Monitor Alarms

To help you quickly troubleshoot problems, you can easily view and monitor policy violations in the Alarms page (Monitor > Alarms).

To understand and view more information about alarms, see

Alarm descriptions

These tables allow you to quickly view all Crosswork Cloud alarms by application. To view a description of a specific alarm, click an alarm from the appropriate application table.

Table 1. Crosswork Cloud Network Insights Alarms

Unexpected AS Prefix

Prefix Withdrawal

Upstream AS Change

AS Origin Violation

ROA Expiry

Valid AS Path Violation

New AS Path Edge

ROA Failure

Peer Down

AS Path Length Violation

ROA Not Found

Advertised Prefix Count

Parent Aggregate Change

DNS Root Prefix Withdrawal

Prohibited IP Prefix

Prefix Advertisement

Subprefix Advertisement

Table 2. Crosswork Cloud Traffic Analysis Alarms

Gateway Connectivity

Device Connectivity

Interface TX Utilization

Interface RX Utilization

Prefix Utilization

Table 3. Crosswork Cloud Trust Insights Alarms

Gateway Connectivity

Device Running Configuration Change

Hardware Integrity Validation

Device Connectivity

Device SSH Host Key Violation

Mismatched Files

Device Certificate Expiring

Dossier Collection Failure

Package Validation

Device Certificate Violation

Expired Device Certificate

Unknown Files

View active alarms

Active alarms are triggered when a policy rule is violated. Follow these steps to view all active alarms.

Procedure


Step 1

In the main window, click Monitor > Alarms.

Step 2

Click the Active tab. The Active Alarm table appears.

Table 4. Active Alarm table descriptions

Column

Description

Alarm Details

The alarm rule that was violated and triggered the alarm. Click this link to View alarm details.

Trigger

The prefix or ASN on which the alarm occurred. Click this link to view prefix or ASN details.

Policy

The name of the policy that triggered the alarm. Click this link to view details about the policy.

# Peers

The number of peers that reported the alarm.

Severity

The configured severity level of the alarm.

Activated

Date and time the alarm occurred.

Notes

Any user-entered notes about the alarm.

Step 3

To change the sort order, click any column heading.

Step 4

To filter column information, click Add Filter under the column heading and enter text on which to filter.

Step 5

To temporarily suspend alerts for an alarm, select the check box next to one or more alarms you want to snooze, then click Snooze.

  1. From the Snooze Duration drop-down list, choose the time range for which you want to snooze the alarm and then click Snooze. Crosswork Cloud will not send notifications for this alarm for the time range you select.


Temporarily suppress (snooze) alarm notifications

You can temporarily ignore an alarm for a certain period of time or indefinitely. Snoozed alarms will not send notifications until someone intentionally resumes the alarm or until the user defined time range passes. You can choose to snooze an alarm once until it is cleared, one hour, one day, one week, 30 days, or indefinitely.

Although the alarm is snoozed, the alarm state will stay in sync with BGP updates.

Follow these steps to snooze an alarm.

Procedure


Step 1

Choose Monitor > Alarms.

Step 2

Click the Active tab. All active alarms appear in the table.

Step 3

Select the check box next to one or more alarms you want to temporarily suspend and click Snooze. The Snooze Alarm? window appears.

Step 4

From the Snooze Duration drop-down list, choose the time range for which you want to suspend alerts for and click Snooze. This time range will apply to all the alarms you have selected.

Step 5

To verify and view snoozed alarms, click the Snoozed tab.

Step 6

To resume a snoozed alarm, select the check box next to the alarm and click Unsnooze.


View and resume snoozed alarms

Procedure


Step 1

In the main window, click Monitor > Alarms.

Step 2

Click the Snoozed tab. The Snoozed Alarm table appears.

Table 5. Snoozed alarm table descriptions

Column

Description

Alarm Details

The alarm rule that was violated and triggered the alarm. Click this link to View alarm details.

Trigger

The prefix or ASN on which the alarm occurred. Click this link to view prefix or ASN details.

Policy

The name of the policy that triggered the alarm. Click this link to view details about the policy.

# Peers

The number of peers that reported the alarm.

Severity

The configured severity level of the alarm.

Status

  • The alarm state since the last BGP update.

  • Time until the alarm becomes active again:

    • Snoozed Once—The alarm will become active after it is cleared.

    • Snoozed—Hover your mouse over the text to see how much time left until the alarm becomes active again.

Activated

Date and time the alarm occurred.

Modified

Date and time the last status change occurred.

Notes

Any user-entered notes about the alarm.

Step 3

To resume an alarm, select the check boxes next to the alarm and click Unsnooze.

Step 4

To change the sort order, click any column heading.

Step 5

To filter column information, click Add Filter under the column heading and enter text on which to filter.


View alarm details

When an alarm appears in the Alarm table, you can choose to view more information about that alarm. In addition to viewing more details about the alarm, you have the option to modify the policy associated with the alarm or choose to snooze the alarm.

Procedure


Step 1

Choose Monitor > Alarms.

Step 2

Click the specific alarm for which you want to see details. The Alarm Details page appears.

Step 3

Click on one of the tabs to view additional information about the alarm.

Note

 

Not all tabs described below appear for all alarm types. Only tabs relevant to the alarm type you specified are available.

  • Overview—This page appears by default. It contains details about the alarm and the rules that are contained in the policy for which the alarm was raised. See Alarm Overview details for more information.

  • Relevant BGP Updates—Contains details about the BGP updates, as reported by peers, that triggered this alarm. See Relevant BGP update details for alarms for more information.

  • History—Contains historical details about the alarm. See View alarm history for more information.

Step 4

Using the buttons located on the top-right corner, you can update a policy associated with the alarm or snooze the alarm:

  • For Network Insights, click Remove Prefix/ASN from Policy to remove the prefix or ASN and the rule that triggered the alarm from the policy. For Traffic Analysis or Trust Insights, click Edit Policy to make any changes to the policy.

  • Click Snooze to temporarily suspend alerts for the alarm, select the time range for which you want to snooze the alarm, then click Snooze. Crosswork Cloud will not send notifications for this alarm for the time period you select.


Alarm Overview details

To view alarm overview details, choose Monitor > Alarms, click the specific alarm for which you want to see the details, then click the Overview tab. The alarm Overview page appears.

Table 6. Alarm Overview Field Descriptions

Field

Description

Severity

The configured severity level of the alarm.

Activated

Date and time the alarm occurred.

Deactivated

Date and time the alarm was previously deactivated.

Last User Action

The most recent action performed on this alarm by a user.

Expected

The value Crosswork Cloud expects to report for the alarm.

Observed

The actual value observed by Crosswork Cloud.

Violation Peers

The peers that observed the violation.

Geographical map

The location from where the alarm originated.

Notes

Enter any notes about the alarm.

Alarm Looking Glass details

To view alarm Looking Glass details, choose External Routing Analytics > Monitor > Alarms, click View for the alarm for which you want to view more details, then click the Looking Glass tab.


Note


This tab is displayed only if it is available and relevant to the alarm type you specified.


Crosswork Cloud Network Insights displays alarm looking glass details as described in the following table.

Table 7. Alarm Looking Glass field descriptions

Field

Description

Peer AS

The Peer AS.

Peer

The peer identifier, which is used to identify the peer but keep its identity private.

AS Path

The AS routing path.

Communities

The communities path attribute, if applicable.

Last Modified

Date and time the prefix was most recently modified.

Relevant BGP update details for alarms

To view an alarm's relevant BGP update details, click Monitor > Alarms > alarm-name, then click the Relevant BGP Updates tab.

Table 8. Relevant BGP updates field descriptions

Field

Description

Not displayed

A note appears if there are any violation peers with updates older than 6 months, which are not displayed.

Peer

The peer from which the BGP update was received.

Peer AS

The Peer AS from which the BGP update was received.

Prefix

The prefix from which the BGP update was received.

AS Path

The AS routing path.

Communities

The communities path attribute, if applicable.

Update Type

The BGP update type.

Last Updated

Date and time of the last BGP update.

View alarm history

The Alarm history page displays historic alarms for which you can specify a time range. By default, alarms are sorted by the most recent Event At date. The history of an alarm includes every state transition that occurred during its lifecycle and cannot be altered.

Follow these steps to view alarm history.

Procedure


Step 1

Choose Monitor > Alarms.

Step 2

From the Timeframe drop-down list, select a time period that you are interested in. The window updates, displaying alert information for the time range you selected.

Step 3

You can filter any columns that display the Add Filter text. Click Add Filter and enter text on which you want to filter.

Step 4

Under the Timeframe drop-down list, click Tools Table icon to do any of the following tasks:

  • Customize Columns—By default, not all available columns are displayed. Select this option to add, remove, or reorder columns.

  • Export CSV—Select this option to export all currently loaded rows.

    Note

     

    Loaded rows are rows that are currently visible and may only be a subset of the total. You can scroll down to load more rows.

  • Save Table Settings—Select this option to save any customized table settings. This includes any column width resizing, the addition or removal of columns, and any applied filters. After you initially save a table setting, you can later choose to Remove Table Settings or Update Table Settings.