Network Management

Syslog or Traps warning above threshold reached (Legacy Orion Syslog and Traps)

This article describes how to address the issue where the Orion Console displays a warning that the Syslog or Traps table has run out of space.

First published date

10/18/2018 6:27 AM

Last published date

8/23/2023 2:40 AM

Overview

Note: This only applies to Legacy Orion Syslog and Traps
This won't apply for Orion Log Analyzer / Viewer


The Orion Console displays a warning that the Syslog or Traps has reached a specific number of rows, which is above the predetermined warning threshold. 

Product section

Network Performance Monitor

Cause

Increase or Decrease Syslog Row count value

Resolution

Perform one of the following procedures:

  • Adjust the Syslog or Trap message threshold in your Orion database
  • Reduce or delete the Syslog or Trap message threshold in your Orion database.

If you need to keep a large number of Syslogs or Traps for operational needs, adjust the threshold. 


Adjust the Syslog or Trap message threshold in your Orion database (Note: Increasing Default values may have a negative DB performance impact for your Orion DB)

  1. Back up your Orion database. 
  2. Go to Start > All Programs >SolarWinds Orion > Advanced Features > Database Manager.
  3. Click Add Default Server.
  4. Expand your SQL server Instance Name
  5. Locate Orion DB > Right-click on it and click New Query
  6. Adjust your Syslog warning threshold (if required) and execute:
    -- Scripts are not supported under any SolarWinds support program or service.
    -- Scripts are provided AS IS without warranty of any kind. SolarWinds further
    -- disclaims all warranties including, without limitation, any implied warranties
    -- of merchantability or of fitness for a particular purpose. The risk arising
    -- out of the use or performance of the scripts and documentation stays with you.
    -- In no event shall SolarWinds or anyone else involved in the creation,
    -- production, or delivery of the scripts be liable for any damages whatsoever
    -- (including, without limitation, damages for loss of business profits, business
    -- interruption, loss of business information, or other pecuniary loss) arising
    -- out of the use of or inability to use the scripts or documentation.
    
    Update settings set Currentvalue = xxxxxxxx Where SettingID = 'Syslog-MaxRowCount'

    Note:  xxxxxxx equals to the new threshold.
     

  7. Adjust your Traps warning threshold (if required). 

    Execute:

    -- Scripts are not supported under any SolarWinds support program or service.
    -- Scripts are provided AS IS without warranty of any kind. SolarWinds further
    -- disclaims all warranties including, without limitation, any implied warranties
    -- of merchantability or of fitness for a particular purpose. The risk arising
    -- out of the use or performance of the scripts and documentation stays with you.
    -- In no event shall SolarWinds or anyone else involved in the creation,
    -- production, or delivery of the scripts be liable for any damages whatsoever
    -- (including, without limitation, damages for loss of business profits, business
    -- interruption, loss of business information, or other pecuniary loss) arising
    -- out of the use of or inability to use the scripts or documentation.
    
    Update settings set Currentvalue = xxxxxxxx Where SettingID = 'Trap-MaxMessageAge'

    Note:  xxxxxxx equals to the new threshold.


Reduce or delete the Syslog or Trap message threshold in your Orion database

  1. Back up your Orion database. 
  2. Go to Start > All Programs > SolarWinds Orion > Advanced Features > Database Manager.
  3. Click Add Default Server.
  4. Expand your SQL instance, normally Netperfmon or Solarwinds.
  5. Right-click Syslog or Traps and then click Query Table.
  6. Clear the provided query.
  7. Enter the following query to delete all Syslog messages, Traps, and trap variable bindings older than a designated date (which you can change as desired).

    Execute:

    -- Scripts are not supported under any SolarWinds support program or service.
    -- Scripts are provided AS IS without warranty of any kind. SolarWinds further
    -- disclaims all warranties including, without limitation, any implied warranties
    -- of merchantability or of fitness for a particular purpose. The risk arising
    -- out of the use or performance of the scripts and documentation stays with you.
    -- In no event shall SolarWinds or anyone else involved in the creation,
    -- production, or delivery of the scripts be liable for any damages whatsoever
    -- (including, without limitation, damages for loss of business profits, business
    -- interruption, loss of business information, or other pecuniary loss) arising
    -- out of the use of or inability to use the scripts or documentation.
    
    Delete from Syslog Where datetime <= '4/1/2016 12:59 AM'
    
    Delete from Traps Where datetime <= '4/1/2016 12:59 AM'
    
    Delete from TrapVarBinds where TrapID not in (select TrapID from Traps)

     

  8. (Optional) Delete all existing Syslog messages, Traps, and trap variable bindings using the following Truncate commands:
    -- Scripts are not supported under any SolarWinds support program or service.
    -- Scripts are provided AS IS without warranty of any kind. SolarWinds further
    -- disclaims all warranties including, without limitation, any implied warranties
    -- of merchantability or of fitness for a particular purpose. The risk arising
    -- out of the use or performance of the scripts and documentation stays with you.
    -- In no event shall SolarWinds or anyone else involved in the creation,
    -- production, or delivery of the scripts be liable for any damages whatsoever
    -- (including, without limitation, damages for loss of business profits, business
    -- interruption, loss of business information, or other pecuniary loss) arising
    -- out of the use of or inability to use the scripts or documentation.
    
    Truncate Table Syslog
    Truncate Table Traps
    Truncate Table TrapVarBinds


    You may also like to check out Tips and tricks for managing traps and syslog in Orion NPM
    and Retention Settings for Syslogs and Traps