PDF

Options: Monitoring

Monitoring options - the NetCrunch node address and how it is chosen, discovery defaults, and the settings that prevent false DOWN alerts.

ToolsOptionsMonitoring

General

NetCrunch Node address
Allows selecting the NetCrunch node address from the list of local interface addresses.
Since the monitoring of all nodes in the atlas depends on NetCrunch node, therefore other nodes will be monitored only when selected interface in the NetCrunch Node Address field is enabled and working properly.
Automatically change NetCrunch node
In the case that the selected interface becomes unavailable, the program changes the NetCrunch node automatically to another available interface. Using the DHCP service can cause this change in the local machine IP address. In this case, it is recommended to select the Automatically Change NetCrunch Node check box.
Do not trigger "Node is DOWN" alert for newly discovered nodes
Full monitoring of newly discovered nodes starts only after the node has responded to at least one monitoring request.
Use WINS to resolve node properties
Forces the program to use the WINS to resolve properties of the node.

Default Node Settings

Specifies the default settings for node identification method and monitoring time.

Identification method
A drop-down list that enables selecting how NetCrunch should identify nodes by default: Auto, IP address or DNS Name.
Monitoring time
Default monitoring time that will be automatically set for any newly discovered or inserted nodes.
SNMP profile
SNMP profile saves the Read/Write communities, SNMP authentication credentials, and encryption password, depending which SNMP version is implemented for the node. The SNMP Profile drop-down list allows selecting the correct SNMP profile for the node.
You can also click the Manage SNMP Profiles icon link, next to the Profile field to create a new SNMP profile.
Port
Specifies the port used for SNMP monitoring on the selected node.
Timeout
Specifies the maximum time in milliseconds that NetCrunch should wait for a reply from SNMP before timing out.
Retry count
This parameter specifies how many requests should be sent if SNMP does not respond correctly (timeout, SNMP error, etc.).
Data collection time
The exact time used for collecting inventory data.

Auto Discovered Services

Displays a list of services automatically discovered for nodes. It also enables adding network services to the list or removing them.

Network Services

Displays a list of network services that can be monitored at an extended level. It also enables adding/deleting network services to/from the list and editing their parameters.

The configuration of the extended monitoring level is performed in a set of different windows which contain specific parameters related to the type of the configured service.

The following network services can be configured and monitored at the extended level:

DNS
Domain Name System - service is used for name resolution of domain names on the network.
FTP
File Transfer Protocol - service is used to transfer files over the network.
HTTP
HyperText Transport Protocol service is used for communication and transfer of information on intranets and the WWW servers.
HTTPS
HTTP service running on Secure Sockets Layer (SSL).
POP3
Post Office Protocol 3 service is used to hold incoming emails over the network.
SMTP
Simple Mail Transfer Protocol service is used to transfer and forward email messages over the network.

Physical Segments

Enables the Physical Segments Monitoring. Once, the monitoring is enabled you can choose several analysis methods that can be used to create the most accurate physical segment topology.

Analysis Options

Processing of forwarding tables
The base method that is always used.
Spanning Tree (STP ) Tables
The STP is used in switched networks to prevent loops.
Cisco Discovery Protocol (CDP)
The CDP is used to share information about other directly connected Cisco equipment. It runs on most Cisco devices.
Hide inactive nodes
By default, NetCrunch is trying to remember the last position of all nodes. If this check box is selected, the down nodes will not be shown on Physical Segments Maps.
Data refresh time
Specifies the time interval when NetCrunch will collect information about the physical topology of the monitored atlas. You can specify a different time for refreshing all physical segments in the monitored atlas from the time of monitoring services.
Since the topology of physical maps is not changing frequently it is suggested to define a longer period. All maps in the Physical Segments section of the Atlas Views window will be updated if any change is discovered.

Map Layout Options

When you enable the displaying of physical segment topology maps of your network via a wizard, NetCrunch creates the physical representation of the network. You can also specify some layout elements of the created maps:

Port name style
Specifies the style of the port name on the maps.
Port box style
Specifies the style of the port shape on maps.
Sort Ports By
Allows sorting ports by number or name.

SNMP Traps

Listen to SNMP traps
Allows the program to listen to SNMP traps on a specific port, and possibly redirecting such SNMP traps to a different node in the network.
Group the same messages
NetCrunch uses the mechanism of grouping identical SNMP trap messages received during monitoring. The field specifies the number of seconds when received messages will be combined into. The program default time is 15 seconds.

Syslog Server

Listen to syslog messages
Allows the program to listen for incoming Syslog messages so that they can be processed as NetCrunch events or redirected to other nodes. Clearing this check box will disable this feature.
Redirect syslog messages
Allows the program to redirect incoming Syslog messages to a remote host for processing.
Group the same messages
NetCrunch uses a mechanism of grouping identical Syslog messages received during monitoring.
In this field, you can specify the time when received messages will be combined. The program default is 15 seconds.

Windows Event Log

Reconnection Time
Specifies the reconnect time interval when NetCrunch connects to the Windows machines selected in alerting and gather information specified in created events.
Group the same log entries
Combines the identical entries into one. The field specifies the maximum number of seconds between incoming log entries that will result in grouping them together. The program default time is 15 seconds.

Flow Collector

Enable flow traffic monitoring
Enables NetFlow and sFlow monitoring on specified ports.

Advanced

DNS Resolver

Use Direct DNS Name Resolver
Displays the current information about DNS name for nodes in the DNS Name column in the Map window.
Flush Name Cache
When this button is used, the cache memory of the DNS names is cleared and NetCrunch will query the DNS server to resolve DNS names.
It is important when the DNS server configuration in the monitored network is changed.

HTTP/S Proxy

Proxy settings can be used to send HTTP/S requests by Web Page Sensor and HTTP/S sensor.

auto-discovered servicesdefaultsdnsmonitoringnetflownetwork servicesnodeoptionsphysicalresolversegmentssnmpsyslogthreadstraps