Monitoring Splunk

detect and the reason for the network flapping and reaons

riqbal47010
Path Finder

Last week our one of our core network devices have flapping issue. As per my discussion with network team, there is flapping and active device become standby and standby become active and then there is new eigrp path. and this is happing continuously. which causes network unstable and dead slow because every second routes are getting changed.

can we determine the flapping through any of the streaming command or through streamstats command.

Tags (1)
0 Karma

DavidHourani
Super Champion

Hi @riqbal47010,

You could easily detect this if you are collecting network device logs that's for sure. But figuring out the root cause is about understanding where the problem is, do you know which kind of logs or data could contain this kind of info ?

My advise is to approach the network team and check with them what their usual troubleshooting procedure is, then based on that build a usecase that can automate that procedure using dashboards, reports & alerts.

Let me know if you find the appropriate data source for getting the root cause of flapping ( This could include configuration change logs , since a lot of the network incidents are due to changes).

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...