Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Fault Menu Historical Event Browser


The IP/MPLSView main window has a Fault menu used to display an event browser and event summary reports, to edit thresholds, and to edit event subscriptions. The Event Browser can be used to monitor changes to the network such as link status, LSP tunnel status, VPN status, application errors, and many other types of events.

Select Fault>Historical Event Browser to start the Historical Event Browser.


For an event to be displayed in the historical event browser, it must first be cleared in the Live Event Browser.

To display events in the historical event browser, select Actions > Manage Queries. The Historical Events Query window is displayed.

In the Historical Events Query window, select New. The New Event Query window is displayed.

Select the attributes you want and select a value from the menu in the field. Figure 1 shows the Historical Event Queries and New Event Query windows.

Figure 1: Historical Event Queries and New Event Query Window
Event Queries and New Event Query Window

From the Select Event Query menu, select the query you want and click the arrow. The results are displayed in the Historical Event Browser window.

Events are colored. By default, critical events are red, warnings are yellow, and major events are pink.

Icons at the top of the window are used to synchronize events with the Event Server, post network events, save events to a a file, print events, toggle INFO events, and clear all INFO events.

Select an event to display event details in the lower pane of the window.

Figure 2 shows the historical Event Browser window with one event selected.

Figure 2: Historical Event Browser Window
Event Browser Window

Table 1 describes the Historical Event Browser table columns.

Table 1: Historical Event Browser Table Columns

Column Name


Event State

This is the state of the event.

Event ID

This is the unique ID of the event. If the row corresponds to an aggregate event, this is the ID of the most recent event in the aggregated events.


Supplied by the device sending the event, and is usually a terse description of the information represented by the event. For example, linkUp, mplsLspDown. Event types are defined in the /u/wandl/db/config/ file.

Element Type

The element associated with the event. For example, Interface, Tunnel, or VPN.

Device ID

Usually the hostname of the device. These names are derived from files created by a Scheduling Live Network Collection task in the Task Manager.

Element Name

The name of the element. For example, if the element type is Interface, the element name might be ge-0/0/3.0.


The severity of the event can be INFO, UP, WARNING, MINOR, MAJOR, CRITICAL, or DOWN. These are automatically set by default for each event, but can also be customized.


The time the event occurred, using the server’s time zone. For aggregate events, this is the time the most recent event occurred.

First Timestamp

(For aggregate events only.) The timestamp of the first event in the aggregated events.


(For aggregate events only.) The number of events included in the aggregate event.

Source IP

This is the IP address of the device sending the event.

Source ID

This is the identifier of the device sending the event.

Ack’d On

The time the event was acknowledged.

Ack’d By

The name of the user who acknowledged the event.

Aggregate ID

Identifier for the aggregate event.

Cleared By

The name of the user who cleared the event.

Note that the number of rows in the events table may not be the same as the number of events due to aggregation of events. Events that share the same Event Type, Device ID, Element Type, and Element Name are grouped together into one row representing an aggregate event in order to reduce clutter in the Event Browser.