Information

This site will undergo a brief period of maintenance on Friday, 18 December at 12:30 AM Central/12:00 PM IST. During a 30 minute window, site availability may be intermittent.

Configuring a policy in TrueSight Network Automation to correlate a recent NMS event with a configuration change


This topic provides an example of how to configure a policy that sends a Change Summary report via email whenever an Entuity Network Analytics device event occurs within two hours after a change has occurred on that device.

To add a policy condition keyword

  1. Log on to TrueSight Network Automation.
  2. Select Policies > Keywords.
  3. Click Add to add a new Keyword.
  4. In the Add Keyword page, select the options and enter values as shown in the following table:

    Field

    Action

    Name

    Enter Entuity Device Event.

    Type

    Select Event (the default).

    Severity

    Select all options.

    Category

    Select External.

    Event

    Select Any (the default).

    Search String

    Enter EYE Group ID:8.

  5. Click Add.
    The Add Keyword page should look like the following example:

    AddKeyword.png
  6. Click Save.

    Warning

    Note

    This keyword catches Entuity Network Analytics device events. You can customize your keywords to get as granular as you want. For instance, leaving the filter at EYE Group ID: will catch all Entuity Network Analytics events. Setting to EYE Group ID:2 will catch Entuity Network Analytics Port events. Setting to AvailMonitor Node will catch just AvailMonitor Node Down and AvailMonitor Node Up events.

To add a policy condition

  1. Choose Policies > Conditions.
  2. Click Add to add a new condition.
  3. In the Name field, enter Entuity Device Event Now.
  4. In the Keyword field, select Entuity Device Event.
  5. Select the Triggering Condition option.
  6. In the Network Span section, select Entire Network.
  7. Click Save.
  8. Choose Policies > Conditions.
  9. Next to the factory installed condition, Change Detected Past, click the Copy Icon_Copy.png icon.
  10. In the Name field, enter Change Detected Past 2 Hours.
  11. Leave the Keyword field set to Changed Detected.
  12. Leave the Triggering Condition option unselected.
  13. Leave the Network Span field set to Same as Triggering Device.
  14. Change the Duration field to Last 2 Hours.
  15. Leave the Occurrence Count field set to 1.
  16. Modify the Description field to say something similar to the following:

    A configuration change was detected in the past 2 hours.
    The page will look similar to the following example:
    EditCondition.png
  17. Click Save.

To add a policy

  1. Choose Policies > Policies.
  2. Click Add to add a new Policy.
  3. In the Name field, enter Entuity Device Event and Recent Change.
  4. In the Type field, select Event Based.
  5. Select the Enabled option and leave the rest of the fields on this tab at their defaults.
  6. Click the Conditions tab.
  7. In the Triggering Condition field, select Entuity Device Event Now.
  8. For the first Other Condition(s), select Change Detected Past 2 Hours.
    The screen will look similar to the following example:
    EntuityPolicyCondition.png
  9. Click the Actions tab.
  10. Select Add Action and choose Notifications > Send Email.
  11. In the Annotation field, enter something like Entuity Device Event and Recent Change.
  12. In the To field, specify email recipients.
  13. In the Report field, select Change Summary Report.
  14. Leave the Include Link option selected.
  15. Select the Include Attachment option.
  16. Select your attachment format (that is, PDF).
  17. Select the Include All Details option.
  18. In the Network Span field, select Same as Triggering Device.
  19. Select the Include Events option.
  20. Leave the Configuration field set to Running.
  21. Leave the Time Period field set to Last 2 Hours.
    The page will look similar to the following example:

    EntuitySendEmail.png
  22. Click OK.
  23. Click Save.

To test this policy, make a change to a device that will cause some device events to be generated. For example, remove Entuity Network Analytics from the SNMP access control list. Note that the report was generated because the SNMP Not Responding event occurred within 2 hours after a change was made on the device. 

Network Automation sent the report out automatically when this occurred. The report includes the following information:

  • Who made the change
  • When the change was made
  • What device was changed
  • What the change consisted of: (for example, 172.21.127.10 pulled from ACL 40)
  • Device events that occurred as a result of the change: SNMP Not Responding
     ACL 40 is the list that manages SNMP access. This report tells Network Operations that 172.21.127.10 needs to be returned to the list.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

TrueSight Network Automation 24.3