Forum Discussion
Hi Mahlon,
We send clears for Syslog events because we treat all events equally (e.g. IPMI, Windows, Syslog, UDP traps, etc.). Our philosophy is to only alert on alertable events, where alertable events usually have an underlying condition that can clear, or be resolved, or expire. However, I understand that Syslog-based events aren't the same as all other events, and that getting cleared messages may not always be desirable. You can actually configure your LogicMonitor Alert Rules to not send cleared alerts for Syslog events - there is an option for all Alert Rules to 'Send notification when alerts clear'. So if you dedicate a rule to routing Syslog events, unchecking this option gives you the flexibility to only have active and acknowledged notifications sent.
Thanks,
Sarah
Related Content
- 4 years agoAnonymous