Interface Flapping (Specific Interfaces) Probe

The Interface Flapping (Specific Interfaces) probe determines if specific interfaces are flapping and raises anomalies accordingly.

Probe Overview

If the number of times that the operational state of a specified interface changes is greater than a specified number (Threshold) over a specified amount of time (Duration), then the interface is flapping and an anomaly is raised. Also, if the percentage of flapping interfaces exceeds the specified percentage (Max Flapping Interfaces Percentage), then an anomaly is raised for that device. You can select individual interfaces by system and link names, or you can take advantage of tags and select multiple interfaces simultaneously based on system and link tags. Any interfaces with those tags will be subject to the probe.

Probe Parameters

When you instantiate the predefined Interface Flapping (Specific Interfaces) probe you can customize the above mentioned parameters or leave default values as is, as shown in the screenshot below. Of course, you'll need to add at least one interface before the probe can collect data; you can add it during instantiation or after.

User interface for configuring a predefined probe to monitor interface flapping issues. Includes options to set parameters like interfaces, system tags, max flapping percentage, threshold, duration, and description panel with a create button to finalize.

Probe Stages

The following stages are used in the interface flapping probe for specific fabric interfaces:

Flowchart showing a sequence of processes for analyzing device interface status and flapping, including device interface status, status history, flapping detection, percentage flapping per interface, and system anomalous flapping.

The sections below discuss the stages in detail.

Device Interface Status Processor

Device Interface Status Service Collector (Input)

We begin with the source processor (no inputs), which is a Service Collector configured to collect interface status telemetry for selected device interfaces, as shown in the screenshot below.

Configuration interface for processor device_int_status in a network management tool showing service collector, graph query for systems and interfaces, query tag filter, telemetry details, and advanced options for query expansion and streaming.

Device Interface Status (Output)

This processor keeps track of when the operational state (up, down) of the interface changes. It collects and outputs this information as device interface status (device_if_status). Each interface is identified by its system ID and interface name. Operational state and a few other details are included in the output as shown in the list below:

  • System ID - ID of the leaf device, usually the serial number

  • Interface - name of the interface

  • Remote Interface - interface name on the other end

  • Remote System Label - the device name on the other end

  • Value - operational state of the device (up, down)

  • Updated - when the state was last updated

The following screenshot is an example of the details that are collected from this processor.

Table displaying network device interface status with columns for System ID, Interface, Remote Interface, Remote System Label, Value showing interface status as up, and Updated time.

Device Interface Status History Processor

Device Interface Status History Collector (Input)

For this stage, the Accumulate processor is configured for collecting device interface status history as shown in the screenshot below.

Configuration interface for processor device interface status history, showing Accumulate section with input from device_if_status value, Total Duration 1 minute, Max Samples 6, Graph Query Empty, and Enable Streaming False.

Device Interface Status History (Output)

Device interface status history table showing spine1 system with interfaces xe-0/0/0 and xe-0/0/1 up for remote systems leaf1 and leaf2.

Device Interface Flapping Processor

Device Interface Flapping Collector (Input)

Configuration interface for processor named device interface flapping in a monitoring system. Shows sections for range, processing, and advanced settings.

Interface Status Flapping (Output)

Dashboard showing network monitoring interface status flapping with no anomalies and false values for spine1 and leaf1/leaf2, updated an hour ago.

Percentage Flapping per Device Interfaces Processor

Percentage Flapping per Device Interfaces Collector (Input)

Configuration interface showing percentage flapping per device interfaces processor, with inputs for in, if_status_flapping, value, grouped by system_id, reference state true, and streaming disabled.

Flapping Device Interface Percentage (Output)

Dashboard monitoring interface showing flapping device percentage. Table includes System ID spine1 with total count 2, value, and updated an hour ago. Gauge indicates low percentage.

System Anomalous Flapping Processor

System Anomalous Flapping Collector (Input)

Configuration interface for System Anomalous Flapping processor in monitoring system. Inputs include Input Name: in, Stage Name: flapping_device_int_perc, Column Name: value. Anomalous Range is greater than or equal to 11 for the property value. Raise Anomaly is True. Advanced settings include disabled Graph Query, Raise on NaN, Anomaly Metric Logging, and Enable Streaming. Anomaly MetricLog Retention Duration is 1 day and Retention Size is 1073741824 bytes.

System Flapping(Output)

Dashboard for system_flapping monitoring system 5254007CD62C spine1 with no anomaly. Current value at 11 percent. Last updated an hour ago.