Comments
-
Any word on resolution yet?
-
I know about time of day sets, this does not help. Basically I need a scheduled task to run on LEM daily. Our issue is email alert overload. We want an alert is a machine tried to go to a bad address that we have a sinkhole setup for. Only if we setup the rule one pc could trigger from 1 to thousands of events, which…
-
Maybe I am not explaining the event very well, as I don't thing an InternalAgentOffline.DetectionTime < InternalAgentOnline.DetectionTime would help, as the offline was already preceding the online. Think of it like this. A PC has an agent, the connection is unplugged, therefore triggering an offline event as there is no…
-
Ok, this is great information. However in our situation, how do we get just one agent offline within a specified timeframe, say only alert once in a 12 hour window. The situation we had with the flakey VPN, was the agent went offline, then back online, about every 10 minutes. In the video, the reset correlation would be…
-
Havn't done a lot of customization yet. Although we are grouping environmnets based on custom properties.
-
As LEM uses an agent, there is a security chain that gets established between the agent and the server. As long as this security is not broken, it should not matter what the given IP address is of a workstation (We run agents on laptops and desktops no problem). You will note in the articles, that if an agent is no longer…
-
Here is a screenshot of the alert for the DHCP Server service, however we just alert on any monitored Windows Service being down. Component Type 9 is Windows Service As for the canned alert you can copy and modify as needed. Just remove the action to run a program to restart the service and add an action to email. The…
-
I just checked ours and we seem to be experiencing similar issues. Discovery is set for every 4 hours and last successful was 11/30
-
I created a quick demo on how to setup email alert in a rule, this should help you out: Setting Up LEM Email Template
-
I had the same problem when first setting up email alerts. In the Rule, under the email template, there are boxes next to the variables. You need to go to the Events or Event Groups and the drag the field you want to use for the variable. For example, if you wanted to know the $User that failed to login, you could drag the…
-
What we do is use custom properties, then use the All Nodes Resource. SO we have an Environment properties for Test, Dev, Prod, etc.. So each level can use custom properties. Then if you only want to see only certain types, like Windows you can use the Filter Nodes at the bottom to make a custom query like " MachineType…