6 years ago

SDT EventSources

It would be nice from time to time to be able to SDT EventSources. We use Syslog and once in awhile it would be nice to be able to "ignore" all Syslog events from a specific device.

  • It is possible to add one, but it doesn't actually work. The SDT is applied, but the events keep coming in and generating alerts.

  • The events will still be collected as an SDT does not stop alerting, but the SDT should cancel your escalations.

  • It doesn't, we broke the email relay server you use once already when a Tech tried due to a Cisco UC server freaking out and sending thousands.

  • Have you tried enabling rate-limiting?  At least until it all gets sorted out - I'd consider setting up a duplicate escalation chain and an alert rule specifically for some of your syslog eventsources and enable rate-limiting on them.  Before my LogicMonitor days, I had this happen a few times and it sucks dealing with a crippled Exchange server while also trying to work out a firewall issue.  Syslog is unpredictable sometimes.