I'm having problems with my trap exploder not keeping up in forwarding snmp traps.
It appears that the trap exploder can only handle up to about 200 traps/second, so anything more than that causes the trap exploder to start falling behind.
From the network we're managing we currently get about 220-250 traps/second so it quickly builds up that we have a backlog.
The effect of this is that when the trap forwarder gets around to forwarding the trap to the IPAM domain, e.g. LinkDown, this can be several hours after the event occured and means that the user can suddenly see an Interface | NetworkConnection - Down | DownOrFlapping event hours after the initial problem started and was resolved.
My parameters set apart from defaults in the trapd.conf file used by the dedicated trap exploder are:
I've tried setting a WINDOW: 5, made no difference and I've set the THREADS to 25 (the maximum), but again it doesn't appear to make a difference.
I don't think it's viable to discard events older than a certain time as Unstable conditions could be missed and management is very tight for these customers.
Does anyone have any advice or other options I could try.
Note I've been told other trap forwarders from other vendors can handle up to 2000/sec, I don't really want to have to integrate another vendor trap forwarder, but looking at the problem it appears that may be the only way.