Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy
A network engineer configures an Embedded Event Manager (EEM) applet to automatically restart a process if it fails. The applet is triggered when a syslog message containing 'PROCESS_FAILURE' is detected. Which EEM event detector type should be used?
- ASyslog
- BSNMP
- CTimer
- DNone
Show answer & explanationAnswer & explanation
Correct answer: A. Syslog
The EEM Syslog event detector allows an applet to be triggered by specific syslog messages, which directly matches the scenario of detecting 'PROCESS_FAILURE' in a syslog message.
Why the other options are wrong
- B. The SNMP event detector triggers applets based on SNMP traps or polling SNMP OIDs.
- C. The Timer event detector triggers applets based on a schedule or recurring interval.
- D. The None event detector is for applets that are manually run or triggered by another applet.
EEM Syslog Event Detector
An Embedded Event Manager (EEM) event detector that triggers an EEM applet when a specific syslog message pattern is matched.
- Monitors syslog messages for predefined patterns.
- Enables automated responses to critical system events.
- Uses regular expressions for pattern matching.
Memory trick: EEM listens for Timers, Syslog, SNMP, and more, to automate tasks and help you soar.