Network Monitoring Flashcards
Which three of the following actions are native log entry actions?
add a tag to the log entry
continue rule processing but do not save
halt further rule processing for the log entry
If a NetFlow collector service is showing a “down” status, which two of the following steps are possible troubleshooting options?
Confirm the database connection is up and server has free resources.
Start or restart SolarWinds’ NetFlow service from Orion service manager.
What is the minimum amount of RAM required for setting up log collection in hybrid cloud observability?
16 GB
A universal device poller (UDP) was created on the main polling engine to collect CPU temperature for routers polled by the main polling engine and switches polled by the additional polling engine. It
is noted that statistics from the switches are missing. What is the likely cause of the missing statistics?
UDPs are tied to polling engine on which they are hosted
A probe is to be built to test connections to Office 365 from two different locations. How would this be accomplished?
Create two probes and assign each to an agent in each location.
Flow data is not generating from a device in the web console. Wireshark was used to confirm the flows are being sent from the device to the poller and not blocked by the firewall. Why is the data
not showing in the web console?
missing source address field in flow configurations
Which two of the following tasks must be accomplished to monitor servers and connections in a load-balancing environment?
add Cisco Nexus device in network health / performance monitoring
enable F5 iControl polling
What is a possible result of decreasing the top talking optimization value?
increased storage requirement
Which two of the following troubleshooting steps can be performed when a node is “up” and the data cannot be found in SolarWinds’ platform web console?
Ping the device from the polling engine the device is assigned to using the command line.
Wait ten minutes after a device is added to the console. Refresh the screen.
Which tool can be used to display the physical layout of interfaces on graphical stencils?
device view
Which two of the following best practices are used when creating a universal device poller (UDP)?
Consult vendor documentation for OID.
Perform SNMPwalk to determine if OID exists.
A poller is to be built that will add two values together to show a single value in the web console using the universal device poller (UDP) tool. How would this be accomplished?
build a poller for each OID then use transform results to combine values from the two pollers
Which two of the following flow sources are supported by hybrid cloud observability?
Cisco
J-Flow
Which two of the following statements explain creating alerts for NBAR2 applications?
Applications and NBAR2 applications in top applications are sorted by bytes.
It is possible to combine applications and NBAR2 applications.
Which port allows log analysis in the SolarWinds platform to accept secure syslog messages?
TCP port 6514
Which three of the following traffic flow protocols (supported by hybrid cloud observability’s flow monitoring) support flow sampling?
Cisco NetFlow
IPFIX
NetFlow Lite
Which custom filter allows a user to view specific statistics about an entire network and its devices without having to navigate through the web console by single-device views?
flow navigator
Which three of the following data points does NetFlow use to confirm traffic is in the same flow?
IP address
L3 protocol
port number
Which custom poller supports multiple object IDs (OIDs)?
universal device poller (UDP)
Which custom poller supports interface traffic, UPS battery status, and CPU temperature?
universal device poller (UDP)
An unknown traffic event is noted in the web console. What is the likely cause?
receiving flows from a device not monitored by the network
What can be done to show the description of an object ID (OID)?
Perform an SNMPwalk on the target device.
Which NetFlow component can be applied to an interface to track IPv4 traffic?
flow monitor
It is noted that the hardware health monitoring for a Cisco switch is generating false positives. It is verified that the alerted hardware issues are not occurring. What is causing the issue?
MIB on the device is not the preferred MIB that is being polled.
Which SNMP version allows usernames and passwords?
version 3
Which port needs to be open in order to analyze flow and monitor CBQoS?
Flow (UDP, 2055), CBQoS (SNMP, 161)
If the data collected for hardware health is incorrect, which step could rectify the issue?
Change the MIB tree used for polling.
If an IP address group is hidden in IP address groups management, what impact will it have on the data?
group will not be shown in charts or reports
In which two of the following cases does duplicate flow data occur?
both IP flow ingress and egress applied for all interfaces
both IP flow ingress and egress applied on one interface
Several resources are showing duplicate flow data. What is the most likely cause?
source devices are configured to export flow data on ingress and egress
SNMP get type defines the SNMP polling method used by a universal device poller (UDP) to get the device’s object ID (OID) values. Which SNMP get type retrieves values from a particular column?
table
It is noted in flow source view that some devices are showing “never received” in the last received flow column. It is verified that the flows are not being blocked by a firewall. What is the likely cause?
a primary field of data is missing and being dropped
Which two of the following flow technologies are supported?
J-Flow
sFlow
One NetPath probe is showing a “no data found” error, however other probes are returning data without issue. What is the most likely resolution?
delete the probe, reinstall the agent manually, and re-add the probe
Which two of the following Windows versions are supported for log collection in hybrid cloud observability?
Windows 10
Windows server 2019
From which two of the following locations can the status of the flow collector service be checked?
NetFlow collector services
NetFlow settings
Which two of the following processing policies are processed independently and at the same time?
syslog
traps
Which tool presents live flow traffic data sourced from / to a main polling engine server, providing basic insight into traffic on the main polling engine?
local NetFlow source
Which method is used to add new UPS battery status statistics onto an existing node that does not have the default value polled?
define custom statistic with universal device poller (UnDP)
SNMP traps are being received from several devices. While most of the traps are normal, traps from one of the devices contain fields that are unreadable. The device is not being monitored in any other way. Which two of the following points should be checked?
Verify the device supports SNMP and is added as a node.
Verify the device’s MIB file is in SolarWinds’ MIB database.
What is the unit of data used for alerting on flows?
bPs
On a single node, one or more interfaces are showing an “unknown” status. What is the best way to resolve the issue?
Delete and re-add the affected interfaces.
What is the correct sequence of steps to create a device studio poller?
Select the technology, specify the data source, save the poller, and assign the poller to node.
Network wide node and interface changes were recently made to several fields including names and IP addresses on nodes, captions, and aliases for their interfaces. Those changes are not updated in the hybrid cloud observability web console, even if a new polling is forced. What should be done to resolve the issue?
Run a rediscovery on both nodes and interfaces to refresh the data.
Which additional polling method is needed after adding Cisco ASA and Cisco Nexus for SNMP monitoring?
CLI
A universal device poller (UDP) is being built for a metric to monitor in a radial gauge of a web console. When a gauge resource in the poller is to be selected, it is found that the resource is grayed out. What could be causing this?
object ID (OID) polled does not support radial gauge.
Event logs are to be collected from Windows servers in order to be analyzed in hybrid cloud observability. Which two of the following actions must be taken in order to accomplish this ask?
configure server to send logs to another server running the platform
deploy and configure the platform agent to collect the logs
Which statement depicts the relationship between device studio pollers’ supported technologies and universal device pollers’ (UDPs) supported technologies?
UDPs can poll for hardware status of SNMP enabled devices, device studio pollers cannot
A NetPath probe is to be built to monitor the paths between two sites. No Windows servers are available to run the agent. Which two of the following options can be used to set up the probe?
Install the agent on a Windows 10 computer.
Run the probe from the hybrid cloud observability (HCO) server.
A universal device poller (UDP) and a transformer are built to display a transform value for a node’s CPU temperature, however the value is not transformed as displayed on the web console. Which two of the following reasons could have caused the issue?
custom poller used for transformation is not assigned to same node
custom poller and transformer are not using same polling interval
Which three of the following switch port report errors can cause a duplex mismatch?
CRC
> 0.5% receive
late collision
In device studio, which three of the following technologies are supported for custom polling?
multi-CPU / memory
node details
single CPU / memory
Which two of the following technologies are used when building device studio pollers?
machine type for node details widget
power supply status for vital statistics view
A new node has been added to hybrid cloud observability; however, certain data being polled on similar devices is not being polled on the new node. How can this be resolved?
assign existing universal device poller (UDP) to new node
Which three of the following setting can be used to customize the thresholds for an object in SolarWinds’ platform?
X concurrent polls
X consecutive polls
X of Y polls
Upon examining bandwidth utilization, it is confirmed that the total utilization and flow numbers do not match. What is the likely cause?
flows do not contain all traffic in bandwidth numbers
What network capacity planning method is suitable for important devices and connections?
peak calculation
A device studio poller is being built for the node details widget. The plan is to add a field for serial numbers. How would this be accomplished?
Create a serial number universal device poller (UDP) and link to the node details widget.
A node is being polled. The only data visible is response time and packet loss. Detailed statistics are needed. How should this issue be resolved?
switch polling method from ICMP to SNMP
Which tool in the web console will verify the object ID (OID) being used is a match for the node being created for a custom poller?
MIB browser