- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Unrealistic number sent on SNMP
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unrealistic number sent on SNMP
Hello everyone!
Could anyone illuminate me if the number I see in Skyline actually is realistic?
We see a "P" suffix in TCP Established column in cpview:
And in Skyline we see this number:
Now, I'm pretty sure that the "P" doesn't stand for Psycho. But the number we see there surely is!
asg_perf -v shows this:
To be honest, I want to say that there is no problem, given the numbers here. But without knowing what P means, I can't really be confident.
Any opinions would be much appreciated.
Cheers!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which SNMP (OID) number are you comparing, are you confusing Skyline vs SNMP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Chris_Atkinson sorry for the late answer.
We have monitoring configured via Skyline (metrics from cpview are sent from the SGM to the Prometheus DB, after which they are visualized in Grafana).
Do you happen to know what "P" stands for in cpview?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know P is for push in tcpdump, but here, comparing screenshots you sent, from the 2nd one, number matches in billions, so logically, sounds like it would imply 15 billion packets? Just my ecucated guess...
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @the_rock I've tested the behavior of the "TCP Established" column in a lab, and the moment connections close, the number decreases. And it increases as new connections are made (I wrote a bash script to create concurrent connections).
Could it be that that Maestro is receiving an attack?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think that number means "Peta", considering the number in Grafana starts with the same 5 digits. At least math check out there. So this means SNMPD actually sends the correct number ("18446P") from CPView.
Then my question is, whether the value in TCP Establised column decreases as the connections close. In my lab, I tried establishing some 500 connections from a host and I see the increase in numbers, but when I close the connections it goes back down.
So which one is the correct behavior, the total values of all times, or only the value of active TCP connections?
