Event Management Fundamentals - Lab 3.4 Unbound Event binding to Application CI instead of Host CI
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday
Hello community,
I am currently stuck on Lab 3.4 (Event Binding with Event Rules and CI Field Matching) because the behavior of my lab instance does not match the Lab Guide instructions for the very first event execution.
What the Lab Guide states (Section A, steps 9-10):When triggering the Lab3.4 UnboundEvent-IIS sample from the Event Generator, the generated alert is supposed to bind to the Host (server) CI (win-ksx74drkgh). The guide explicitly highlights this in step 10 to show an unbound/infrastructure event behavior before we create custom rules.
What actually happens in my instance:As soon as the event is generated, an existing out-of-the-box rule named "IIS Server Lock - Lab 3.4" triggers automatically. The Processing Notes show that it immediately query fields for name: IIS 7.5 and version: 7.5, binding the alert directly to the Application CI (IIS 7.5 / cmdb_ci_microsoft_iis_web_server) instead of the host server.
Because the alert is automatically resolving to the application CI from the start, it ruins the logical progression of the remaining lab exercises where we are supposed to configure this binding behavior ourselves.
Has anyone found a workaround for this version discrepancy?
Thank you for your help!