IBM E027SLL-H Troubleshooting Guide - Page 259

After an event is cleared in Netcool/OMNIbus, the event's, severity is changed back to its original

Page 259 highlights

Table 21. Monitoring events in Netcool/OMNIbus do not have expected values (continued) Cause Resolution An acknowledgement expiration status update event from the hub monitoring server has re-opened a sampled event in the Netcool/OMNIbus ObjectServer after the operator cleared or deleted the event in Netcool/OMNIbus and has set the Summary attribute to the situation name. (Other OMNIbus attributes may not be set as expected too.) If a sampled event is cleared or deleted in Netcool/OMNIbus, the behavior of the bidirectional event synchronization architecture is to send a request to the hub Tivoli Enterprise Monitoring Server to acknowledge the situation with a specified timeout. The reason for this behavior is that you cannot close sampled situation events unless the monitoring agent determines the situation condition is no longer true. If the acknowledgment timeout of the situation expires and the situation is still true, then a new situation event is opened in the Netcool/OMNIbus ObjectServer so that the Netcool/OMNIbus operator is notified that the event condition has not been resolved. By default, Netcool/OMNIbus removes cleared events from the alerts.status table after 2 minutes. If the event has already been removed from the alerts.status table when the acknowledgment expiration times out, a new event is opened in the ObjectServer. However, the event data is not fully populated, because the acknowledgment expiration status update event contains a subset of the base IBM Tivoli Monitoring EIF slots and not any of the agent-specific data. In addition, the OMNIbus Summary attribute is set to the situation name and not the descriptive text that is used when the IBM Tivoli Monitoring sends an open event to Netcool/OMNIbus. To ensure that the event data is fully populated when the acknowledgement expires, set the default acknowledgment expire time to be less than the time cleared events remain in the alerts.status table. If the event is still in the alerts.status table when the acknowledgment expiration status update event is received, the event will be deduplicated by the IBM Tivoli Monitoring triggers and the event attribute settings from the original event will be maintained. To increase the time that cleared events remain in the alerts.status table, edit the Netcool/OMNIbus delete_clears automation trigger. Then set the acknowledgement expire time to be less than time used by the delete_clears trigger logic. See the topic "Changing the default acknowledgment timeout used when sampled events are deleted or cleared in Netcool/OMNIbus" in the IBM Tivoli Monitoring Installation and Setup Guide for more information. After an event is cleared in Netcool/OMNIbus, the event's severity is changed back to its original severity If you clear a monitoring event in Netcool/OMNIbus and you are using the bi-directional architecture, the hub monitoring server sends a loopback event to OMNIbus after it processes the event status change from OMNIbus. If the default deduplication trigger is processing monitoring events and the event had been cleared, the deduplication trigger changes the event's severity to the original severity value that is included in the loopback event. Chapter 14. Event synchronization troubleshooting 241

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310

Table 21. Monitoring events in Netcool/OMNIbus do not have expected values (continued)
Cause
Resolution
An acknowledgement expiration
status update event from the hub
monitoring server has re-opened
a sampled event in the
Netcool/OMNIbus ObjectServer
after the operator cleared or
deleted the event in
Netcool/OMNIbus and has set
the Summary attribute to the
situation name. (Other OMNIbus
attributes may not be set as
expected too.)
If a sampled event is cleared or deleted in
Netcool/OMNIbus, the behavior of the bidirectional
event synchronization architecture is to send a request
to the hub Tivoli Enterprise Monitoring Server to
acknowledge the situation with a specified timeout. The
reason for this behavior is that you cannot close
sampled situation events unless the monitoring agent
determines the situation condition is no longer true. If
the acknowledgment timeout of the situation expires
and the situation is still true, then a new situation event
is opened in the Netcool/OMNIbus ObjectServer so that
the Netcool/OMNIbus operator is notified that the
event condition has not been resolved.
By default, Netcool/OMNIbus removes cleared events
from the alerts.status table after 2 minutes. If the event
has already been removed from the alerts.status table
when the acknowledgment expiration times out, a new
event is opened in the ObjectServer. However, the event
data is not fully populated, because the
acknowledgment expiration status update event
contains a subset of the base IBM Tivoli Monitoring EIF
slots and not any of the agent-specific data. In addition,
the OMNIbus Summary attribute is set to the situation
name and not the descriptive text that is used when the
IBM Tivoli Monitoring sends an open event to
Netcool/OMNIbus.
To ensure that the event data is fully populated when
the acknowledgement expires, set the default
acknowledgment expire time to be less than the time
cleared events remain in the alerts.status table. If the
event is still in the alerts.status table when the
acknowledgment expiration status update event is
received, the event will be deduplicated by the IBM
Tivoli Monitoring triggers and the event attribute
settings from the original event will be maintained. To
increase the time that cleared events remain in the
alerts.status table, edit the Netcool/OMNIbus
delete_clears automation trigger. Then set the
acknowledgement expire time to be less than time used
by the delete_clears trigger logic. See the topic
"Changing the default acknowledgment timeout used
when sampled events are deleted or cleared in
Netcool/OMNIbus" in the IBM Tivoli Monitoring
Installation and Setup Guide for more information.
After an event is cleared in Netcool/OMNIbus, the event's
severity is changed back to its original severity
If you clear a monitoring event in Netcool/OMNIbus and you are using the
bi-directional architecture, the hub monitoring server sends a loopback event to
OMNIbus after it processes the event status change from OMNIbus. If the default
deduplication trigger is processing monitoring events and the event had been
cleared, the deduplication trigger changes the event's severity to the original
severity value that is included in the loopback event.
Chapter 14. Event synchronization troubleshooting
241