Exploring Event Analytics in NDFC
In this video, you will check alarms, create alarm policy, configure event forwarding, and check accounting.
Hello. My name is Tomas Klanschnik. I am a Cisco data center network subject matter expert with the Cisco technical education team. In this video, you will explore event analytics in NexSys dashboard fabric controller. You will begin with checking alarms in NexSys dashboard fabric controller. Then you will create an alarm policy. You will configure event forwarding. And you will finish with checking the accounting. Let's look at an example where you have implemented a VXLAN EVPN fabric called Fabric with two Spine and two Leaf switches in your environment. Now something happened in the system and Axos Dashboard Fabric Controller raised an alarm. So your first task is to check alarms raised and cleared. You will check alarm policies and create a new one. You would like to be informed about all events in Fabric with a minimum severity critical through email immediately when it happens. This is why you will configure event forwarding and set up an event. In the end, you will view accounting information in NexSys Dashboard Fabric Controller to identify when and what configuration changes have been made in the system and the user responsible for them. Open and log in to NexSys dashboard fabric controller. From the left menu bar, choose dashboard. The overview window displays the default dashlets. In this video, you will focus on event analytics. Event Analytics dashlet displays events with critical error and warning severity. In this example, you can see four zero one minuteor errors. Click on Minor to navigate to Event Analytics pane. You can also click on Operations and Event Analytics to get to the same pane. Alarms tab shows three vertical tabs: alarms raised, alarms cleared, and alarm policies. Alarms raised tab displays the alarms that are generated with various fields: severity of the alarm, source device IP address and name, alarm category, creation and updated time, and policy that caused alarm triggering. In the message field, you can see the alarm description. In this example, you can see that interface Ethernet one slash one zero five is in undesired state, link not connected. Select the first listed alarm, click actions, and choose acknowledge. Click close in the acknowledge succeeded information window. In the acknowledge user, you can now see the username who acknowledged the alarm. In this example, it was admin user. Select the same alarm again, click Actions and choose Clear to clear the alarm. Click Close in the Clear succeeded information window. You can see the alarm disappeared from the alarms raised list. Now click Alarms Cleared tab. This tab displays the cleared alarms. Click twice on the Cleared Time column to sort cleared alarms by their cleared time. You can see previously cleared alarm for interface oneone hundred five in the top row. You can observe alarm cleared time and cleared by admin user in this example. An alarm can also be cleared by the system itself if conditions for the alarm are no longer met. You can see an example of this kind of alarm in the second row. You can recognize it by looking at the cleared by column. It says Event in this case. Click Alarm policies tab. You can see a few active default alarm policies created to trigger alarms because of discovery and reachability issues, for example. To create a new alarm policy, click Actions and choose Create new alarm policy. First, choose policy type. In this example, choose Device Health Policy. Give the policy a name, for example, Peripherals. Scroll down and select all three peripherals checkboxes: Fan, Power Supply, and Module. Click Create Device Health Policy. You can see a new policy named Peripherals listed. If a fan, power supply or module will become unreachable in any device, an alarm will be raised. It can be very useful for the users monitoring your environment to be notified about a particular event immediately when it happens. Nexus dashboard fabric controller enables forwarding an event through email or SNMP traps. To configure proper forwarding of events, navigate to settings and server settings. Choose events tab. Make sure trap listen field is enabled for the system to be able to listen and process SNMP traps. Make sure that enable event forwarding is also enabled to allow event forwarding. Scroll down and enable snooze event forwarding. This will stop the event forwarding within the given time range. You might want to use this feature when upgrading the system to avoid lots of unnecessary events being forwarded. Specify start time. In this example, use Tuesday, June thirteenth at three o'clock in the GMT plus one time zone and year two thousand and twenty three. Specify snooze stop time. In this example, Tuesday, June thirteenth at twenty three o'clock in the GMT plus one time zone and year two thousand and twenty three. Click save. To set up an event forwarding using the Cisco Nexus Dashboard Fabric Controller web user interface, navigate back to Operations and Event Analytics, go to Events tab, click Actions and choose Event Setup. Choose Forwarding tab. You can see Event forwarding enabled and Smoother enabled. Click Actions and choose Add rule. For the forwarding method, choose Email and enter a receiver email address. In this example, type in n d f c eventscisco dot com. In the fabric field, choose fabric. Choose critical for this example. In the minimum severity drop down list, click add rule. You can see a new line added for fabric events. Press X to close event setup window. Configuration changes to the system get locked in a separate log file that can be seen in a tab called accounting. Using accounting tab can help you to identify who did what configuration change and when was it done. You can see several accounting lines with information such as source in one of the lines in this example one zero point one seven six dot one one five dot two three zero. That is an IP address of a Cisco Nexus dashboard. You can also see username, the time the event was created, and the description of an accounting event. This concludes the Cisco technical education video on exploring event analytics in Cisco Nexus dashboard fabric controller. Thank you for watching.