SlideShare a Scribd company logo
SolarWinds® Level 2 Training
                                                                        Advanced Alert Manager
                                                                               August 23, 2012




COPYRIGHT © 2012, SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
                                                                    1
Advanced Alert Manager

» Hosts
   Jason Ferree –Support Supervisor
   Mark Wiggans – Information Development




                      Are you Certified?




                                     2
Agenda

   Introductions & Housekeeping
   A Look Under the Hood
   Condition Groups
   Suppression
   Service Groups
   Alert Actions and Variables
   Troubleshooting
   Q&A


                                   © iStockphoto




                               3
Introductions and Housekeeping

» Today’s Content will Focus on Orion® Advanced Alert
  Manager and Dependencies
    We only have an hour
» Ask questions!
    Don’t be afraid to ask deeper questions
    Don’t wait until the end – ask away
» Today’s session is being recorded
    Recorded session on SolarWinds.com
    Slides available on slideshare.com




                                    4
Advanced Alert Manager

» How Alerts Work – A Look Under the Hood.




                            5
Advanced Alert Manager

» Launching the Alert Manager Interface - Quick Tour




                              6
Advanced Alert Manager

» Understanding Condition Groups
    All = logical AND
    Any = logical OR
    Not all and None - Use very carefully
» Embedded condition groups
    Follow the left alignment for embedded conditions




                                    7
Advanced Alert Manager

» Suppression - Example 1, Direct Suppression
      Alert condition: Node down
      Suppression condition: node name = Lab router
      Desired Result – Alert on all devices down except Lab router
      Actual Result - if a node exists in SQL database with the name “Lab
       router”, then all node down alerts will be suppressed.



       If a suppression condition is true, alerts will be suppressed regardless of
       the trigger condition.




                                          8
Advanced Alert Manager

» Suppression - Example 2, Embedded Suppression
    Alert condition: Simple Condition Group
       • Trigger alert when all if the following apply
            • Node status is equal to down
            • Node name is not equal to Lab router
    Suppression condition: None
    Desired Result – Alert on all devices down except Lab router
    Actual Result - Alert on all devices down except Lab router



      To embed a suppression condition, flip the logic and add the condition to
     the trigger.




                                          9
Advanced Alert Manager

» Suppression - Example 3, “Suppression” using Groups and
  Dependencies




                             10
Advanced Alert Manager

» Example 3 Explained – “Suppression” Using Groups and
  Dependencies
      Create a service group and add site 1 remote devices
      Create a service group for the data center routers
      Create a dependency - site 1 group dependent on data center group
      Set datacenter status rollup to mixed
      Create an alert for data center group
        • Trigger - Group status is equal to down
        • Default reset – Condition no longer exists
        • No suppression




                                         11
Advanced Alert Manager

» Example 3 in Action
    Alert for data center group when both routers are down
        • Site 1 devices status set to unreachable
    Existing node down alert fires for parent device down



   Alert!


                                                             Status set to
                                                             unreachable




                                         12
Advanced Alert Manager

» Alert Actions
    Send an email
        • Trouble ticket integration point!
      Send a message via syslog or trap
      Execute a program or script
      Send Windows® Net message
      Tons more


» Variables
    What triggered the alert, when, what was affected, status….




                                         13
Advanced Alert Manager

» Troubleshooting Alerts
   Issue will most likely be in one of three areas
      1 - Alert or Suppression Condition
              Errors in condition logic
              Logical contradictions
              Other conditions not logically possible
              Suppression killing all triggers
   2 - Alert Action
              Error in external program or script
              Email issues
   3 - Alert is OK but test is invalid
              Check test logic, timing, and alert criteria



                                        14
Advanced Alert Manager

» Other Alert Types
    Basic Alerts
       • Most all functionality exists in Advanced Alerts
    Syslog Alerts
       • Defined in Syslog Alerts/Rules UI
    Trap Alerts
       • Defined in Trap Alerts/Rules UI
       • Allows for filtering, parsing, thresholds and alert actions




                                         15
Summary and Q&A

 » Thank you for attending!
 » Additional Resources
         Understanding Orion Advanced Alert Manager
               • http://www.solarwinds.com/documentation/Orion/docs/UnderstandingOrionAdvancedAlerts.pdf
         Using Orion Groups and Dependencies
               • http://www.solarwinds.com/documentation/Orion/docs/Groupsanddependencies.pdf
         Thwack® Alert Lab
               • http://thwack.solarwinds.com/community/labs_tht/alert-lab




COPYRIGHT © 2012, SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.

                                                                    16

More Related Content

PPTX
thwackCamp 2013: Cut the Alert Noise: Best Practices to Avoid Common Pitfalls...
PPTX
How to Eliminate the #1 Cause of Network Down-time
PPT
資安控管實務技術
PDF
Outpost24 webinar - Differentiating vulnerabilities from risks to reduce time...
PDF
TECHNICAL BRIEF: Using Symantec Endpoint Protection 12.1 to Protect Against A...
PDF
Vulnerability Management Program
PDF
VoIP Troubleshooting and Monitoring with SIP3
PDF
Implementing Vulnerability Management
thwackCamp 2013: Cut the Alert Noise: Best Practices to Avoid Common Pitfalls...
How to Eliminate the #1 Cause of Network Down-time
資安控管實務技術
Outpost24 webinar - Differentiating vulnerabilities from risks to reduce time...
TECHNICAL BRIEF: Using Symantec Endpoint Protection 12.1 to Protect Against A...
Vulnerability Management Program
VoIP Troubleshooting and Monitoring with SIP3
Implementing Vulnerability Management

Viewers also liked (7)

PPTX
Survey: IT is Everywhere (End Users’ Perspective, Hong Kong)
PPTX
Federal Webinar: Security Compliance with SolarWinds Network Management Tools
PPTX
Survey: IT is Everywhere (End Users’ Perspective, Brazil)
PPTX
SolarWinds Federal Webinar: Technical Update & New Feature Demo November 2016
PPTX
SolarWinds User Group - Hawaii November 2016
DOCX
Pang ugnay
PPTX
Leveraging SolarWinds to Consolidate IT Operations and Management at NHS
Survey: IT is Everywhere (End Users’ Perspective, Hong Kong)
Federal Webinar: Security Compliance with SolarWinds Network Management Tools
Survey: IT is Everywhere (End Users’ Perspective, Brazil)
SolarWinds Federal Webinar: Technical Update & New Feature Demo November 2016
SolarWinds User Group - Hawaii November 2016
Pang ugnay
Leveraging SolarWinds to Consolidate IT Operations and Management at NHS
Ad

Similar to Customer Level 2 Training: Service Groups, Alerts and Dependencies (20)

PPTX
incident analysis - procedure and approach
PPTX
Fault management presentation
PPTX
Why Workstation Log Management is Crucial for Network Security?
KEY
Drop, Stop & Roll
PDF
Cloud malfunction up11
PDF
Nagios Conference 2012 - Alex Solomon - Managing Your Heros
PPTX
Top 10 Things Logs Can Do for You, Today
PPT
Fault detection consequence
PPTX
IT Alert Management Survey Results - February 2013
PPTX
SolarWinds® Getting Started With NPM and SAM
PPTX
Testing Safety Critical Systems (10-02-2014, VU amsterdam)
PPTX
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
PPTX
Soft serve devops
PPTX
Java Insecurity: How to Deal with the Constant Vulnerabilities
PDF
SVCC-2014
PPTX
2015 05-07 - vu amsterdam - testing safety critical systems
PPTX
Vulnerability management today and tomorrow
PDF
IE Exploit Protection
PDF
ZooKeeper-Group-Membership-and-Creating-Groups.pdf
PDF
[PH-Neutral 0x7db] Exploit Next Generation®
incident analysis - procedure and approach
Fault management presentation
Why Workstation Log Management is Crucial for Network Security?
Drop, Stop & Roll
Cloud malfunction up11
Nagios Conference 2012 - Alex Solomon - Managing Your Heros
Top 10 Things Logs Can Do for You, Today
Fault detection consequence
IT Alert Management Survey Results - February 2013
SolarWinds® Getting Started With NPM and SAM
Testing Safety Critical Systems (10-02-2014, VU amsterdam)
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Soft serve devops
Java Insecurity: How to Deal with the Constant Vulnerabilities
SVCC-2014
2015 05-07 - vu amsterdam - testing safety critical systems
Vulnerability management today and tomorrow
IE Exploit Protection
ZooKeeper-Group-Membership-and-Creating-Groups.pdf
[PH-Neutral 0x7db] Exploit Next Generation®
Ad

More from SolarWinds (20)

PPTX
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
PPTX
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
PPTX
Government Webinar: Alerting and Reporting in the Age of Observability
PPTX
Government and Education Webinar: Full Stack Observability
PPTX
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
PPTX
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
PPTX
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
PPTX
Government and Education Webinar: Simplify Your Database Performance Manageme...
PPTX
Government and Education Webinar: Leverage Automation to Improve IT Operations
PPTX
Government and Education Webinar: Improving Application Performance
PPTX
Government and Education: IT Tools to Support Your Hybrid Workforce
PPTX
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
PPTX
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
PPTX
Government and Education Webinar: Zero-Trust Panel Discussion
PPTX
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
PPTX
Government and Education Webinar: SQL Server—Advanced Performance Tuning
PPTX
Government and Education Webinar: Recovering IP Addresses on Your Network
PPTX
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
PPTX
Government and Education Webinar: Conquering Remote Work IT Challenges
PPTX
Government and Education Webinar: SQL Server—Indexing for Performance
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
Government Webinar: Alerting and Reporting in the Age of Observability
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Improving Application Performance
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: SQL Server—Indexing for Performance

Recently uploaded (20)

PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
MYSQL Presentation for SQL database connectivity
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Machine learning based COVID-19 study performance prediction
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Diabetes mellitus diagnosis method based random forest with bat algorithm
MYSQL Presentation for SQL database connectivity
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Review of recent advances in non-invasive hemoglobin estimation
Advanced methodologies resolving dimensionality complications for autism neur...
Building Integrated photovoltaic BIPV_UPV.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Reach Out and Touch Someone: Haptics and Empathic Computing
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
The Rise and Fall of 3GPP – Time for a Sabbatical?
Dropbox Q2 2025 Financial Results & Investor Presentation
The AUB Centre for AI in Media Proposal.docx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Big Data Technologies - Introduction.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Per capita expenditure prediction using model stacking based on satellite ima...
Machine learning based COVID-19 study performance prediction

Customer Level 2 Training: Service Groups, Alerts and Dependencies

  • 1. SolarWinds® Level 2 Training Advanced Alert Manager August 23, 2012 COPYRIGHT © 2012, SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. 1
  • 2. Advanced Alert Manager » Hosts  Jason Ferree –Support Supervisor  Mark Wiggans – Information Development Are you Certified? 2
  • 3. Agenda  Introductions & Housekeeping  A Look Under the Hood  Condition Groups  Suppression  Service Groups  Alert Actions and Variables  Troubleshooting  Q&A © iStockphoto 3
  • 4. Introductions and Housekeeping » Today’s Content will Focus on Orion® Advanced Alert Manager and Dependencies  We only have an hour » Ask questions!  Don’t be afraid to ask deeper questions  Don’t wait until the end – ask away » Today’s session is being recorded  Recorded session on SolarWinds.com  Slides available on slideshare.com 4
  • 5. Advanced Alert Manager » How Alerts Work – A Look Under the Hood. 5
  • 6. Advanced Alert Manager » Launching the Alert Manager Interface - Quick Tour 6
  • 7. Advanced Alert Manager » Understanding Condition Groups  All = logical AND  Any = logical OR  Not all and None - Use very carefully » Embedded condition groups  Follow the left alignment for embedded conditions 7
  • 8. Advanced Alert Manager » Suppression - Example 1, Direct Suppression  Alert condition: Node down  Suppression condition: node name = Lab router  Desired Result – Alert on all devices down except Lab router  Actual Result - if a node exists in SQL database with the name “Lab router”, then all node down alerts will be suppressed. If a suppression condition is true, alerts will be suppressed regardless of the trigger condition. 8
  • 9. Advanced Alert Manager » Suppression - Example 2, Embedded Suppression  Alert condition: Simple Condition Group • Trigger alert when all if the following apply • Node status is equal to down • Node name is not equal to Lab router  Suppression condition: None  Desired Result – Alert on all devices down except Lab router  Actual Result - Alert on all devices down except Lab router To embed a suppression condition, flip the logic and add the condition to the trigger. 9
  • 10. Advanced Alert Manager » Suppression - Example 3, “Suppression” using Groups and Dependencies 10
  • 11. Advanced Alert Manager » Example 3 Explained – “Suppression” Using Groups and Dependencies  Create a service group and add site 1 remote devices  Create a service group for the data center routers  Create a dependency - site 1 group dependent on data center group  Set datacenter status rollup to mixed  Create an alert for data center group • Trigger - Group status is equal to down • Default reset – Condition no longer exists • No suppression 11
  • 12. Advanced Alert Manager » Example 3 in Action  Alert for data center group when both routers are down • Site 1 devices status set to unreachable  Existing node down alert fires for parent device down Alert! Status set to unreachable 12
  • 13. Advanced Alert Manager » Alert Actions  Send an email • Trouble ticket integration point!  Send a message via syslog or trap  Execute a program or script  Send Windows® Net message  Tons more » Variables  What triggered the alert, when, what was affected, status…. 13
  • 14. Advanced Alert Manager » Troubleshooting Alerts Issue will most likely be in one of three areas 1 - Alert or Suppression Condition Errors in condition logic Logical contradictions Other conditions not logically possible Suppression killing all triggers 2 - Alert Action Error in external program or script Email issues 3 - Alert is OK but test is invalid Check test logic, timing, and alert criteria 14
  • 15. Advanced Alert Manager » Other Alert Types  Basic Alerts • Most all functionality exists in Advanced Alerts  Syslog Alerts • Defined in Syslog Alerts/Rules UI  Trap Alerts • Defined in Trap Alerts/Rules UI • Allows for filtering, parsing, thresholds and alert actions 15
  • 16. Summary and Q&A » Thank you for attending! » Additional Resources  Understanding Orion Advanced Alert Manager • http://www.solarwinds.com/documentation/Orion/docs/UnderstandingOrionAdvancedAlerts.pdf  Using Orion Groups and Dependencies • http://www.solarwinds.com/documentation/Orion/docs/Groupsanddependencies.pdf  Thwack® Alert Lab • http://thwack.solarwinds.com/community/labs_tht/alert-lab COPYRIGHT © 2012, SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. 16