Smart Alert Suppression helps reduce alert noise when a parent device goes offline and causes downstream devices to appear offline. For example, if an upstream switch or gateway loses connectivity, multiple access points or other downstream devices may also appear offline.
What Smart Alert Suppression does
When enabled, Auvik uses the network topology map to identify parent and downstream device relationships. If a parent device is determined to be offline, Auvik can suppress offline alerts from downstream devices to reduce redundant notifications.
Smart Alert Suppression:
- Reduces cascading offline alerts from downstream devices.
- Uses Auvik’s network topology to determine device relationships.
- Applies only to alerts created in Alerts v2.
- Can work alongside site-level alert suppression.
Smart Alert Suppression does not combine multiple alerts into one message or create a single bundled alert. Instead, it prevents or suppresses secondary downstream alerts while the parent issue is active.
Legacy alerts are not affected by Smart Alert Suppression.
Before enabling Smart Alert Suppression
Make sure the topology shown in Auvik accurately reflects the physical network.
Auvik uses information such as SNMP data, CDP, and LLDP to identify device connections. Verify that:
- Network infrastructure is being monitored with SNMP where appropriate.
- SNMP credentials are configured correctly.
- CDP or LLDP is enabled on network devices where supported.
- Device interfaces and connections appear correctly in the topology map.
- The parent device and downstream devices are assigned to the expected site.
If a link is unmanaged, a device is not discovered, or CDP/LLDP information is unavailable, Auvik may not be able to identify the dependency. In that case, downstream alerts may not be suppressed.
For more information, see Why doesn’t my topology map look right?.
How to enable Smart Alert Suppression
To enable Smart Alert Suppression at a site:
- Log in to the desired site.
- Navigate to Admin > Manage Alerts > Alert Suppression.
- Set Smart Alert Suppression to Enabled.
- Click Save.
To enable Smart Alert Suppression for multiple sites:
- Log in to the global site.
- Navigate to Admin > Manage Alerts > Alert Suppression.
- Select the sites where suppression should be enabled.
- Click Save.
Smart Alert Suppression is disabled by default and must be enabled for the applicable sites.
Optimize parent-device detection
Suppression works best when Auvik identifies the parent device as offline before it identifies downstream devices as offline.
To improve detection order:
- Go to Admin > Discovery > Discovery Settings > Health Check Frequencies.
- Add or edit a health-check rule for parent devices such as core switches, routers, or firewalls.
- Place the parent-device rule above the applicable downstream-device rule.
- Configure the health check carefully so that it does not delay detection of a genuine outage.
Auvik recommends testing health-check changes before applying them broadly.
Scope and testing
Smart Alert Suppression is intended for Alerts v2 offline conditions where the parent and downstream relationship is clear.
Examples include:
- Access points connected downstream from a PoE switch.
- Devices connected behind an upstream switch.
- Network devices dependent on an upstream router or gateway.
Where possible, test the configuration during approved maintenance or in a controlled environment:
- Confirm that the topology correctly shows the parent and downstream devices.
- Verify that Smart Alert Suppression is enabled for the applicable site.
- During an approved maintenance window, take the identified parent device or link offline.
- Confirm that the parent alert is generated.
- Verify whether downstream offline alerts are suppressed.
Some downstream alerts may still occur before Auvik identifies the parent device as offline.
Limitations
Smart Alert Suppression may not work as expected when:
- The topology does not accurately represent the network.
- A parent device cannot be determined.
- CDP or LLDP information is unavailable.
- Links or devices are unmanaged or missing from Auvik.
- The topology contains loops or incorrect connections.
- The alert was created in the legacy alerting system.
- The cause is specific to an individual device, such as an authentication failure, incorrect credential, or device-specific configuration issue.
Smart Alert Suppression does not guarantee that every downstream alert will be prevented. Suppression timing depends on when Auvik identifies the parent and downstream devices as offline.
If the parent device cannot be reliably identified for a site, do not use suppression for that site until the topology and device relationships are corrected.
Smart Alert Suppression and site-level alert suppression
Smart Alert Suppression uses topology relationships between parent and downstream devices.
Site-level alert suppression is intended for environments such as shared-collector deployments and suppresses alerts based on selected parent devices being offline. Review the requirements for site-level suppression before enabling it.
For more information, see Alert Suppression for Sites using Alerts v2.