Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Syslog Format for Flatline alerts (match if a statistical value is less/more/equals to threshold X)

...

Paste code macro
languagejava
<16>Oct 23 15:40:43 dpod [0x00a0001a][DPOD-alert][info] AlertName:(Devices CPU Metric) AlertDesc:(Alert on Devices CPU over 80%) on:(idg77) Value:(85.0) Threshold:(75.0) Filters:[device(),domain(),service()] Interval:[timestampStart(10/23/2018 15:35:43.714),timestampStartLong(1540298143714),timestampEnd(10/23/2018 15:40:43.714),timestampEndLong(1540298443714)]


TimeDPOD server hostnameAlerts Syslog Message IDLevelAlert NameAlert DescriptionOn (Alert Device/ Object)Alert Details

10/23/2018 15:40:43.714


dpod

0x00a0001a
(always the same)

info
May be set via System Parameters ("Syslog Severity Field Value")
Devices CPU MetricAlert on Devices CPU over 80%idg77Value:(85.0) Threshold:(75.0) Filters:[device(),domain(),service()] Interval:[timestampStart(10/23/2018 15:35:43.714),timestampStartLong(1540298143714),timestampEnd(10/23/2018 15:40:43.714),timestampEndLong(1540298443714)]

Syslog Format for Frequency alerts (match if the number of fetched documents is more than threshold X)

...

Paste code macro
languagejava
<16>Oct 23 17:44:23 dpod [0x00a0001a][DPOD-alert][info] AlertName:(Transaction Errors Alert) AlertDesc:(Alert when 5 or more Transactions with errors in the last 30 minutes) on:(mpgw - webapi) Value:(22.0) Threshold:(5.0) Filters:[device(idg77),domain(),service()] Interval:[timestampStart(10/22/2018 17:44:23.088),timestampStartLong(1540219463088),timestampEnd(10/23/2018 17:44:23.088),timestampEndLong(1540305863088)]


TimeDPOD server hostnameAlerts Syslog Message IDLevelAlert NameAlert DescriptionOn (Alert Device/ Object)Alert Details
10/23/2018 17:44:23.088dpod0x00a0001a
(always the same)
info
May be set via System Parameters ("Syslog Severity Field Value")
Transaction Errors AlertAlert when 5 or more Transactions with errors in the last 30 minutesmpgw - webapiValue:(22.0) Threshold:(5.0) Filters:[device(idg77),domain(),service()] Interval:[timestampStart(10/22/2018 17:44:23.088),timestampStartLong(1540219463088),timestampEnd(10/23/2018 17:44:23.088),timestampEndLong(1540305863088)]

...

Paste code macro
languagejava
<16>Oct 24 08:30:23 dpod[0x00a0001a][DPOD-alert][info] AlertName:(Objects Down Alert) AlertDesc:(Alert on any DP object that is enabled but down) on:([Domain is down, LogTarget, idg77, HospitalA_Domain]) Value:(null) Threshold:(null) Filters:[device(),domain(),service()] Interval:[timestampStart(10/24/2018 08:25:23.531),timestampStartLong(1540358723531),timestampEnd(10/24/2018 08:30:23.531),timestampEndLong(1540359023531)]


TimeDPOD server hostnameAlerts Syslog Message IDLevelAlert NameAlert DescriptionOn (Alert Object Down)Alert Details
10/24/2018 08:30:23.531dpod0x00a0001a
(always the same)
info
May be set via System Parameters ("Syslog Severity Field Value")
Objects Down AlertAlert on any DP object that is enabled but down[Domain is down, LogTarget, idg77, HospitalA_Domain]

Value:(null) Threshold:(null) Filters:[device(),domain(),service()] Interval:[timestampStart(10/24/2018 08:25:23.531),timestampStartLong(1540358723531),timestampEnd(10/24/2018 08:30:23.531),timestampEndLong(1540359023531)]



...

Paste code macro
languagejava
<16>Oct 24 08:47:23 dpod[0x00a0001a][DPOD-alert][info] AlertName:(Syslog Errors MessageCode Alert) AlertDesc:(Alert on any syslog errors with specific message codes) on:([An error occurred on socket (260). Error details (113: No route to host). Local(172.17.100.200:58056) - Remote(n/a), 11, 31562, 297, 1540359962073, 1, 526, idg77, 3, 02, 2018, 176f0f31-d750-11e8-b42e-000c299db48d, 073827, 7, 1540359962073827, error, wdp-syslog-sys-error_active-node_N001, 2018-10-24T08:46:02.073827+03:00, 172.17.100.156, APIMgmt_B72F7777F4, 10, false, 08:46:02, MonTier-SyslogAgent-1, 08, 46, <11>2018-10-24T08:46:02.073827+03:00 MonTierLocalId-3 [0x80e006ba][network][error] trans(54159): An error occurred on socket (260). Error details (113: No route to host). Local(172.17.100.200:58056) - Remote(n/a), 24, 1540359963013, 54159, 1540359963013, 7.5.2.4+, 0x80e006ba, +03:00, network, 60000]) Value:(null) Threshold:(null) Filters:[device(),domain(),service()] Interval:[timestampStart(10/24/2018 08:42:23.538),timestampStartLong(1540359743538),timestampEnd(10/24/2018 08:47:23.538),timestampEndLong(1540360043538)]




TimeDPOD server hostnameAlerts Syslog Message IDLevelAlert NameAlert DescriptionOn (Syslog Errors)Alert Details
10/24/2018 08:30:23.531dpod0x00a0001a
(always the same)
info
May be set via System Parameters ("Syslog Severity Field Value")
Syslog Errors MessageCode AlertAlert on any syslog errors with specific message codes[An error occurred on socket (260). Error details (113: No route to host). Local(172.17.100.200:58056) - Remote(n/a), 11, 31562, 297, 1540359962073, 1, 526, idg77, 3, 02, 2018, 176f0f31-d750-11e8-b42e-000c299db48d, 073827, 7, 1540359962073827, error, wdp-syslog-sys-error_active-node_N001, 2018-10-24T08:46:02.073827+03:00, 172.17.100.156, APIMgmt_B72F7777F4, 10, false, 08:46:02, MonTier-SyslogAgent-1, 08, 46, <11>2018-10-24T08:46:02.073827+03:00 MonTierLocalId-3 [0x80e006ba][network][error] trans(54159): An error occurred on socket (260). Error details (113: No route to host). Local(172.17.100.200:58056) - Remote(n/a), 24, 1540359963013, 54159, 1540359963013, 7.5.2.4+, 0x80e006ba, +03:00, network, 60000]Value:(null) Threshold:(null) Filters:[device(),domain(),service()] Interval:[timestampStart(10/24/2018 08:42:23.538),timestampStartLong(1540359743538),timestampEnd(10/24/2018 08:47:23.538),timestampEndLong(1540360043538)