SlideShare a Scribd company logo
Cut the Alert Noise: Best Practices to Avoid
Common Pitfalls and Optimize Managing IT Alerts
SolarWinds® thwackCamp 2013
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Agenda
» What is Alert Central™ and how does it work?
» Solving common IT alert problems with Alert Central
 Automatic assignment and escalation
 Reassignment, moving alerts between team members/groups quickly
 Integrating on call scheduling with alert management
 Filtering out alerts that don’t need escalation
 Preventing alerts from duplicate systems from being escalated
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
How Alert Central Works
» Deployed as Virtual Appliance
» Alerts from IT systems company-wide are
consolidated in Alert Central (collected via e-mail
or direct integration with SolarWinds Orion family
products)
» Alert Central handles escalation and on-call
scheduling (with configurable policies) to ensure
alerts go to the appropriate person
» That person can then acknowledge and clear the
alert, reassign, or escalate it (via email or in
console)
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Automatic Assignment & Escalation
» Problem: get alerts ONLY to the people who can handle them.
» Problem: if someone’s not available, alerts can get stuck until they are.
» Problem: if everyone’s notified, it takes time to identify whether they care.
» Solution:
 Create groups for each logical staff group in Alert Central.
 Create escalation policies within each group to follow the group’s notification preferences.
 Assign alerts to each group based on information in the alert.
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Moving alerts between team members/groups quickly
» Problem: With a mass email system, it’s easy to lose track of who is responsible or
miss that it’s you that got “assigned” the alert.
» Problem: When alerts need to go to another group, it can be unclear how to do so.
» Problem: Working remotely or from home, having to log in to deal with alerts can be
time consuming.
» Solution:
 Automatic assignment makes sure only one person has the ball.
 Reassign alerts via email or the console
 Reassign alerts to either a specific user or a group, which will use the group’s configured
escalation policy automatically.
 Each user can configure notification policies in Alert Central for their notification preferences.
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Integrating on call scheduling with alert management
» Problem: Maintaining an external on call calendar (on the whiteboard, in a
spreadsheet, in a shared calendar) can be hard to keep accurate
» Problem: Without on call integrated to alerting, either a shared device has to be
used or a person has to be available 24/7 to find the on call person
» Solution:
 Use on call calendars within Alert Central to support rotations, regular schedules
 Integrate on call directly with escalation policies – with fallback options
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Filtering out alerts that don’t need escalation
» Problem: Some alerts don’t need immediate action or are handled by regular
helpdesk/IT staff, but come in through the same email source
» Problem: Realistically, systems sometimes generate noise or invalid alerts, and it’s
faster to tune them out until a fix is made
» Solution:
 Identify criteria for noise alerts based on the email/alert details
 In Alert Central’s source configuration, choose the “Trash this alert” option for that alert criteria
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Preventing alerts from duplicate systems from being escalated
» Problem: Implementing new systems while leaving old systems running generates
some duplicate alerts
» Problem: Overlapping monitoring systems can generate similar alerts, but both
copies don’t need to be delivered
» Problem: In any case, it’s not possible to tune out an entire source, filtering needs to
be more sensitive
» Solution:
 Identify data in the duplicate alert that doesn’t need to be delivered
 Use “Trash this alert” to indicate the duplicate alerts should be skipped
 As more cases come up, continue evolving the policy easily
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Resources
» Alert Central Getting Started Videos
 Configuring Escalation Policies & On Call:
http://www.youtube.com/watch?feature=player_embedded&v=8h7nUEXJ3ws
 Configuring Orion Alert Sources:
http://www.youtube.com/watch?feature=player_embedded&v=BJLK0IqDHII
 Configuring Email Alert sources:
http://www.youtube.com/watch?feature=player_embedded&v=oMxN2oZZM4s
» Alert Central on thwack®
 http://thwack.solarwinds.com/community/tools_tht/alert-central
» Alert Central Resource Library
 Links to FAQs, downloads, and more: http://thwack.solarwinds.com/docs/DOC-170671
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Questions?
© 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
Thank You!
The SOLARWINDS and SOLARWINDS & Design marks are the exclusive property of SolarWinds
Worldwide, LLC, are registered with the U.S. Patent and Trademark Office, and may be registered or
pending registration in other countries. All other SolarWinds trademarks, service marks, and logos
may be common law marks, registered or pending registration in the United States or in other
countries. All other trademarks mentioned herein are used for identification purposes only and
may be or are trademarks or registered trademarks of their respective companies.

More Related Content

PPTX
How to Eliminate the #1 Cause of Network Down-time
PPTX
thwackCamp 2013: Get the Most Out of your Web Performance Monitor
PPTX
Troubleshooting VOIP with the Orion Platform
PPTX
Network Performance Monitor (NPM) 10.4: New Features, Tips and Tricks for
PPTX
Cyber Tech Israel 2016: Get Your Head in the Cloud
PPTX
Customer Level 2 Training: Service Groups, Alerts and Dependencies
PPTX
Threat Intelligence + SIEM: A Force to be Reckoned With
DOCX
How to Eliminate the #1 Cause of Network Down-time
thwackCamp 2013: Get the Most Out of your Web Performance Monitor
Troubleshooting VOIP with the Orion Platform
Network Performance Monitor (NPM) 10.4: New Features, Tips and Tricks for
Cyber Tech Israel 2016: Get Your Head in the Cloud
Customer Level 2 Training: Service Groups, Alerts and Dependencies
Threat Intelligence + SIEM: A Force to be Reckoned With

What's hot (20)

PPTX
How to Close the SecOps Gap
PDF
Neuralstar- Network Management System
PDF
TECHNICAL BRIEF: Using Symantec Endpoint Protection 12.1 to Protect Against A...
PPTX
Cloud video surveillance
PPT
How-To: WSUS Reporting Made Easier
PPTX
Top 10 steps towards eliminating inside threats by paresh thakkar
PDF
Veritas Resiliency Platform
PPTX
SolarWinds® Getting Started With NPM and SAM
PDF
SPS Enterprise Family
PDF
Migrating to the Cloud: Lessons Learned from Federal Agencies
PDF
ESG Labs Testing and Performance Audit of the NetBackup 5330 Appliance
PPTX
Webinar: SecurePlanHealth Updates
PDF
PDF
Icomm agentless-architecture
PPTX
What's New with Ivanti’s Enterprise Licensing Agreement?
PDF
Ivanti New Pricing Model
PPTX
System Center Endpoint Protection
PDF
The Business Value of System Center 2012
PDF
Whitepaper: Simplifying Data Center Network Management Leveraging SDN - Happi...
How to Close the SecOps Gap
Neuralstar- Network Management System
TECHNICAL BRIEF: Using Symantec Endpoint Protection 12.1 to Protect Against A...
Cloud video surveillance
How-To: WSUS Reporting Made Easier
Top 10 steps towards eliminating inside threats by paresh thakkar
Veritas Resiliency Platform
SolarWinds® Getting Started With NPM and SAM
SPS Enterprise Family
Migrating to the Cloud: Lessons Learned from Federal Agencies
ESG Labs Testing and Performance Audit of the NetBackup 5330 Appliance
Webinar: SecurePlanHealth Updates
Icomm agentless-architecture
What's New with Ivanti’s Enterprise Licensing Agreement?
Ivanti New Pricing Model
System Center Endpoint Protection
The Business Value of System Center 2012
Whitepaper: Simplifying Data Center Network Management Leveraging SDN - Happi...
Ad

Viewers also liked (15)

PPTX
Performance Management and Capacity Planning in VMware® and Hyper-V® environm...
PPT
Drastiriotita1
PPT
Not Just for the Web: Cascade and Mass Email Messages
PDF
Commercial Floor Maintenance
PDF
Boot camp posters 2
DOCX
Caderno de práticas corrigidas02 de maio
PDF
The Mobile Worker
PDF
7th pre alg -l26
PPTX
Planning and Developing a Content Strategy
PPTX
Understanding ROI for Network Change & Configuration Management
PPTX
SolarWinds Presents Compliance with Log and Event Manager
PPTX
Henoch-Schönlein purpura (HSP)
PDF
Seguridad alimentaria sostenible
PDF
Teaser Trends Fashion: Confirmação Tendências Verão 2014
PDF
Casa avándaro
Performance Management and Capacity Planning in VMware® and Hyper-V® environm...
Drastiriotita1
Not Just for the Web: Cascade and Mass Email Messages
Commercial Floor Maintenance
Boot camp posters 2
Caderno de práticas corrigidas02 de maio
The Mobile Worker
7th pre alg -l26
Planning and Developing a Content Strategy
Understanding ROI for Network Change & Configuration Management
SolarWinds Presents Compliance with Log and Event Manager
Henoch-Schönlein purpura (HSP)
Seguridad alimentaria sostenible
Teaser Trends Fashion: Confirmação Tendências Verão 2014
Casa avándaro
Ad

Similar to thwackCamp 2013: Cut the Alert Noise: Best Practices to Avoid Common Pitfalls and Optimize Managing IT Alers (20)

PDF
Alert centraladminguide
PPTX
National Government Webinar: Reap the Rewards of IT Consolidation
PPTX
IT Alert Management Survey Results - February 2013
PPTX
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
PPTX
Design Like a Pro: Alarm Management
PPTX
Government and Education Webinar: How the New Normal Could Improve your IT Op...
PPTX
Government and Education Webinar: Leverage Automation to Improve IT Operations
PPTX
Design Like a Pro: Alarm Management
PDF
A Practical Approach to Incident Management for SaaS/PaaS
PPTX
Threat Detection as presented at the 2016 DGI Cyber security Conference
PPTX
Government Webinar: Alerting and Reporting in the Age of Observability
PPTX
Federal Webinar: Using Integrated Tools to Improve IT Service Management
PPTX
SolarWinds Federal Tools Webinar - Using Integrated Tools to Improve Federal ...
PPTX
Government and Education Webinar: Zero-Trust Panel Discussion
PPTX
SolarWinds Federal Cybersecurity Survey 2016
PPTX
SolarWinds Federal Cybersecurity Survey 2015
PPTX
Federal Webinar: Best Practices and Tools for Reducing Insider Threats
PPTX
Webinar - ServiceNow and SolarWinds: Improving IT Operations Together
PPTX
Federal Webinar: Leverage IT Operations Monitoring and Log Data to Reduce Ins...
PDF
OSMC 2018 | Eliminating Alerts or Operation Forest by Rihards Olups
Alert centraladminguide
National Government Webinar: Reap the Rewards of IT Consolidation
IT Alert Management Survey Results - February 2013
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Design Like a Pro: Alarm Management
Government and Education Webinar: How the New Normal Could Improve your IT Op...
Government and Education Webinar: Leverage Automation to Improve IT Operations
Design Like a Pro: Alarm Management
A Practical Approach to Incident Management for SaaS/PaaS
Threat Detection as presented at the 2016 DGI Cyber security Conference
Government Webinar: Alerting and Reporting in the Age of Observability
Federal Webinar: Using Integrated Tools to Improve IT Service Management
SolarWinds Federal Tools Webinar - Using Integrated Tools to Improve Federal ...
Government and Education Webinar: Zero-Trust Panel Discussion
SolarWinds Federal Cybersecurity Survey 2016
SolarWinds Federal Cybersecurity Survey 2015
Federal Webinar: Best Practices and Tools for Reducing Insider Threats
Webinar - ServiceNow and SolarWinds: Improving IT Operations Together
Federal Webinar: Leverage IT Operations Monitoring and Log Data to Reduce Ins...
OSMC 2018 | Eliminating Alerts or Operation Forest by Rihards Olups

More from SolarWinds (20)

PPTX
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
PPTX
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
PPTX
Government and Education Webinar: Full Stack Observability
PPTX
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
PPTX
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
PPTX
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
PPTX
Government and Education Webinar: Simplify Your Database Performance Manageme...
PPTX
Government and Education Webinar: Improving Application Performance
PPTX
Government and Education: IT Tools to Support Your Hybrid Workforce
PPTX
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
PPTX
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
PPTX
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
PPTX
Government and Education Webinar: SQL Server—Advanced Performance Tuning
PPTX
Government and Education Webinar: Recovering IP Addresses on Your Network
PPTX
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
PPTX
Government and Education Webinar: Conquering Remote Work IT Challenges
PPTX
Government and Education Webinar: SQL Server—Indexing for Performance
PPTX
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
PPTX
Government Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWinds
PPTX
Government Webinar: Preparing for CMMC Compliance Roundtable
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Improving Application Performance
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: SQL Server—Indexing for Performance
Government Webinar: Monitoring Azure and Deploying SolarWinds on Azure Govern...
Government Webinar: RMF, DISA STIG, and NIST FISMA Compliance Using SolarWinds
Government Webinar: Preparing for CMMC Compliance Roundtable

Recently uploaded (20)

PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
Machine Learning_overview_presentation.pptx
PDF
Electronic commerce courselecture one. Pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Empathic Computing: Creating Shared Understanding
PDF
Encapsulation theory and applications.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
Digital-Transformation-Roadmap-for-Companies.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
MIND Revenue Release Quarter 2 2025 Press Release
Machine Learning_overview_presentation.pptx
Electronic commerce courselecture one. Pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Unlocking AI with Model Context Protocol (MCP)
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Chapter 3 Spatial Domain Image Processing.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
sap open course for s4hana steps from ECC to s4
Encapsulation_ Review paper, used for researhc scholars
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Per capita expenditure prediction using model stacking based on satellite ima...
Empathic Computing: Creating Shared Understanding
Encapsulation theory and applications.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?

thwackCamp 2013: Cut the Alert Noise: Best Practices to Avoid Common Pitfalls and Optimize Managing IT Alers

  • 1. Cut the Alert Noise: Best Practices to Avoid Common Pitfalls and Optimize Managing IT Alerts SolarWinds® thwackCamp 2013 © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
  • 2. Agenda » What is Alert Central™ and how does it work? » Solving common IT alert problems with Alert Central  Automatic assignment and escalation  Reassignment, moving alerts between team members/groups quickly  Integrating on call scheduling with alert management  Filtering out alerts that don’t need escalation  Preventing alerts from duplicate systems from being escalated © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED.
  • 3. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. How Alert Central Works » Deployed as Virtual Appliance » Alerts from IT systems company-wide are consolidated in Alert Central (collected via e-mail or direct integration with SolarWinds Orion family products) » Alert Central handles escalation and on-call scheduling (with configurable policies) to ensure alerts go to the appropriate person » That person can then acknowledge and clear the alert, reassign, or escalate it (via email or in console)
  • 4. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Automatic Assignment & Escalation » Problem: get alerts ONLY to the people who can handle them. » Problem: if someone’s not available, alerts can get stuck until they are. » Problem: if everyone’s notified, it takes time to identify whether they care. » Solution:  Create groups for each logical staff group in Alert Central.  Create escalation policies within each group to follow the group’s notification preferences.  Assign alerts to each group based on information in the alert.
  • 5. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Moving alerts between team members/groups quickly » Problem: With a mass email system, it’s easy to lose track of who is responsible or miss that it’s you that got “assigned” the alert. » Problem: When alerts need to go to another group, it can be unclear how to do so. » Problem: Working remotely or from home, having to log in to deal with alerts can be time consuming. » Solution:  Automatic assignment makes sure only one person has the ball.  Reassign alerts via email or the console  Reassign alerts to either a specific user or a group, which will use the group’s configured escalation policy automatically.  Each user can configure notification policies in Alert Central for their notification preferences.
  • 6. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Integrating on call scheduling with alert management » Problem: Maintaining an external on call calendar (on the whiteboard, in a spreadsheet, in a shared calendar) can be hard to keep accurate » Problem: Without on call integrated to alerting, either a shared device has to be used or a person has to be available 24/7 to find the on call person » Solution:  Use on call calendars within Alert Central to support rotations, regular schedules  Integrate on call directly with escalation policies – with fallback options
  • 7. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Filtering out alerts that don’t need escalation » Problem: Some alerts don’t need immediate action or are handled by regular helpdesk/IT staff, but come in through the same email source » Problem: Realistically, systems sometimes generate noise or invalid alerts, and it’s faster to tune them out until a fix is made » Solution:  Identify criteria for noise alerts based on the email/alert details  In Alert Central’s source configuration, choose the “Trash this alert” option for that alert criteria
  • 8. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Preventing alerts from duplicate systems from being escalated » Problem: Implementing new systems while leaving old systems running generates some duplicate alerts » Problem: Overlapping monitoring systems can generate similar alerts, but both copies don’t need to be delivered » Problem: In any case, it’s not possible to tune out an entire source, filtering needs to be more sensitive » Solution:  Identify data in the duplicate alert that doesn’t need to be delivered  Use “Trash this alert” to indicate the duplicate alerts should be skipped  As more cases come up, continue evolving the policy easily
  • 9. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Resources » Alert Central Getting Started Videos  Configuring Escalation Policies & On Call: http://www.youtube.com/watch?feature=player_embedded&v=8h7nUEXJ3ws  Configuring Orion Alert Sources: http://www.youtube.com/watch?feature=player_embedded&v=BJLK0IqDHII  Configuring Email Alert sources: http://www.youtube.com/watch?feature=player_embedded&v=oMxN2oZZM4s » Alert Central on thwack®  http://thwack.solarwinds.com/community/tools_tht/alert-central » Alert Central Resource Library  Links to FAQs, downloads, and more: http://thwack.solarwinds.com/docs/DOC-170671
  • 10. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Questions?
  • 11. © 2013 SOLARWINDS WORLDWIDE, LLC. ALL RIGHTS RESERVED. Thank You! The SOLARWINDS and SOLARWINDS & Design marks are the exclusive property of SolarWinds Worldwide, LLC, are registered with the U.S. Patent and Trademark Office, and may be registered or pending registration in other countries. All other SolarWinds trademarks, service marks, and logos may be common law marks, registered or pending registration in the United States or in other countries. All other trademarks mentioned herein are used for identification purposes only and may be or are trademarks or registered trademarks of their respective companies.

Editor's Notes

  • #5: Quick demo: group escalation policies; routing rules (which we’ll come back to later, so we don’t need to be too specific on).
  • #6: Quick demo: look at an alert in AC, show reassignment. Show user notification prefs.
  • #7: Quick demo: on call calendars, calendars in escalation policies
  • #8: Quick demo: alert source config with a trash option
  • #9: Quick demo: sourceconfig with more filtering rules