>> I looked in trapd.conf, there wasn't an
entry for it, so I manually put one in there, and set to log only
Did you edit trapd.conf or use the GUI to add this trap def? If you just
edit (very risky anyway - if you mess it up, trapd won't restart) then you
must stop and restart trapd to pick up the change, or issue this from the
command line: event -e FMTCHG
Ultimately, though you are going to have to fix the problem at its source -
DNS -- unless you just want the logs to fill up too.
James Shanks
Tivoli (NetView for UNIX) L3 Support
Xu He <xuhe@YAHOO.COM> on 05/21/99 09:34:09 AM
Please respond to Discussion of IBM NetView and POLYCENTER Manager on
NetView <NV-L@UCSBVM.UCSB.EDU>
To: NV-L@UCSBVM.UCSB.EDU
cc: (bcc: James Shanks/Tivoli Systems)
Subject: Trap flooding event browser in NT 5.1
Good day everyone,
I have encountered a very weird problem with a particular event in the
event browser. I am getting flooded with this trap, about 4 a second
from five machines. My event log size is set to 15000 events, and it's
getting filled up every few hours, and I am not seen any of the
important events. I connected to the database, and the only events in
there are these events. The trap is 58982415, the message is as:
Nameserver returned duplicate name
xxx.xx.xxx.xxx (172.25.67.237) for address 172.25.71.237; interface
172.25.71.237 will be deleted.
I did a nslookup on the name, and it had two address assigned to it.
These devices looks like printers, and have may have a loop back
address assigned to them. I looked in trapd.conf, there wasn't an
entry for it, so I manually put one in there, and set to log only, but
it's still been stored in the event database and all the message are
getting purged every few hours.
Has anyone seen this problem? I am running NT 5.1 version of netview.
What can i do to the message ignoree completely.
Thanks
Xu He
Network Solutions, Inc.
_____________________________________________________________
Do You Yahoo!?
Free instant messaging and more at http://messenger.yahoo.com
|