nv-l
[Top] [All Lists]

RE: Data collection/thresholds, ruleset question

To: nv-l@lists.tivoli.com
Subject: RE: Data collection/thresholds, ruleset question
From: "Paul Maine Jr." <paulm@msicc.com>
Date: Wed, 19 Sep 2001 22:45:54 -0500
Todd

No, Netview NT does not have this capability. I know this does not help you
but I am solving my hysterisis issue ( by the way I also have an EE/Physics
background ) by forwarding the Netview alarms to the Tivoli Enterprise
Console(TEC). With TEC you can write your own rules. When the events are
sent to TEC, TEC look for four ( you can change the number to anything you
wish) successive samples that are above the threshold before doing anything.
If one of the successive sample drops below the lower threshold - TEC starts
counting over.

By using this technique you can filter out most of the "short duration
spikes".

Paul

-----Original Message-----
From: netview@toddh.net [mailto:netview@toddh.net]
Sent: Wednesday, September 19, 2001 10:32 PM
To: IBM NetView Discussion
Subject: Re: [NV-L] Data collection/thresholds, ruleset question, trap
con tent


"Paul Maine Jr." <paulm@msicc.com> writes:
> Todd
> 
> We have Netview NT and there is not a GUI means to accomplish what
> you are asking for. You are wanting to use hysteresis. Hysteresis is
> a means to reduce the number of events generated by quickly changing
> data ( i.e. you desire to filter spikes in your measurements ). I
> don't know if the unix version of Netview has this capability.

Hi Paul! Thanks for the info.  You've got me intrigued, though. 

I'm familiar with the concept of hysteresis (as an EE in former life),
but I guess there's two ways to look at it--what I'll call "value
hysteresis" and "time hysteresis."

The UNIX version of netview does have "value hysteresis"
capability--it's implemented as two values: a threshold trigger level,
and a rearm level.  The difference between them is the amount of
hysteresis in the value supressing multiple alerts on a borderline,
fluctuating reading.

Unforunately, "value hysteresis" doesn't really do anything to filter
out one-time peaks, since the alert would be sent the first time a
sample exceeds a threshold.  In this way, value hysteresis reduces the
occurrence of _repeated_ alerts, but notifies immediately.  I'm not
sure if this is the sort of hysteresis of which you speak.

I just don't see a way to implement the test for two consecutive polls
for being greater than a given value--a metric that aims to capture
only sustained problems (and hence retard when the _first_ alert is
sent in the event of a problem).

Does the NT version have this notion of "time hysteresis" to pass only
sustained problem?

-- 
Todd H.


<Prev in Thread] Current Thread [Next in Thread>

Archive operated by Skills 1st Ltd

See also: The NetView Web