show rmon

Displays the Remote monitoring (RMON) agent status and information about RMON alarms, events, history, logs, and statistics on the interface.
Syntax
show rmon { alarm alarm-number | event event-number | history history-index | logs event-index | statistics [ number | interface-type | interface-number ] }
Parameters
alarm
Specifies to display the RMON alarm table.
alarm-number
Specifies the alarm index identification number. Valid values range from 1 through 65535.
event
Specifies to display the RMON event table.
event-number
Specifies the event index identification number. Valid values range from 1 through 65535.
history
Specifies to display the history control data entries for port or interface.
history-number
Specifies the history index identification number of the history entry.
logs
Specifies to display the RMON logging table where RMON log entries are stored.
event-index
Specifies the event index identification number. Valid values range from 1 through 65535.
statistics
Specifies to display the RMON Ethernet statistics; and the statistics group that collects statistics on promiscuous traffic across an interface and total traffic into and out of the agent interface. Valid values range from 1 through 65535.
statistics-number
Specifies the statistics index identification number of the statistics entry.
interface-type
Specifies the ethernet interface or management port.
interface-number
Specifies the interface or management port number.
Modes

Privileged EXEC mode

Global configuration mode

The show rmon command displays the following information:

Output field Description
Rising threshold The sampling value limit, beyond which the rising alarm is triggered.
Falling threshold The sampling value limit, beyond which the falling alarm is triggered.
Octets The total number of octets of data received on the network. This number includes octets in bad packets. This number does not include framing bits but does include Frame Check Sequence (FCS) octets.
Drop events Indicates an overrun at the port. The port logic could not receive the traffic at full line rate and had to drop some packets as a result. The counter indicates the total number of events in which packets were dropped by the RMON probe due to lack of resources. This number is not necessarily the number of packets dropped, but is the number of times an overrun condition has been detected.
Packets The total number of packets received. This number includes bad packets, broadcast packets, and multicast packets.
Broadcast pkts The total number of good packets received that were directed to the broadcast address. This number does not include multicast packets.
Multicast pkts The total number of good packets received that were directed to a multicast address. This number does not include packets directed to the broadcast address.
CRC align errors The total number of packets received that were from 64 - 1518 octets long, but had either a bad FCS with an integral number of octets (FCS Error) or a bad FCS with a non-integral number of octets (Alignment Error). The packet length does not include framing bits but does include FCS octets.
Undersize pkts The total number of packets received that were less than 64 octets long and were otherwise well formed. This number does not include framing bits but does include FCS octets.
Fragments The total number of packets received that were less than 64 octets long and had either a bad FCS with an integral number of octets (FCS Error) or a bad FCS with a non-integral number of octets (Alignment Error). It is normal for this counter to increment, since it counts both runts (which are normal occurrences due to collisions) and noise hits. This number does not include framing bits but does include FCS octets.
Oversize packets The total number of packets received that were longer than 1518 octets and were otherwise well formed. This number does not include framing bits but does include FCS octets.
Note: 48GC modules do not support count information on oversized packets and report 0.
Jabbers The total number of packets received that were longer than 1518 octets and had either a bad FCS with an integral number of octets (FCS Error) or a bad FCS with a non-integral number of octets (Alignment Error).
Note: This definition of jabber is different from the definition in IEEE-802.3 section 8.2.1.5 (10BASE5) and section 10.3.1.4 (10BASE2). These documents define jabber as the condition where any packet exceeds 20 ms. The allowed range to detect jabber is between 20 ms and 150 ms.
This number does not include framing bits but does include FCS octets.
Note: 48GC modules do not support count information on jabbers and report 0.
Collisions The best estimate of the total number of collisions on this Ethernet segment.
64 octets pkts The total number of packets received that were 64 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
65 to 127 octets pkts The total number of packets received that were 65 - 127 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
128 to 255 octets pkts The total number of packets received that were 128 - 255 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
256 to 511 octets pkts The total number of packets received that were 256 - 511 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
512 to 1023 octets pkts The total number of packets received that were 512 - 1023 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
1024 to 1518 octets pkts The total number of packets received that were 1024 - 1518 octets long. This number includes bad packets. This number does not include framing bits but does include FCS octets.
Event Index The event index identification number.
Log Index The log index identification number.
Log Generated time The time at which the log is generated.
Log Description Indicates the type of alarm; whether it is a rising or falling alarm.
Examples

The following example shows the output of the show rmon alarm command.

device(config)# show rmon alarm 
Alarm 1 is active, owned by monitor
 Monitors etherStatsPkts.13 every 5 seconds
 Taking absolute samples, last value was 675
 Rising threshold is 100, assigned to event 1
 Falling threshold is 0, assigned to event 1
 On startup enable rising or falling alarm

Alarm 2 is active, owned by monitor
 Monitors etherStatsPkts.2 every 5 seconds
 Taking absolute samples, last value was 414
 Rising threshold is 100, assigned to event 3
 Falling threshold is 0, assigned to event 3
 On startup enable rising or falling alarm

The following example shows the output of the show rmon event command.

device(config)# show rmon event 
Event 1 is active, owned by monitor
 Description is testing
 Event firing causes log, community 
 Batch ID 0, argument <none>
 Last fired at system up time 3 minutes 52 seconds 

Event 2 is active, owned by monitor
 Description is logging
 Event firing causes log and trap, community public
 Batch ID 0, argument <none>
 Last fired at system up time 8 minutes 12 seconds 

The following example shows the output of the show rmon history history-index command.

device(config)# show rmon history 1
History 1 is active, owned by monitor
 Monitors interface mgmt1 (ifIndex 25) every 30 seconds
 25 buckets were granted to store statistics

The following example shows the output of the show rmon logs command.

device(config)# show rmon logs
 Event Index = 1
	 Log Index = 1
	 Log Generated time = 00:03:52 (23200)
	 Log Description  = rising alarm 

 Event Index = 2
	 Log Index = 1
	 Log Generated time = 00:08:12 (49200)
	 Log Description  = rising alarm 

 Event Index = 3
	 Log Index = 1
	 Log Generated time = 00:05:12 (31200)
	 Log Description  = rising alarm 

 Event Index = 4
	 Log Index = 1
	 Log Generated time = 00:01:32 (9200)
	 Log Description  = falling alarm 

	 Log Index = 2
	 Log Generated time = 00:02:52 (17200)
	 Log Description  = rising alarm  

The following example shows the output of the show rmon logs event-index command.

device(config)# show rmon logs 2
Event Index = 2
	 Log Index = 1
	 Log Generated time = 00:08:12 (49200)
	 Log Description  = rising alarm 
  

The following example shows the output of the show rmon statistics number command.

device(config)# show rmon statistics 1
Ethernet statistics 1 is active, owned by monitor
 Interface 1/1/1 (ifIndex 1) counters
           Octets                    0
      Drop events                    0             Packets                    0
   Broadcast pkts                    0      Multicast pkts                    0
 CRC align errors                    0      Undersize pkts                    0
    Oversize pkts                    0           Fragments                    0
          Jabbers                    0          Collisions                    0

 Packet size counters
               64                    0           65 to 127                    0
       128 to 255                    0          256 to 511                    0
      512 to 1023                    0        1024 to 1518                    0

The following example shows the statistics of the ethernet interface 1/2/1.

device(config)# show rmon statistics ethernet 1/2/1
Ethernet statistics 65 is active, owned by monitor
 Interface 1/2/1 (ifIndex 65) counters
           Octets          30170677670
      Drop events                    0             Packets             72281139
   Broadcast pkts                    0      Multicast pkts             66309417
 CRC align errors                    0      Undersize pkts                    0
    Oversize pkts                    0           Fragments                    0
          Jabbers                    0          Collisions                    0

 Packet size counters
               64                    0           65 to 127             10703415
       128 to 255             19353559          256 to 511             18658554
      512 to 1023             17980963        1024 to 1518              5584648
History
Release version Command history
08.0.20 The logs keyword was introduced.