Usage Guidelines
The logging correlator rule command defines the correlation rules used by the correlator to store messages in the logging correlator buffer. A rule must, at a minimum, consist of three elements: a root-cause message, one or more non-root-cause messages, and a timeout.
When the root-cause message, or a non-root-cause message is received, the timer is started. Any non-root-cause messages are temporarily held, while the root-cause is sent to syslog. If, after the timer has expired, the root-cause and at least one non-root-cause message was received, a correlation is created and stored in the correlation buffer.
A rule can be of type stateful or nonstateful. Stateful rules allow non-root-cause messages to be sent from the correlation buffer if the bi-state root-cause alarm clears at a later time. Nonstateful rules result in correlations that are fixed and immutable after the correlation occurs.
Below are the rule parameters that are available while in stateful correlation rule configuration mode:
RP/0/0/CPU0:router(config-corr-rule-st)# ?
context-correlation Specify enable correlation on context
nonrootcause nonrootcause alarm
reissue-nonbistate Specify reissue of non-bistate alarms on parent clear
reparent Specify reparent of alarm on parent clear
rootcause Specify root cause alarm: Category/Group/Code combos
timeout Specify timeout
timeout-rootcause Specify timeout for root-cause
RP/0/0/CPU0:router(config-corr-rule-st)#
Below are the rule parameters that are available while in nonstateful correlation rule configuration mode:
RP/0/0/CPU0:router(config-corr-rule-nonst)# ?
context-correlation Specify enable correlation on context
nonrootcause nonrootcause alarm
rootcause Specify root cause alarm: Category/Group/Code combos
timeout Specify timeout
timeout-rootcause Specify timeout for root-cause
RP/0/0/CPU0:router(config-corr-rule-nonst)#
Note |
A rule cannot be deleted or modified while it is applied, so the no logging correlator apply command must be used to unapply the rule before it can be changed.
|
Note |
The name of the correlation rule must be unique across all rule types and is limited to a maximum length of 32 characters.
|
Use the show logging correlator buffer to display messages stored in the logging correlator buffer.
Use the show logging correlator rule command to verify correlation rule settings.