Working with Alarms
This section describes how to view, assign, and clear alarms on a Mobility Services Engine using the Prime Infrastructure. It also describes how to define alarm notifications (all, critical, major, minor, warning) and how to e-mail those alarm notifications.
Guidelines and Limitations
Once the severity is cleared, the alarm is deleted from the Prime Infrastructure after 30 days.
Viewing Alarms
To view Mobility Services Engine alarms, follow these steps:
Procedure
|
Step 1 |
Choose Monitor > Alarms. |
||
|
Step 2 |
Click the Advanced Search link in the navigation bar. A configurable search dialog box for alarms appears. |
||
|
Step 3 |
Choose Alarms from the Search Category drop-down list. |
||
|
Step 4 |
Choose the severity of alarms from the Severity drop-down list. The options are All Severities, Critical, Major, Minor, Warning, or Clear. |
||
|
Step 5 |
Choose Mobility Service from the Alarm Category drop-down list. |
||
|
Step 6 |
Choose the Condition from the Condition combo box. Alternatively, you can enter the condition in the Condition text box. |
||
|
Step 7 |
From the Time Period drop-down list, choose the time frame for which you want to review alarms. The options range from minutes (5, 15, and 30) to hours (1 and 8) to days (1 and 7). To display all, choose Any time. |
||
|
Step 8 |
Select the Acknowledged State check box to exclude the acknowledged alarms and their count in the Alarm Summary page. |
||
|
Step 9 |
Select the Assigned State check box to exclude the assigned alarms and their count in the Alarm Summary page. |
||
|
Step 10 |
From the Items per page drop-down list, choose the number of alarms to display in each page. |
||
|
Step 11 |
To save the search criteria for later use, select the Save Search check box and enter a name for the search.
|
||
|
Step 12 |
Click Go. The alarms summary dialog box appears with search results.
|
||
|
Step 13 |
Repeat Step 2 to Step 12 to see Context-Aware Service notifications for the Mobility Services Engine. Enter Context Aware Notifications as the alarm category in Step 5. |
Monitoring Cisco Adaptive wIPS Alarm Details
To view MSE alarm details, follow these steps:
Procedure
|
Choose Monitor > Alarms > failure object to view details of the selected Cisco wIPS alarm. The following alarm details are provided for Cisco Adaptive wIPS alarms: |
-
General Properties—The general information might vary depending on the type of alarm. For example, some alarm details might include location and switch port tracing information. The following table describes the general parameters associated with the MSE Alarm and wIPS Traps condition.
-
Detected By wIPS AP—The access point that detected the alarm.
-
wIPS AP IP Address—The IP address of the wIPS access point.
-
Owner—Name of person to which this alarm is assigned or left blank.
-
Acknowledged—Displays whether or not the alarm is acknowledged by the user.
-
Category—For wIPS, the alarm category is Security.
-
Created—Month, day, year, hour, minute, second, AM or PM that the alarm was created.
-
Modified—Month, day, year, hout, minute, second, AM or PM that the alarm was last modified.
-
Generated By—Indicates how the alarm event was generated (either NMS or from a trap).
NMS (Network Management System - Prime Infrastructure—Generated through polling. Prime Infrastructure periodically polls the Cisco WLCs and generates events. Prime Infrastructure generates events when the traps are disabled or when the traps are lost for those events. in this case, "Generated by" NMS.
Trap—Generated by the controller. Prime Infrastructure process these traps and raises corresponding events for them. In this case, "Generated by" is controller.
-
Severity—Level of severity including critical, major, minor, warning, and clear.
-
Last Disappeared—The date and time that the potential attack last disappeared.
-
Channel—The channel on which the potential attack occurred.
-
Attacker Client/AP MAC—The MAC address of the client or access point that initiated the attack.
-
Attacker Client/AP IP Address—The IP address of the client or access point that initiated the attack.
-
Target Client/AP IP Address—The IP address of the client or access point targeted by the attacker.
-
Controller IP Address—The IP address of the controller to which the access point is associated.
-
MSE—The IP address of the associated Mobility Services Engine.
-
Controller MAC address—The MAC address of the controller to which the access point is associated.
-
wIPS access point MAC address
-
Forensic File
-
Event History—Takes you to the Monitoring Alarms page to view all events for this alarm.
-
-
Annotations—Enter any new notes in this text box and click Add to update the alarm. Notes appear in the "Annotations" display area.
-
Messages—Displays the alarm name.
-
Description—Displays the consolidated information about the alarm.
-
Mitigation Status—Displays what mitigation action was initiated against the attack.
-
Audit Report—Click to view config audit alarm details. This report is only available for Config Audit alarms.
Configuration audit alarms are generated when audit discrepancies are enforced on config groups.

Note
If enforcement fails, a critical alarm is generated on the config group. If enforcement succeeds, a minor alarm is generated on the config group. The alarms have links to the audit report where you can view a list of discrepancies for each controller.
-
Event History—Opens the MSE Alarm Events page to view events for this alarm. When there are multiple alarm pages, the page numbers appear at the top of the page with a scroll arrow on each side. Use these scroll arrows to view additional alarms.
-
Rogue Clients—If the failure object is a rogue access point, information about rogue clients is displayed.
-
Map Location—Displays the map location for the alarm.
-
Floor—The location where this attack was detected.
-
Last Located At—The last time where the attack was located.
-
On MSE—The mobility server engine in which this attack was located.
-
Location History—Click the Location History to see details on the current attacker and victim location.

Note
Out of all the alarms reported by wIPS, the following four alarms are detected at the wIPS server in the Mobility Services Engine (MSE) and not in the access point. For these alarms, currently there is no location information present. The list of alarms are: -
124 Hotspotter tool detected
-
133 Day-Zero attack by device security anomaly
-
135 Day-Zero attack by WLAN security anomaly
-
138 Unauthorized association by vendor list
-
-
Related Alarm List—Lists all the alarms related to a particular attack. This shows what consolidation rule was used to consolidate the alarms.
-
Alarm Name—Name of the alarm.
-
First Heard—Indicates the date and time when the attack first seen.
-
Last Heard—Indicates the date and time when the attack was last seen.
-
Status—Status of the attack.
-
Assigning and Unassigning Alarms
To assign and unassign an alarms, follow these steps:
Procedure
|
Step 1 |
Choose Monitors > Alarms to display the Alarms page. |
||
|
Step 2 |
Select the alarms that you want to assign to yourself by selecting their corresponding check boxes.
|
||
|
Step 3 |
If you choose Assign to Me, your username appears in the Owner column. If you choose Unassign, the username column becomes empty. |
Deleting and Clearing Alarms
If you delete an alarm, the Prime Infrastructure removes it from its database. If you clear an alarm, it remains in the Prime Infrastructure database, but in the Clear state. You should clear an alarm when the condition that caused it no longer exists.
To delete or clear an alarm from a Mobility Services Engine, follow these steps:
Procedure
|
Step 1 |
Choose Monitors > Alarms to display the Alarms page. |
|
Step 2 |
Select the alarms that you want to delete or clear by selecting their corresponding check boxes. |
|
Step 3 |
From the Select a command drop-down list, choose Delete or Clear. Click Go. |
E-mailing Alarm Notifications
The Prime Infrastructure lets you send alarm notifications to a specific e-mail address. Sending notifications through e-mail enables you to take prompt action when needed.
You can choose the alarm severity types (critical, major, minor, and warning) to have e-mailed to you.
To send alarm notifications to e-mail, follow these steps:
Procedure
|
Step 1 |
Choose Monitor > Alarms. |
||
|
Step 2 |
. The Email Notification page appears.
|
||
|
Step 3 |
Select the Enabled check box next to the Mobility Service.
|
||
|
Step 4 |
Click the Mobility Service link. The page for configuring the alarm severity types that are reported for the Mobility Services Engine appears. |
||
|
Step 5 |
Select the check box next to all the alarm severity types for which you want e-mail notifications sent. |
||
|
Step 6 |
In the To text box, enter the e-mail address or addresses to which you want the e-mail notifications sent. Separate e-mail addresses by commas. |
||
|
Step 7 |
Click . You are returned to the Alarms > Notification page. The changes to the reported alarm severity levels and the recipient e-mail address for e-mail notifications are displayed. |






Feedback