Alert suppression for sites can reduce the number of alerts for organizations that use a shared collector. This functionality will suppress alerts based on whether the entire selection of parent devices are offline. It should be noted that some LAN devices may notify as down before the shared collector determines the parent to also be down.
Key Considerations Before Implementation
An improper deployment of the alert suppression could potentially prevent alerts from triggering for the entire site. Only alerts created in the new alert platform will be suppressed.
Your organization is responsible for creating the correct suppression rules. Please keep the following items in mind:
This solution is intended for use with sites that are monitored with a shared collector.
- Alerts for all entities will be suppressed if all parent devices are offline.
- All offline alerts will require a custom clear condition of operational status of “UP.” If offline alerts are configured at the MSP level, the clear condition needs to be set here.
- Some alerts may trigger before the parent alert can suppress the remaining devices.
- Organizations using high availability failover may want to test the functionality before implementing.
- When a parent is determined to be down, the alert engine assigns a temporary status of unreachable to all devices in the site.
Optimizing the Collector Actions
Alert Suppression will work best when the parent device is determined to be down before other devices in the network. The best way to ensure that this happens is by adding a rule for the parent device(s) to the top of the health check frequencies table.
The parent devices should have the highest priority, and the frequency and minimum failures should at least match the network element schedule or be lower values.
Setting Up an Offline Alert that Works with Alert Suppression
When the collector determines that the parent or set of parent devices are offline, it sets the state of all devices in the site to unreachable until the parent device(s) are back online. This means that the clear condition of offline alerts needs to be set to custom, Up.
It is critical to have any offline alert use the operational status equal to UP.
Selecting the Parent Devices
The devices can be elected on the Alert Suppression underneath Alert Management. From here you can directly select devices, or create a naming rule that selects devices. Using a string matching rule will make sense for sites that have a high availability set up.
Suppression is Not Recommended in All Environments
This functionality is site-based. If a single set of devices can not be determined to be a parent for a tenant site (all within the same site URL), then alert suppression using this method is not recommended until further enhancements are released.