Hi, I'm trying to write a ruleset to check thresholds on Cisco
Authentication traps. To test it, I'm writing a log file after the threshold
criteria has been met. I can get source, time etc from the $NVA, NVATTR_x
variables, no problem... but I can't get the guilty party in any variable.
The trap is defined as :
Cisco Incorrect Community Name (authenticationFailure Trap) authAddr: $1
But I can't extract the '$1' from the trap. What am I doing wrong?
mfg,
Howard Allison
Softcom Consulting GmbH
A - 1120 Wien
Rosasgasse 29
Tel. (43 1) 815 7930
Fax. (43 1) 815 79 3022
howard@howard-allison.com
|