Joe Williams

SDT EventSources

Recommended Posts

It would be nice from time to time to be able to SDT EventSources. We use Syslog and once in awhile it would be nice to be able to "ignore" all Syslog events from a specific device.

Share this post


Link to post
Share on other sites

The events will still be collected as an SDT does not stop alerting, but the SDT should cancel your escalations.

Share this post


Link to post
Share on other sites

Have you tried enabling rate-limiting?  At least until it all gets sorted out - I'd consider setting up a duplicate escalation chain and an alert rule specifically for some of your syslog eventsources and enable rate-limiting on them.  Before my LogicMonitor days, I had this happen a few times and it sucks dealing with a crippled Exchange server while also trying to work out a firewall issue.  Syslog is unpredictable sometimes.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now