Create an event rule to bind alerts to a CI running on a host.
Before you begin
Role required: evt_mgmt_admin
About this task
By default, an incoming event from a CI running on a host can bind to an alert based
on the event Node field value. If the value resides in a different
event field, you can use an event rule transform to copy the data to the
Node field on the alert. The Description
field with a name the same as a field of the selected CI can be used as an identifier. The
Transform and compose screen can be used to add such fields. All the identifier fields must
be matched to bind to the CI. Then the system can locate the CI that matches the
alert.
Procedure
-
Navigate to .
-
Select the server in the configuration item column of the desired alert.
Leave this screen open so that you can copy any necessary values to use in the
binding.
-
Navigate to .
-
Select New and fill in the appropriate fields of the event rule.
-
In the Severity field, enter a Severity value.
-
In the Description field, enter a description that
includes the server name or IP address for enabling the binding to an
appropriate CI.
-
Right-click the top of the form and select Save to save the form.
- Optional:
Right-click the State field and select Ready.
-
Right-click the top of the form and select Insert and Stay to insert the changes and keep the form.
-
Right-click the top of the form and select Reload form to refresh the form.
Repeat the step until the State changes to
Processed. You can view the results in the
Processing Notes field. Binding does not take place, since
at this step you haven't defined any event rules.
-
Select Create Event Rule.
Open this Event Rule Designer in a new tab so that you can easily go back to the
Event screen.
-
In the Event Rule Info, fill in the appropriate fields of the event rule.
-
Select Event Filter to build the condition.
-
In the Event Filter screen, select
Description that contains the
description of the desired condition.
-
In the Event Input table, copy the
Description text and paste it in the condition.
The Event Input table can be used as a reference to
the available event fields and in this case the
Description field.
-
Select Transform and Compose Alert Output.
-
In the Event Input table, select the Description
field.
-
In the Edit Regex Expressions dialog box, mark a
field, such as the IP address, and select Node..
The field becomes a regex expression for the
Node.
-
Select Done.
-
Select Binding to bind the alert to the CI using CI identifiers.
-
Select Override default binding to override the default binding.
The default binding uses the value of the Node field to try
to match the CI name: CI name, FQDN, IP, or MAC address.
-
In the Binding type field, select CI field matching.
-
In the CI type field, select Configuration Item.
-
Select Submit.
The Event Rules screen opens listing the new event
rule.
-
To test the rule.
-
Navigate to .
-
Select the recent event that you created.
You can also go back to the Event in the open tab.
-
In the Node field, type the server name.
-
Select the State field and select Ready
-
In the Message key field, type a new message key.
-
Right-click the top of the form and select Insert and Stay to insert the changes and keep the form.
-
Right-click the top of the form and select Reload form to refresh the form.
Repeat the step until the State changes to Processed. You can view the binding results in the Processing Notes field.