I recently stood up a Kiwi server and have rules configured to email users when a node has certain syslog events. Now the users want ONLY their notifications from the devices they manage instead of all of the events.
Is there a way to tie Orion's Syslog alerting engine to use the Nodes Custom Properties and Kiwi to filter based upon a CP? For instance if a device sends an event the filter would look at Orion's CP and then based upon that would send it to the right group.
I was thinking of having the events hit the Kiwi server first then it forward the events to Orion's Syslog. Hopefully from there it can link to the CP and then decide who to email to.
I can't do this by the device IP or hostname......