I got the following demand: We have several PaloAlto networks firewalls and I need to monitor different traps - unfortunately, the Trap-Handling is quite cumbersome related to other network monitoring systems, but it is how it is.
This trap OID is sent, when a connected software module fails: 220.127.116.11.4.1.25418.104.22.168.2.0.2303 SNMPv2-SMI::enterprises.25422.214.171.124.1.304 = TS-Agent <name>(vsys1): Error: Failed to connect to <ip>(<ip>):5009 details: none
I created a Trap-Receiver on the firewall object and configured these settings to filter out only this specific trap:
Include Filter: any Exclude Filter: Warning Filter: Error Filter: bindings[126.96.36.199.4.1.254188.8.131.52.2.0.2303,Failed]
When the trap fires, I can see, the trap under the message tab, but the trap is not recognized as an error-trap.
I already tried to leave out the text after the OID, but that didn't work either.
Has somebody ideas how to fix this problem? I'm looking forward to any input.
Best Regards Chacko
PS: A more general question: Isn't there a better way to monitor trap behavior? - if I understood it right, I need to filter out each specific trap which I need to have monitored, because the default polling-interval and alerting settings is different for most traps.