Alerts Syslog Format
...
Time | Host | Alerts Syslog Message ID | Level | Alert Name | Alert Description | On (Alert Device/ Object) | Alert Details |
---|---|---|---|---|---|---|---|
10/23/2018 15:40:43.714 | dpod | 0x00a0001a | info | Devices CPU Metric | Alert on Devices CPU over 80% | idg77 | Value:(85.0) Threshold:(75.0) Filters:[device(),domain(),service()] Interval:[timestampStart(10/23/2018 15:35:43.714),timestampStartLong(1540298143714),timestampEnd(10/23/2018 15:40:43.714),timestampEndLong(1540298443714)] |
- Alert Type: Frequency, match if the number of fetched documents is more than threshold X
<16>Oct 23 17:44:23 dpod [0x00a0001a][DPOD-alert][info] AlertName:(Transaction Errors Alert) AlertDesc:(Alert when 5 or more Transactions with errors in the last 30 minutes) on:(mpgw - webapi) Value:(22.0) Threshold:(5.0) Filters:[device(idg77),domain(),service()] Interval:[timestampStart(10/22/2018 17:44:23.088),timestampStartLong(1540219463088),timestampEnd(10/23/2018 17:44:23.088),timestampEndLong(1540305863088)]
...
- Alert Type: Any, match if any record was fetched
- Alert Type: List, match if a certain field of the fetched records matches a blacklist/whitelist
The message ID for all alerts will always be 0x00a0001a
The message level (info, warn, error, etc) may be set via the system parameters (under "Syslog Severity Field Value")