Forum Discussion

Justin_Lanoue's avatar
5 months ago

LM Logs - Alerting

Hello,

Just wanted to ask if there is a way to have alerting on multiple lets say IP addresses in a similar log message but not have it spam our ticketing system?

Log Message 1 - 1.1.1.1 is down

Log Message 2 - 2.2.2.2 is down

Log Message 3 - 1.1.1.1 is down 

I want to be able to alert on 1.1.1.1 being down and suppress it for a day on duplicate alerts but if I have a alert query for "is down" then 2.2.2.2 will also get suppressed for a whole day as well when its a whole separate device/alert.

I would also not be able to add all lets say 50 IP addresses that may alert as their own alert condition.

Is there a way or is LM Log too limiting right now?

  • Anonymous's avatar
    Anonymous

    I can't think of a way to do this. Without defining all 50 IP addresses up front, you couldn't setup different pipelines nor different pipeline alerts. That means they'd all alert together and the difference in IP addresses wouldn't be detected by LM aside from noticing that it matches the pattern of actually having an IP address.