Hello all,
I am still confused by Alert Suppression. Let me start with a simple scenario. I have the following hypothetical setup:
Orion > RouterA>RouterB>SwitchA>25 Servers connected to the switch
I want to monitor the devices RouterA, RouterB, SwitchA, and each of the servers connected to the switch. So that means I will add each of these 28 devices to Orion System Manager. Lets say I have just installed Orion and have not modified the canned alerts but I do have "Page me when a node goes down" and "Page me when an interface goes down" activated and working correctly. So at this point if a server goes down I get a page for the server (node) going down and the switch interface that the server was attached to goes down so I am paged again. So I know both alters are working correctly.
Now lets say Router A fails. How do I set up suppression so I don't get a page for RouterB going down, SwitchA going down, and all 25 servers going down. Do I have to create seperate alerts for all 27 devices and suppressions for all 27 devices?
To make it even more simple lets say SwitchA fails. How do I set up suppression so that I don't get an alert from all the 25 server nodes that I am monitoring. Do I have to set up an alert for each of the 25 server nodes and add a suppression that if switch 25 goes down don't page? I hope not! That would be very painful.
I can't seem to find any documentation or tutorials that shows the logic behind suppressions. Solar Winds does tell me how to create a suppression but does a very poor job at telling how this is put into action in the real world. I have not found any posts on this forum that are answered very well either.
Solar Winds are you listening....