Subject: |
RE: [Monitoring processes] zFailSeverity and count threshold in OSProcess template |
Author: |
Jane Curry |
Posted: |
2019-05-08 09:31 |
Having just tested this out....
YES - if the count goes to 0 then you get 2 events, one for the process not running of class /Status/OSProcess and one for the threshold which no longer meets the max/min limits, of class /Perf/Snmp. Each has it's own severity. The 2 events are unrelated in the events system - unless you want to write something to relate them ;)
Cheers,
Jane
------------------------------
Jane Curry
Skills 1st United Kingdom
jane.curry@skills-1st.co.uk
------------------------------
Subject: |
RE: [Monitoring processes] zFailSeverity and count threshold in OSProcess template |
Author: |
Hrvoje T |
Posted: |
2019-05-13 10:02 |
Thank you Jane, you are very helpful as usual. I guess I'll leave both but trigger notifications on only one of them.
I just checked my systems and got some events during the weekend. Yes, two pair of events are generated.
One is problem-clear pair with messages:
Problem: Process set contains 0 running processes: wabk81Clear: Process up: wabk81 Using regex 'wabk81' with pid's 21319
Other is:
Problem:
threshold of count not met: current value 0.000000
Clear: threshold of count restored: current value 1.000000
At first sight one would pick first one to trigger notifications but this one, at least on my side, is not quite complete. All fields in event details are empty (like zenoss.device.device_class, zenoss.device.groups, zenoss.device.ip_address, zenoss.device.location, zenoss.device.priority, zenoss.device.production_state). So I'm opting for threshold event as it is filled with all required information. Just a little transformation will do to make message look nicer. This is something for Zenoss to look up into, events triggered by zFailSeverity are missing some important fields (Zenoss 6.2.0 installed).
------------------------------
Hrvoje T
CS Computer Systems
Zagreb
------------------------------