Network Management

Orion Platform node mapping limitations in LA

Situations exist where Log Analyzer cannot map a device to an Orion Platform node. Typically, this occurs when a syslog and trap message originating device is already monitored by the Orion Platform.

First published date

11/8/2018 3:52 PM

Last published date

5/11/2020 9:39 PM

Overview

When a syslog and trap message originating device is already monitored by the Orion Platform, LA uses IP address or host name information from syslog and trap messages to map the device to the existing Orion Platform node. However, there are situations when LA cannot map the device to the Orion Platform node.

Product section

Log Analyzer

Resolution

Secondary IP Addresses 

If the device was imported into the Orion Platform as an SNMP node or WMI node, the Orion Platform can poll additional IP addresses (IP other than the Orion Platform polling IP) using an IP address poller (N.IPAddress.WMI.Generic or N.IPAddress.SNMP.Generic). However, the polling may take up to 30 minutes to obtain additional IP addresses. If the device sends syslog or trap messages using one of the additional IP addresses as the source IP, node mapping may take up to 30 minutes and any unmapped messages could be dropped. You can either run Rediscover from the Node Details page to speed up additional address polling, or reconfigure the device to use the Orion Platform polling IP as the syslog/trap source IP. 

Examples of source IP configuration: Juniper Syslog Source IPJuniper Trap Source Interface (© 2019 Juniper Networks Inc., available at https://www.juniper.net/documentation/, obtained on May 2019.) and Cisco ASA Syslog/Trap Source Interface (© 2019 Cisco, available at https://www.cisco.com/c/en/us/support/index.html, obtained on May 2019.)


If the device was imported as an ICMP node or external node, and the device sends a syslog or trap message using one of the additional IP address as the source IP, you can either reimport the device as a WMI or SNMP node, or reconfigure the device to use the Orion Platform polling IP as the syslog/trap source IP.


IP Address Conflicts 

When the source IP address of the syslog or trap message matches more than one Orion Platform node (either matching the Orion Platform polling IP or secondary IP), LA may not be able to determine to which node to map the message. In this instance, the message may be discarded. For devices with conflicting IPs, reassign the Orion Platform nodes to different polling engines. Then, reconfigure each device to send syslog and trap messages to the polling engine the node is currently assigned to.


Missing IP address or host name in syslog message body

When a syslog message body doesn't contain an IP address or host name of the originating device, LA falls back to use the packet source IP for Orion Platform node mapping. When syslog messages are forwarded by other devices without keeping the original source IP, the message might be mapped to a wrong device or fail to map. You can work with network administrators to configure the syslog sender to include the device IP address or host name in the message body. Example of configuration: include device id in Cisco ASA syslog message (© 2019 Cisco, available at https://www.cisco.com/c/en/us/support/index.html, obtained on May 2019).



Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.