Network Change & Configuration Management

Reply
Highlighted
Accepted Solution

Enable_15 user listed under Changes

dvaughn2323
Techie
Posts: 8
7971     0

It seems we have an issue with seeing the correct user under Network Analysis>Changes when the device in question is a virtual context. It displays "enable_15".   For example a Cisco 6800 in VSS, or ASA 5585 with virtual contexts.  Shouldn't it actually show the user that logged in and made the change?  It shows the correct user for non virtual devices.

 

 

Re: Enable_15 user listed under Changes

Adviser
Posts: 357
7972     0
The name that is shown is parsed out of the syslog message that was sent to inform NetMRI of the change. So, for some reason either the syslog being sent doesn’t contain the right user, or there is some format/parsing issue. Can you take a look at the syslog that is going out?

John

Re: Enable_15 user listed under Changes

dvaughn2323
Techie
Posts: 8
7972     0

Yes, we've done packet captures just to be sure but the syslog messages contain the correct usernames. 

Re: Enable_15 user listed under Changes

Adviser
Posts: 357
7972     0
Interesting. Do they contain the text ”Enable_15” at all? They must somewhere - it must be a parsing issue.

I think it’s best you open a support case. You can add syslog message formats via a Device Support Bundle yourself, too, if necessary.

Re: Enable_15 user listed under Changes

[ Edited ]
dvaughn2323
Techie
Posts: 8
7972     0

Yes, I believe there is an active case open on this but not much progress.  I'm sort of taking the reins on this from someone else.  

How does the device support bundles work?  I'm new to Infoblox.

Re: Enable_15 user listed under Changes

[ Edited ]
dvaughn2323
Techie
Posts: 8
7972     0

I just looked at a test change I made on a 6800 VSS and it actually listed the user as "N/A" not enable_15.  However, still not my username.  I also did a packet capture and verified that the syslog messages were indeed sent with my correct username.

Re: Enable_15 user listed under Changes

[ Edited ]
Adviser
Posts: 357
7972     0

N/A means it wasn’t able to get it out of the syslog message. More typically that is seen when the syslog has not been configured to be sent to the NetMRI at all, or is blocked by a firewall (it’s UDP so you won’t get an error usually). You can check if NetMRI got the syslog by looking at the ”Change Method” - it should list Syslog in there (there may also be other methods listed). You can also click on the gear and choose View Change Details - it will show you the actual syslog message if there is one.

If you know syslog is getting to the NetMRI, then it’s likely a syslog message format issue. You can see the list of defined syslog formats here:

https://YOUR-NETMRI/netmri/api/change/syslog-config.tdf?contentType=text/xml

(Note: this is NOT an officially support API!)

The logic is that first syslogs are filtered by a simple string match on the MessageFilterString. Any non-matching syslog are ignored. Any matching syslogs are then parsed according to the MessageParsePattern. Only rows for the matching vendor for the specified device (determined by the source IP of the syslog) will be tried, and they will be tried based on the MessageParseOrder with the first match winning.

I myself haven’t spent much time doing DSBs, but there is a way to add entries to this list via a DSB. You’ll have to check the docs to figure out how to do that (unless someone else on here knows and replies…)

John

Re: Enable_15 user listed under Changes

dvaughn2323
Techie
Posts: 8
7972     0

Thanks!  This is alot of useful information.  

Re: Enable_15 user listed under Changes

dvaughn2323
Techie
Posts: 8
7972     0

I'm probably missing something... but your link from above is a deadend.  

 

Re: Enable_15 user listed under Changes

Adviser
Posts: 357
7972     0
You need to replace ”netmri” with the IP or name of your NetMRI.

Re: Enable_15 user listed under Changes

[ Edited ]
dvaughn2323
Techie
Posts: 8
7972     0

Yeah, I tried that but it's returning a 404.  I've tried both Name and IP.  I've got a call with Infoblox today so hopefully that will clear some of this up.  Thanks for your help.

Re: Enable_15 user listed under Changes

Adviser
Posts: 357
7972     0

You're sure it wasn't a 401? You need to be authenticated - so you login to NetMRI then just change the URL in the browser. Still, a support case is probably best here.

Re: Enable_15 user listed under Changes

Adviser
Posts: 357
7972     0

Oh, wait, I see the problem, it should be:

 

https://YOUR-NETMRI/netmri/api/change/syslog-config.tdf?contentType=text/xml

 

I used angle brackets around the hostname and the forum stripped them out as bad HTML...

 

I will update the answer above too.

 

Re: Enable_15 user listed under Changes

dvaughn2323
Techie
Posts: 8
7972     0

That worked, thanks.

Showing results for 
Search instead for 
Do you mean 

Recommended for You