User's Manual
36-4
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
OL-21521-01
Chapter 36 Configuring Embedded Event Manager
Understanding Embedded Event Manager
  • Syslog event detector—Allows for screening syslog messages for a regular expression pattern 
match. The selected messages can be further qualified, requiring that a specific number of 
occurrences be logged within a specified time. A match on a specified event criteria triggers a 
configured policy action. 
  • Timer event detector—Publishes events for 
 –
An absolute-time-of-day timer publishes an event when a specified absolute date and time 
occurs. 
 –
A countdown timer publishes an event when a timer counts down to zero. 
 –
A watchdog timer publishes an event when a timer counts down to zero. The timer automatically 
resets itself to its initial value and starts to count down again. 
 –
A CRON timer publishes an event by using a UNIX standard CRON specification to define 
when the event is to be published. A CRON timer never publishes events more than once per 
minute. 
  • Watchdog event detector (IOSWDSysMon)—Publishes an event only on the master switch when 
Publishes an event when one of these events occurs: 
 –
CPU utilization for a Cisco IOS process crosses a threshold. 
 –
Memory utilization for a Cisco IOS process crosses a threshold. 
Two events can be monitored at the same time, and the event publishing criteria requires that one or 
both e
vents cross their specified thresholds.
Embedded Event Manager Actions
These actions occur in response to an event:
  • Modifying a named counter. 
  • Publishing an application-specific event. 
  • Generating an SNMP trap. 
  • Generating prioritized syslog messages. 
  • Reloading the Cisco IOS software.
  • Reloading the switch stack.
  • Reloading the master switch in the event of a master switchover. If this occurs, a new master switch 
is elected.
Embedded Event Manager Policies
EEM can monitor events and provide information, or take corrective action when the monitored events 
occur or a threshold is reached. An EEM policy is an entity that defines an event and the actions to be 
taken when that event occurs.
There are two types of EEM policies: an applet or a script. An applet is a simple policy that is defined 
with
in the CLI configuration. It is a concise method for defining event screening criteria and the actions to 
be taken when that event occurs. Scripts are defined on the networking device by using an ASCII editor. 
The script, which can be a bytecode (.tbc) and text (.tcl) script, is then copied to the networking device 
and registered with EEM. You can also register multiple events in a .tcl file.










