Forum Discussion
2 hours ago, mnagel said:I think the only reasonable solution is to redo the code into a datasource, like originally discussed in this thread.
Agreed, a DataSource would fix the multiple alerts that results from an EventSource running.
Although i think the larger question of alert correlation (multiple alerts being statically or dynamically grouped into incidents) is something you should be requesting from your CSM. Even something like occurrence counts on alerts would be good. The same problem happens with SNMP traps; traps can come in every minute and be about the same thing still in an unwanted state. Each one should just increment a counter on the alert. Counter thresholds should be something we can add to alert rules. Even regular datapoints could benefit from this, counting the number of poll cycles/minutes that a particular metric has been over threshold.
Related Content
- 2 years ago