From: Lucy Premus <lpremus@METLIFE.COM>
Date: Wed, 2 Jun 1999 13:09:22 -0400
Yes James I think I understand.  I probably will have more questions once I
delve into it, but I'll give it a shot.  Thanks......Lucy

James_Shanks@tivoli.com on 06/02/99 12:50:08 PM

You want to issue a new trap?   Then you have two ways to go, but either
way you must write a script to issue the snmptrap command with your new
trap data in it.   Then you can kick off that script either in a ruleset or
from an automatic action in trapd.conf.   But writing the script is your
first step.  You have to pass your script the elements of the trap you want
to pass along.  Do you follow me?

James Shanks
Tivoli (NetView for UNIX) L3 Support

Lucy Premus <lpremus@METLIFE.COM> on 06/02/99 11:17:18 AM

Below is an example of a trap we receive from our Cisco PIX firewalls.  It
actually a syslog message, generated by the firewall, that is received by
NetView and converted to a trap via the Cisco syslog mib that I've loaded
NetView.  There are several different syslog messages that can come into
NetView, from the firewalls, but they are all converted and displayed as
via the same syslog mib.

What I would like to do is capture the trap and display a different
event, based on the clogHistMsgText=?????? field (which will be different
depending on the syslog message sent from the firewall).   I believe that
is $4.  Is this possible?  Can it be done via a ruleset or some other

Wed Jun 02 11:04:06 1999     A clogMessageGenerated trap
received from enterprise ciscoSylogMIBNotificationPrefix with 5 arguments:
clogHistFacility=20;  clogHistSeverity=7;  clogHistMsgName=Syslog Trap;
clogHistMsgText=302009;  0 in use,  16384 licensed, 3 most used;

SPECIFIC          :  1 (hex:  1)
GENERIC          :  6
CATEGORY     :  Status Events
ENTERPRISE :  ciscoSyslogMIBNotificationPrefix

