigger: Exceeded MWI on time threshold.

Severity: Warning.

Device Type: Media Server.

Event Code: 2024.

NicDown

Description: Network interface card down on an IPCC.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2040.

NodeToNodeTestFailed

Description: A node-to-node test failed.

Trigger: Node-to-node tests

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4000.

OperationallyDown

Description: Interface—Card or network adapter's operational state is not normal. System Hardware—Disk's operational state is not normal.

Trigger: Polling, or processed trap (see Processed SNMP Traps).

Note For interfaces, Operations Manager will only generate an OperationallyDown clear event if the card is reinserted into the same slot, and if the module index is the same before and after the card is reinserted.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1018.

Also see CardDown, InterfaceOperationallyDown, VoiceCardDown.

OutboundBusyAttemptsThresholdExceeded

Description: Outbound busy attempts exceeded on Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2058.

OutofRange

Description: Device temperature or voltage is outside the normal operating range. When an OutofRange event is generated, you will normally also see fan, power supply, or temperature events.

Trigger: Exceeded one of these thresholds:

Relative temperature threshold

Relative voltage threshold

Severity: Critical.

Device Type: Host, Router, Switch, or Optical Switch.

Event Code: 1019.

PacketLossDS_ThresholdExceeded

Description: Packet loss exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4006.

For more information, see Using Node-To-Node Tests.

PacketLossSD_ThresholdExceeded

Description: Packet loss exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4005.

For more information, see Using Node-To-Node Tests.

PhoneReachabilityTestFailed

Description: Operations Manager cannot reach an IP phone. The IP phone has not responded to three or more successive pings from Operations Manager or the IP SLA device.

Trigger: Polling.

Severity: Critical.

Device Type: IP Phone.

Event Code: 9002.

PhoneRemoved

Description: IP phone lost network connection to the switch.

Trigger: Polling (normally during rediscovery).

Severity: Warning.

Device Type: Phone Access Switch or Voice Gateway.

Event Code: 2025.

Note This event triggers activity on the Phone Activities monitoring dashboard.

PimDown

Description: IPCC Peripheral Interface Manager (PIM) down.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2041.

PortLostContactWithCluster

Description: Voice port lost registration with a Cisco CallManager cluster.

Trigger: Polling.

Severity: Critical.

Device Type: Voice gateway.

Event Code: 2034.

PortsOutOfServiceThresholdExceeded

Description: Port on Cisco CallManager out of service.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2050.

PowerSupplyDegraded

Description: Power supply state is Degraded.

Trigger: Polling.

Severity: Warning.

Device Type: Media Server or Voice Gateway.

Event Code: 2026.

PowerSupplyDown

Description: Power supply state is Down.

Trigger: Trap.

Severity: Critical.

Device Type: Media Server or Voice Gateway.

Event Code: 2027.

QualityDroppedBelowThreshold

Description: Quality has fallen below the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4009.

For more information, see Using Node-To-Node Tests.

RegistrationResponseTime_Threshold
Exceeded

Description: Registration response time exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4003.

For more information, see Using Node-To-Node Tests.

RepeatedRestarts

Description: System repeatedly restarts over a short period of time. Operations Manager issues this event by monitoring the number of system cold and warm starts received within the restart window (using the Restart threshold and the RestartWindow parameters).

Trigger: Exceeded Restart Trap Threshold for Restart Trap Window; or processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1020.

Resumed

Description: Operations Manager resumes monitoring for a device or component that had previously been suspended from monitoring.

Trigger: User clicks Resume on the Detailed Device View for a device or component that was previously suspended from monitoring. Additionally, a user applies changes.

Severity: Critical.

Device Type: Any.

Event Code: 1024.

For more information, see Suspending/Resuming Devices, Suspending/Resuming a Device Component, and Applying Changes.

RingBackResponseTime_Threshold
Exceeded

Description: Ring-back response time exceeds the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4002.

For more information, see Using Node-To-Node Tests.

RoundTripResponseTime_Threshold
Exceeded

Description: Round trip response time fallen below the node-to-node test threshold.

Trigger: Node-to-node test.

Severity: Warning.

Device Type: Router or Switch.

Event Code: 4001.

For more information, see Using Node-To-Node Tests.

SCSIDriveDown

Description: SCSI drive down on Cisco CallManager.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2060.

ServiceDown

Description: Service can run but is not running, due to some problem in the service or device.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2019.

ServicePartiallyRunning

Description: The service can run but is waiting, due to some problem in the service or device (for example, lack of CPU resources).

Trigger: Polling.

Severity: Warning.

Device Type: Media Server.

Event Code: 2007.

Also see ApplicationDown.

ServiceQualityIssue

Description: Operations Manager has received a MOS violation trap from Service Monitor. This indicates that MOS has dropped below a threshold that is set in Service Monitor.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Service Quality events pertain to the call destination, which might be a device (Voice Gateway) or a phone.

Event Code: 8001.

Note This event is displayed on the Service Quality Alert Details display. (See Using the Service Quality Alerts Display.) This event can be generated only when you have a licensed copy of Service Monitor.

SoftwareConferenceOutOfResources

Description: Software conference bridge registered with Cisco CallManager is out of resources.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2057.

SRSTEntered

Description: An IP telephony router is functioning in Survivable Remote Site Telephony (SRST) mode, performing call management for phones in place of the central Cisco CallManager. The event is generated when a WAN link is down, preventing IP phone TCP keepalive messages from reaching the Cisco CallManager.

Trigger: Polling (also see Table 18-1).

Severity: Critical.

Device Type: Router, Switch, or Optical Switch.

Event Code: 9000

Note This event triggers activity on the Phone Activities monitoring dashboard.

SRSTRouterFailure

Description: A catastrophic failure occurred on an SRST router.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Router or VoiceGateway.

Event Code: 2071.

SRSTSuspected

Description: IP Phone Information Facility reports that all phones associated with the SRST router are unregistered, but the WAN link between phones and the central Cisco CallManager is up.

Trigger: Polling.

Severity: Warning.

Device Type: Router, Switch, or Optical Switch.

Event Code: 9001

Note This event triggers activity on the Phone Activities monitoring dashboard.

StateNotNormal

Description: A fan, power supply, temperature sensor, or voltage sensor is not acting normally. When an OutofRange event is generated, you will also see a fan, power supply, or temperature event.

Trigger: Polling.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, or Optical Switch.

Event Code: 1021.

Suspended

Description: Operations Manager suspends monitoring of a device or component.

Trigger: User clicks Suspend on the Detailed Device View for a device or component.

Severity: Critical.

Device Type: Any.

Event Code: 1024.

For more information, see Suspending/Resuming Devices and Suspending/Resuming a Device Component.

SyntheticTestFailed

Description: Individual synthetic test failed on an application.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2011.

SYSLOGNotificationsEvent

Description: Syslog trap generated with a major severity.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Media Server.

Event Code: 2090.

To recieve the SyslogNotificationEvent, you must first enable it for the Cisco CallManager sytem, by running the clogNotificationsEnabled command.

1. On the Operations Manager system, open a Command Prompt, and go to CSCOpx/conf/pif/bin.

2. Enter the following command: SetCCMStorePeriods -f <clogNotificationsEnabled 1(for true) or 2(for false)> -u 5 <ccmAddress> <rwCommunity>.

For example, if x.x.x.x is the Cisco CallManager IP address and the community string is public, the command would look like the following:

SetCCMStorePeriods -f 1 -u 5 x.x.x.x public

TemperatureHigh

Description: Operating temperature exceeds the threshold.

Trigger: Exceeded Relative Temperature Threshold.

Severity: Critical.

Device Type: Media Server, Router, or Switch.

Event Code: 2029.

Also see OutofRange.

TemperatureSensorDegraded

Description: Temperature sensor reports abnormal temperature measurements and reports its condition as Degraded.

Trigger: Polling, or processed trap (see Processed SNMP Traps).

Severity: Warning.

Device Type: Media Server or Voice Gateway.

Event Code: 2030.

TemperatureSensorDown

Description: Temperature sensor reports abnormal temperature measurements and reports its condition as Failed.

Trigger: Processed trap (see Processed SNMP Traps).

Severity: Critical.

Device Type: Media Server or Voice Gateway.

Event Code: 2031.

TooManyInboundPortsActive

Description: Percentage of active Cisco Unity inbound ports exceeded threshold.

Trigger: Exceeded Active Inbound Ports Threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2043.

TooManyOutboundPortsActive

Description: Percentage of active Cisco Unity outbound ports exceeds threshold.

Trigger: Exceeded Active Outbound Ports Threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2044.

TooManyUnityPortsActive

Description: Percentage of active ports exceeds threshold.

Trigger: Exceeded Active Ports Threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2042

TotalTimeUsedThresholdExceeded

Description: Total time used in minutes for greetings and messages in all mailboxes exceeds Total Time Used Threshold.

Trigger: Exceeded Total Time Used Threshold.

Severity: Critical.

Device Type: Media Server.

Event Code: 2047

TranscoderConferenceOutOfResources

Description: Transcoder registered with Cisco CallManager is out of resources.

Trigger: Polling.

Severity: Critical.

Device Type: Media Server.

Event Code: 2055.

Unresponsive

Description: Device does not respond to ICMP or SNMP requests. Probable causes are:

On a system: ICMP ping requests and SNMP queries to the device timeout received no response.

On an SNMP Agent: Device ICMP ping requests are successful, but SNMP requests time out with no response.

Note A system might also be reported as Unresponsive if the only link (for example, an interface) to the system goes down.

Trigger: Polling.

Severity: Critical.

Device Type: Host, Hub, Router, Switch, Optical Switch, Media Server, Phone Access Switch, Voice Mail Gateway, or Voice Gateway.

Event Code: 1022.

VoicePortLostContact
WithCluster

Description: Voice port lost registration with a Cisco CallManager cluster.

Trigger: Polling.

Severity: Critical.

Device Type: Voice Gateway or Voice Mail Gateway.

Event Code: 2036.

VoicePortOperationallyDown

Description: Voice port's operational state is not normal.

Cause: Polling.

Severity: Critical.

Device Type: Voice Gateway.

Event Code: 2037.

Note This event only applies to switch ports, not voice gateway ports.