I've never worked with LA/OLV before to create rules (currently on OLV, working to get LA upgrade approved) and honestly, I've never done much with trap/syslog rules before.
I'm working on setting up alerts triggered by syslog events from UPSs. Currently only working with one as I iron out the bugs. It's a perfect test case, because it shooting out syslog messages constantly. Rule setup to trigger on any syslog message from UPS vender1 and vendor2. I see multiple message in the Syslog Log Viewer, but only a single alert. I don't have any throttling setup as of yet (get things working first, then tame down the rules), just pretty much a wide open "Any message from any UPS triggers an alert."
What am I missing? Is this how it should be working, rather than filling up the alert log? Or is there something I'm doing wrong so that it's not firing off each time? I plan on turning on the throttling to one message every few hours once I know it's working, but shouldn't I see an alert for each syslog message? Dozens of messages and only a single alert.