Using Topology Search

After the topology search capability is configured, you can have Operations Analytics - Log Analysis show you the events that occurred within a specific time period on routes between two devices in the network topology. This capability is useful to pinpoint problems on the network, for example, in response to a denial of service attack on a PE device.

The custom apps of the Network Manager Insight® Pack can be run from the Operations Analytics - Log Analysis and, depending on your configuration, from the Network Views in Network Manager IP Edition and the event lists in the Web GUI. The custom apps support searches on Layer 2 and Layer 3 of the topology. The custom apps use the network-enriched event data and the topology data from the Network Manager IP Edition NCIM database. They plot the lowest-cost routes across the network between two nodes (that is, network entities) and count the events that occurred on the nodes along the routes. You can specify different time periods for the route and events. The algorithm uses the speed of the interfaces along the routes to calculate the routes that are lowest-cost. That is, the fastest routes from start to end along which a packet can be sent. The network topology is based on the most recent discovery. Historical routes are not accounted for. If your network topology is changeable, the routes between the nodes can change over time. If the network is stable, the routes stay current.

Before you begin

  • Knowledge of the events in your topology is required to obtain meaningful results from the topology search, for example, how devices are named in your environment, or with what information devices are enriched. Device names are usually indicative of their functions. This level of understanding helps you run searches in Operations Analytics - Log Analysis.
  • Configure the products to enable the topology search capability. See Configuring topology search.
  • To avoid reentering user credentials when launching between products, configure SSO. See Configuring single sign-on for the topology search capability.
  • Create the network views that visualize the parts of the network that you are responsible for and want to search. See https://www.ibm.com/docs/en/networkmanager/4.2.0?topic=views-creating-networkexternal link.
  • Reconfigure your views in the IBM Netcool/OMNIbus WebGUI to display the NmosObjInst column. The tools that launch the custom apps of the Network Manager Insight Pack work only against events that have a value in this column. See Setting up views for event lists external link in the Netcool/OMNIbus documentation.

Procedure

The flow of this procedure is to select the two nodes, select the tool and a time period over which the tool searches the historical event data. Then, in the Operations Analytics - Log Analysis UI, select the route that you are interested in and view the events. You can run searches on the events to refine the results.

  1. Run the topology search from one of the products, as follows:
    • Web GUI event lists:
      1. In an Event Viewer or AEL, select two rows that have a value in the NmosObjInst column.
      2. Right click and click Event Search > Find events between two nodes > Layer 2 Topology or Event Search > Find events between two nodes > Layer 3 Topology, depending on which layer of the topology you want to search.
      3. Click a time filter, or click Custom and select one.
    • Network Manager IP Edition network views:
      1. Select two devices.
      2. Click Event Search > Find Events Between 2 Nodes > Layer 2 Topology or Event Search > Find Events Between 2 Nodes > Layer 3 Topology depending on which layer of the topology you want to search.
      3. Click a time filter, or click Custom and select one.
    • Operations Analytics - Log Analysis UI. In the Operations Analytics - Log Analysis UI, the app requires search results before you can run it. In the search results, select the NmosObjInst column. The app finds the events between the two nodes on which each selected event originated.
      Important: Select the NmosObjInst cells only. Do not select the entire rows. If you select the entire rows, no results are found, or incorrect routes between the entities on the network are found.
      In the Search Dashboards section of the UI, click NetworkManagerInsightPack > Find events between two nodes on layer 2 topology or Find events between two nodes on layer 3 topology, depending which network layer you want to view.

    See Example for an example of how to run the apps from the Operations Analytics - Log Analysis UI.

    The results of the search are displayed on the Operations Analytics - Log Analysis UI as follows:

    Find alerts between two nodes on layer 2 topology
    This app shows the distribution of alerts on the least-cost routes between two network end points in a layer 2 topology. Charts show the alert distribution by severity and alert group for each route over the specified time period. The ObjectServer field for the alert group is AlertGroup. A list of the routes is displayed from which you can search the events that occurred on each route over the specified time period.
    Find alerts between two nodes on layer 3 topology
    This app shows the distribution of alerts on the least-cost routes between two network end points in a layer 3 topology. Charts show the alert distribution by severity and alert group for each route over the specified time period. The ObjectServer field for the alert group is AlertGroup. A list of the routes is displayed from which you can search the events that occurred on each route over the specified time period.

    The apps count the events that occurred over predefined periods of time, relative to the current time, or over a custom time period that you can specify. For the predefined time periods, the current time is calculated differently, depending on which product you run the apps from. Network Manager IP Edition uses the current time stamp. The Netcool/OMNIbus Web GUI uses the time that is specified in the FirstOccurrence field of the events.

    Restriction: The Web GUI and Operations Analytics - Log Analysis process time stamps differently. The Web GUI recognizes hours, minutes, and seconds but Operations Analytics - Log Analysis ignores seconds. This problem affects the Show event dashboard by node and Search for events by node. If the time stamp 8 January 2014 07:15:26 AM is passed, Operations Analytics - Log Analysis interprets this time stamp as 8 January 2014 07:15 AM. So, the results of subsequent searches might differ from the search that was originally run.
  2. From the bar charts, identify the route that is of most interest. Then, on the right side of the UI, click the link that corresponds to that route.
    A search result is returned that shows all the events that occurred within the specified time frame on that network route.
  3. Refine the search results.
    You can use the patterns that are listed in Search Patterns. For example, to search the results for critical events, click Search Patterns > Severity > Critical. A search string is copied to the search field. Then, click Search.
  4. Extend and refine the search as required.
    For more information about searches in Operations Analytics - Log Analysis, see one of the following links:

Example

An example of how to run the custom apps from the Operations Analytics - Log Analysis UI. This example searches between 2 IP addresses: 172.20.1.3 and 172.20.1.5.
  1. To run a new search, click Add search and type NodeAlias:"172.20.1.3" OR NodeAlias:"172.20.1.5". Operations Analytics - Log Analysis returns all events that have the NodeAlias 172.20.1.3, or the NodeAlias 172.20.1.5.
  2. In the results display, switch to grid view. Scroll across until you see the NmosObjInst column. Identify 2 rows that have different NmosObjInst values.
  3. For these rows, select the cells in the NmosObjInst column.
  4. In the Search Dashboards section of the UI, click NetworkManagerInsightPack > Find events between two nodes on layer 2 topology or Find events between two nodes on layer 3 topology, depending which network layer you want to view.