show notification mac-movement

Displays the MAC address movement notifications.
Syntax
show notification mac-movement { interval-history | threshold-rate }
Parameters
interval-history
Displays the collected history of MAC address movement notification and how the history interval is configured.
threshold-rate
Displays the configuration of the MAC address movement threshold rate.
Modes

User EXEC mode

Privileged EXEC mode

Global configuration mode

Interface configuration mode

The show notification mac-movement interval-history command displays the following information:

Output field Description
Interval-History Mac Movement Notification Specifies whether the interval history data collection is enabled.
Configured Interval The interval over which the MAC address movement statistics were collected.
Number of macs that moved in the interval The number of MAC addresses that moved during the configured interval regardless of how many times each address moved.
Total number of moves in the interval The total number of MAC address moves over the configured interval.
Interval Move-Count The number of times the MAC address has moved within the interval.

The show notification mac-movement threshold-rate command displays the following information:

Output field Description
Threshold-Rate Mac Movement Notification Specifies whether the MAC movement notification threshold rate is enabled.
Configured Threshold-Rate The rate in MAC address moves per sampling interval after which a notification is issued. The range is from 1 through 50000.
Configured Sampling-Interval The sampling interval in seconds over which the number of MAC address moves is measured. The range is from 1 through 86400, which is the number of seconds in a day.
Number of entries in the notification table One entry for each time a MAC address notification threshold was reached.
MAC-Address The MAC address that has moved to a different port.
from-Port The port from which the MAC address moved.
to-Port The port to which the MAC address moved.
Last Move-Time The time the last move occurred. The system uptime is used if there is no time server configured.
Vlan-id The VLAN for the port where the MAC address movement was detected.
Examples

The following example displays the notification interval history.

device# show notification mac-movement interval-history
Interval-History Mac Movement Notification is ENABLED
Configured Interval : 30 seconds
Number of macs that moved in the interval : 100
Total number of moves in the interval : 98654
MAC-Address       from-Port   to-Port   Interval Move-Count   Last Move-Time   Vlan-id
--------------    ---------   -------   -------------------   --------------   -------

0000.0000.0052    1/7/1      1/7/2        1000                 May 15 01:13:20   10
0000.0000.0051    1/7/1      1/7/2        1002                 May 15 01:13:20   10
0000.0000.0050    1/7/1      1/7/2        1012                 May 15 01:13:20   10
0000.0000.004f    1/7/1      1/7/2        1018                 May 15 01:13:20   10
0000.0000.004e    1/7/1      1/7/2        1012                 May 15 01:13:20   10
(output truncated)

The following examples displays the notification for a threshold rate.

device# show notification mac-movement threshold-rate
Threshold-Rate Mac Movement Notification is ENABLED
Configured Threshold-Rate : 5 moves
Configured Sampling-Interval : 30 seconds
Number of entries in the notification table : 100
MAC-Address       from-Port    to-Port    Last Move-Time   Vlan-id
--------------    ---------    -------    --------------   -------
0000.0000.0022    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.0021    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.0020    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.001f    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.0024    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.001e    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.0023    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.001d    1/7/1        1/7/2        Apr 29 18:29:35  10
0000.0000.001c    1/7/1        1/7/2        Apr 29 18:29:35 10
(output truncated)