Hello Community Members,
I understand that similar questions may have been discussed previously within the community. However, I would like to seek some clarification regarding alert evaluation behavior in our SolarWinds environment and would appreciate your insights.
.Environment Details:
- Number of SD-WAN devices: ~300 nodes
- Interface Statistics Polling Interval: 5 minutes
- Alert Evaluation Frequency: 5 minutes
- Threshold: Bandwidth Utilization ≥ 95%
- Trigger Sustained Condition: 20 minutes
- Reset Sustained Condition: 20 minutes
These SD-WAN devices are designed to operate at consistently high bandwidth utilization, which is generating significant alert noise. We are reviewing our alert configuration and want to understand precisely how the alert engine evaluates sustained threshold conditions. Based on our understanding, if interface statistics are polled every 5 minutes and alert evaluation also occurs every 5 minutes, the timeline would be:
Time | BW Utilization Status |
|---|
10:00 | Normal |
10:05 | High BW (>95%) |
10:10 | High BW (>95%) |
10:15 | High BW (>95%) |
10:20 | High BW (>95%) |
10:25 | High BW (>95%) |
10:30 | High BW (>95%) |
My assumption is that the alert would trigger at 10:30, since the threshold has remained breached for more than the configured sustained period (20 minutes) and sufficient polling intervals have occurred.Could you please confirm:
- How the Alert Evaluation Frequency interacts with the Interface Statistics Polling Interval when both are set to 5 minutes?
- Does SolarWinds evaluate only the latest polled statistic during each alert evaluation cycle, or does it perform any historical lookback?
- Based on the example above, at what exact time would the alert be expected to trigger?
- Is our understanding of the sustained threshold logic correct?
Appreciate your guidance on this behavior, as we are attempting to optimize alerting and reduce unnecessary bandwidth utilization alerts from these SD-WAN devices.
@KMSigma.SWI @cnorborg