A device may appear offline in Auvik even though it is powered on and functioning normally. Auvik determines device availability from the monitored device IP and health checks performed by the Auvik collector. If the collector cannot reach the device, Auvik may mark it offline and trigger a Device Offline or Network Element Offline alert.
This can occur when the device responds from another location, such as your workstation or a controller portal, but does not respond from the collector’s network path.
Test reachability from the collector
Test the device from the collector’s network path rather than relying only on a ping from your workstation.
If you have access to the collector host or its diagnostic shell, run the following commands.
Windows collector:
ping -n 20 <device_ip>
tracert <device_ip>Linux-based collector:
ping -c 20 <device_ip>
traceroute <device_ip>If the device responds from your workstation but not from the collector, compare the two network paths. The difference may be caused by VLAN placement, routing, firewall rules, ACLs, NAT, or security policies that apply only to the collector’s source IP.
For information about accessing the collector diagnostic shell, see Diagnose issues using discovery scanning with the Auvik collector?
Verify the monitored IP address
Open the device details in Auvik and confirm that the monitored or primary IP address is the device’s current management IP.
Check for:
- A recent DHCP address change.
- An outdated IP address in Auvik.
- Duplicate IP addresses.
- A management interface that is no longer active.
- A device replacement or network migration.
If the monitored IP is incorrect, correct the underlying addressing issue and update the device information in Auvik as appropriate.
Review the network path
The collector must have a stable route to the device’s management interface.
Ask your network administrator to confirm that:
- The collector can reach the device’s management VLAN or subnet.
- ICMP Echo traffic is permitted between the collector and device.
- Routing and return routing are correct.
- NAT is not changing the source address in a way that causes the device to ignore the collector.
- No firewall or ACL rule is intermittently blocking the collector.
- No ICMP rate limit or control-plane policy is dropping health-check traffic.
A device that is reachable from a workstation but not from the collector can correctly appear offline in Auvik because Auvik evaluates reachability from the collector’s path.
Check for intermittent connectivity
Review the device and collector during the time of the alert.
Check for:
- Interface errors or link flaps.
- Collector host network interruptions.
- Device CPU or memory spikes.
- Firewall or ACL changes.
- Routing or VLAN changes.
- Duplicate IP addresses.
- Device logs showing dropped or rate-limited ICMP traffic.
If the collector host itself is unstable, review its network connection and operating-system health.
For more information, see Troubleshooting the Auvik Collector
Tune the offline alert
If the device is reachable but experiences brief, expected interruptions, review the applicable alert or health-check settings.
Depending on the alerting workflow, you may be able to:
- Increase the number of failures required before the device is considered offline.
- Increase the alert trigger delay.
- Apply the change only to the affected devices or sites.
- Use a maintenance window during planned network changes.
Auvik health checks use consecutive failures when determining whether a device is offline. A short interruption may not produce an alert if the device recovers before the configured failure threshold is reached.
For Alerts v2, see How to set Alert Delays with Alerts v2
Devices that intentionally block ICMP
Some devices intentionally block or rate-limit ICMP. If ICMP cannot be enabled safely:
- Ask the network administrator whether ICMP can be allowed from the collector’s IP address only.
- Exclude the device from the applicable offline alert, if appropriate.
- Monitor the device through a supported controller or management system instead.
- Document the exception so the device is not repeatedly treated as an unexpected outage.
Do not exclude a device from offline monitoring unless its alternative monitoring method is reliable and the operational impact is understood.
Evidence to collect if the issue continues
Collect the following information:
- Device name and monitored IP address.
- Collector assigned to monitor the device.
- Alert name and alert timestamp, including timezone.
- Ping and traceroute results from the collector’s network path.
- Device CPU, memory, and interface statistics.
- Relevant firewall, ACL, routing, or device-log information.
- Any recent IP, VLAN, routing, NAT, or firewall changes.
If the issue persists after reachability and network-path checks, provide this information to Auvik Support.
