We are having problems with alert suppressions. There are three types of issues:
1. A 'Tiered alerting' where if you cannot get past the core switch(its down or unreachable) , do not alert on the devices beyond it. If you can get past the switch, but not past the firewall, alert on that but not all the nodes in your remote sites. And so on. I had this problem before hand and brought it up only to be told a new condition "unreachable" (or some such) would come out with v9 and I could simply suppress the alert if "X was unreachable". I cannot find any such condition and I am wondering if the improved the SQL queries well enough to put complex suppression statements in and have them work.
2. All of the existing alerts we had before going to 9 got a suppression condition added (if Node = Unmanaged) which I had thought was an implied condition, not one that had to be explicitly stated. Is this required now? Also, the existing alerts didn't work after the upgrade; we had to replace the existing email addresses with new ones and then swicth back before they would fire and send off email.
3. We have several APM alerts (if APM APP = Down, alert) that generate email notifications. Sometimes if they are associated with a Node and that node is in unmanaged mode, the alerts will trigger and sometimes they will not. Is there a way to make this consistent? I know the alerts based on the APM will not allow me to put in custom node properties so I am not sure how well it integrates with the NPM.
Thanks in advance for any help.