Create a rule / older instant alarm

Hello

I am creating a rule / alarm, this updated fire for snapshots when have more than X days.

I use the topology: VMWareSnapshot.

Using an adaptation of the function to create the older snapshot report, I tried to create the rule.

creationSnapshot = scope.creationTime.getTime ();

now = new Date () .getTime ();

diffHours = (now - creationSnapshot) / 3600000;

diffDays = diffHours 24;

(diffDays > = registry ("VMW:Old.) Snapshot.Warning'));

When I test the condition in the script console, and in the rule condition, it works fine, but when the rule never fired.

I forgot something?

Thanks for any help or ideas

Kind regards

Alexander Ortiz

Strategic Solutions Consultant

Reference Dell | MCLA APM software, group

Office + 57 312 568 4791, mobile + 57 312 568 4791
E-mail [email protected]

Hi Alex

Yes, I'll try

The rule definition:

Only the State of alert is enabled:

Condition

Article: vBundle-1 VM Snap Shot age

First - check VM list ignore

Second - check VM has Snap Active

Check the third - instant age

List skip from reading the registry

def IgnoreList is registry ("vBundle.vm.snapshot.age.ignore.list");.

Get the name of VM

def VMName1 = scope.get ("name");

def boolean found = false;

If (IgnoreList! = null) {}

Found = IgnoreList.contains (VMName1) ;}

If (found) return false;

Check if the virtual machine has a snapshot active

if(Scope.currentSnapshot == null) {}

return false}

Estimate the age of the snapshot

def NumOfDays is registry ("vBundle.vm.snapshot.age.warning.days");.

try {}

creationTime = scope.currentSnapshot.get("creationTime").getTime ();

If (creationTime == null) return false;

now = new Date () .getTime ();

diffHours = (now - creationTime) / 3600000;

diffDays = diffHours 24;

If (diffDays > = NumOfDays)

Returns true;

Otherwise, return false}

catch (System.Exception e) {return false ;}

Alarm message:

[Warning] Virtual Machine: '@VMName' has a named snapshot: '@SnapshotName', it is longer than @WarningDays days. Remove the old clichés.

There is no variable defined severity level.

The Action is an EmailAction:

mail.message

VM (@VMName) has a snapshot that is @WarningDays the old days

Discovers the alarm to: @foglight_rule_alarm_link

mail. Subject

[Warning] VM (@VMName) has an old cliché

Behavior:

Rule variables:

Expression CriticalDays return register ("vBundle.vm.snapshot.age.critical.days");

Expression FatalDays return register ("vBundle.vm.snapshot.age.fatal.days");

Expression Nom_snapshot scope.currentSnapshot.name;

VMName expression return scope.get ("name");

Expression WarningDays return register ("vBundle.vm.snapshot.age.warning.days");

Registry settings:

vBundle.vm.snapshot.age.ignore.list

vBundle.vm.snapshot.age.warning.days

The days of warning STANDARD are 7 (Disclaimer), 14 (critic) and 30 (fatal).

I hope this is clear for you

If you want the critical and Fatal situation, let me know.

Brian

Tags: Dell Tech

Similar Questions

  • How to move a rule definition with the data store for esx alarm without re-creating the rule?

    Hi, I would spend my rule of definition of alarm of the data at the level of esx store, without re-creating the rule. Is this possible?

    In the Act, I don't want no definition of the alarm at the data store level. So, what is the best practice?



    Best regards

    It is currently not possible.  The rules are hierarchical, and there is no way to stop the inheritance, or move messages.  You will have to re-create them at the appropriate level.

    -KjB

    VMware vExpert

  • Can we create a rule to capture the URL string in the Hits in the APM cartridge.

    Hi team,

    We have an obligation to create a rule/alarm alert when there is string "File not found" are there in the 'LINK' when we capture the Hits. Please let me know is possible to create this kind of rule in Foglight.

    Thank you

    Shashank Soni.

    To follow on what David said, you can find this useful guide:

    Configuration of the analyzers of success

    Hope this helps,

    Shay

  • Is it possible to create a rule for mail Search mail?

    I am trying to create a set of rules that would allow already read messages in folders by year. I can quickly find e-mail a year in research, it would be nice if I could create a rule right out of the research. I don't see this feature, but how can I create a rule which will find all the emails for a given year, and move them to a folder?

    Rules are usually set up for actions that are make again and again. What you describe will be just once, right?

    Do a search for the year you want, select all results, drag them to an appropriate folder.

  • Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Is it necessary to create additional rules not permitted for uses such as Regedit.exe etc when applying software restriction policy?

    Hello

    Please visit the following link. This should explain the software restriction policies in detail.

    http://TechNet.Microsoft.com/en-us/library/bb457006.aspx

  • Need help to create a rule to monitor the "DSDeviceTotalLatency" under "VMWDatastore".

    Hello all, I am very new to vFoglight and tasked to create a rule to control the property 'DSDeviceTotalLatency' of type 'VMWDatastore' topology.  Looking at existing rules, I see that I need to write a mini script on the tab 'Conditions and Actions '.  The problem is that I do not know how to reference this property and the command to use to recover.  Thank you in advance.

    At, it is simple, can be as simple as:

    scope of the rule to the VMWDatastore type on the tab 1

    condition on tab 2:

    If (#totalLatency # 10 >) {return true;}

    return false

  • How to create the rule to trigger only 5 and 20th of each month in Foglight

    Hi team,

    One needs to create a rule in Foglight that fire only a day as the 5th and 20th of each month and check the status. I tried to create it, but I've not found an option less create rule. I think we can do it by Time Driven option or calendar drove but I'm confuse. Can someone let me know how or the document where it mentioned.

    Thank you for your help in advance.

    Thank you

    Shashank Soni.

    That sounds more like a rule-based program.  First, create a new calendar and choose the monthly option and enter one of the days of the month.  I think it might be difficult to get a calendar to be true on two different days, you may create two programs and then create a rule for each.  We can be one simple copy of the other.  Once the calendar is created, you can create a rule, choose led calendar and choose one of your two annexes.

    Maybe someone can be smarter about how to create a monthly calendar for two different dates.

    I hope this helps.
    Jeff (I work for Dell)

  • Create a rule to delete Inbox mail

    How to create a rule to delete Inbox mail after so many days?

    The old version has allowed users to set for example mail to remove after 10 days or when a new mail from the sender received.

    I can't find how to do this on the new version, please help!

    Thank you

    I found it!

    This was previously the title of 'rules' and is now under "sweep".

    Thank you

  • Creating custom rules of MARCH

    I want to be able to create a rule on:

    [Info/UncommonTraffic/Chat]

    [Info, UncommonTraffic, Chat, FileTransfer]

    [Info/UncommonTraffic/Chat/Proxy]

    .. .but be able to use the 'KEYWORD' field to trap on words like SSN / DOB and other keywords to trigger an e-mail action. Im guessing that this is not how the KEYWORD was intended to be used, but it is sure that looked like it when I put up. But as you may have guessed his does not work.

    Can someone tell me what im doing wrong or how can I achieve this to trap for PHI in our Organization.

    I've included a screenshot which may help to explain what page I'm looking at.

    http://razors-edge.org/dropbox/screenshot.jpg

    Thanks in advance.

    Jim,

    Good question! You did the correct support you use the 'keyword' option incorrectly. A device of MARCH is designed to parse and messages of aggregates of the declaration of the devices. In the example of "UncommonTraffic/Info/chat", typical features of statement are firewalls and IDS/IPS solutions. These all simply report on the presence of 'cat' traffic, no report the actual textual conversation. Unforunately the unit in MARCH is not really designed to work the way you want. Is this possible? Yes... you must have an application that is able to decode chat conversations before messages to MARS. In all honesty, it's a lot of work to make the MARCH camera doing something it's not designed to do. I hope this helps and don't forget to check my blog below for examples on how to use 'keywords' in a custom rule!

    -Mike

    http://CS-Mars.blogspot.com

  • How to create a rule of action to subtract from the Ips event log manager console express?

    How to create a rule of action to subtract from the Ips event log manager express console?, some unknown has a guide?

    Thank you.

    Sent by Cisco Support technique iPad App

    Hello

    http://www.Cisco.com/en/us/products/sw/secursw/ps2113/products_tech_note09186a0080bc7910.shtml

    HTH

    Luis Silva

    "If you need IDP (planning, design, implementation) assistance do not hesitate to contact us.

    http://www.Cisco.com/Web/partners/tools/pdihd.html

  • VCS creat search rules

    I want to creat research rules on my VCSC and VCS ex to call this kind of model [email protected]/ * / or [email protected] / * /

    exactly, I have to do to ensure that the rules on vcs and VCS ex

    Hi Mohamed!

    This is a pretty standard deployment.

    Please read carefully:

    http://www.Cisco.com/en/us/docs/Telepresence/infrastructure/VCs/config_guide/Cisco_VCS_Basic_Configuration_Cisco_VCS_Control_with_Cisco_VCS_Expressway_Deployment_Guide_X7-1.PDF

    and configure your VCS accordingly. It covers how to configure VCS for IP my calls as well in what concerns the DNS.

    Martin

    Mohamed: Please note the answers using the star under the messages!

  • Creating exception rules

    I need to create an exception rule for bttray.exe whose political office of the CSA is refusing to run. BTTray is essentially a system tray icon that shows the user what bluetooth connections that it opened.

    Now, if I simply create an exception rule, a virus or malicious code could in the future to copy originally bttray.exe and run itself, since the CSA would allow.

    How to work around this capture-20?

    I would say that creating a rule to allow this executable to run does not create a catch-22. If some malware was introduced using this executable it would try to make something like the access to the registry, access the network etc. In this case, CSA he would cease to operate the new business. I can't give you the actual section in the Administrator's guide, but it has been my experience. Once I created an exception based on an alert the executable is allowed to do what he originally tried to do and nothing else. Once he tried something else CSA arrested.

    Does anyone else have some input?

    Hope this helps

    Be sure to note all the answers.

  • Creating a rule that monitors each carrot in a host

    HI -.

    I'm new to Foglight and trying to create a rule that is triggered if an individual soul on a multicore Linux usage exceeds a given threshold. I already have a rule that follows the overall use of the machine, but there is a desire for the end user to know if one or more hearts are too busy.

    Can someone give me some advice about the particular syntax of topology and the rule that would allow me to follow individual basic info? For global use the topology that I use is

    Host.CPUs where monitoredHost.name like '% machinName % '.

    and as a rule I've got

    AVG (#utilization) for 5 min # > registry ("Average_CPU_Util_Warning")

    It feels like the foregoing, topology must be correct, and the rule should be a loop on the number of cores and returns the value true if one is too high. Something like (I am also climbing the groovy learning curve):

    for i in 0.. #numberOfCores #.

    {

    If avg (#core.utilization for 5 min #) > registry ("Per_Core_CPU_Util_Warning")

    {

    Returns true

    }

    }

    return false

    Advice would be most appreciated.

    Thank you

    -Craig

    As John, the metric to be tested is in the list of processors under Host/HostCPUs.

    It's so much easier just to scope of your rule of "transformer":

    Processor where monitoredHost.name like '% machinName % '.

    The condition can be simply:

    AVG (#utilization) for 5 min # > registry ("Per_Core_CPU_Util_Warning")

    Kind regards

    Brian Wheeldon

  • Failed to create the rule of picking

    Hi gurus,

    I am unable to create collection sets in N-> Inv-> Configuration-> rules-> Picking using this navigation.

    I created the rule and selected the parameters required in the form, click on save, the message get as '1 transaction completed, saved', if I question eponymous in stock picking rule form, impossible to find the same.

    Please let me know where I miss the configurations, profile option to see created picking rules.

    Thank you
    AK

    Just enable it in the header, goto tools and generate the corresponding package.
    If you are in R12 +, then you also need to associate it with an organization by clicking on assign button.

    Thank you
    Claire

  • form was created by an older version of the form builder

    I developed my form using Forms 10 g (9.0.4.0.19 (Production)) and when he kept on the application server.

    After that, I used my forms to uprgrade forms migration assistant... .the 932 kb resulting file converted to a 500 k file...

    I then used the compiler forms

    where in I specified the name of the fmb file... has given the username, the pwd and the string for the database...

    and I see even a compiled fmx copy into folder...

    but when I try to run on I get it

    form was created by an older version of the form builder

    I want that my forms are converted 10.1.2.0.2 production so that i can host the application on the server

    Published by: Chase Suhail on February 8, 2011 23:37

    Hello

    Sources (.fmb) must be built on computer target to generate a binary compatible (.fmx).

    François

Maybe you are looking for