Use > Topology Based Event Correlation (TBEC) Rules

Topology Based Event Correlation (TBEC) Rules

In event correlation, rules are applied to identify commonly occurring events or combinations of events and helps handling of such events by automatically identifying events that can be withheld, removed or need a new event to be generated and displayed to the operators.

How to Access the Correlation Rules

How to Access the Correlation Rules

  • Open the Correlation Rules pane:

    Click Administration > Event Processing > Correlation > Topology-Based Event Correlation.

The OMi MP for Infrastructure includes the following rules to correlate Infrastructure- related events:

System::Computer:CPU Load >> CPU Usage Level

Description: CPU usage of one or more CPUs on the system is high as the system is in a CPU bottleneck.

Cause

CIT: Computer

ETI: CPU Load

Value: Bottlenecked

Symptom

CIT: CPU

ETI: CPU Usage Level

Value: High/ Much Higher Than Normal/ Spike

System::Computer:Memory Load >> CPU Load

Description: CPU bottleneck caused by paging

Cause

CIT: Computer

ETI: Memory Load

Value: Paging

Symptom

CIT: Computer

ETI: CPU Load

Value: Bottlenecked

System::Computer:Memory Load >> Memory Usage Level

Description: Memory usage on system is high as the system is in a memory bottleneck

Cause

CIT: Computer

ETI: Memory Load

Value: Paging

Symptom

CIT: Computer

ETI: Memory Usage Level

Value: Much Higher Than Normal/ Near Capacity

System::Computer:Memory Usage Level >> Swap Usage Level

Description: High memory usage results in swapping

Cause

CIT: Computer

ETI: Memory Usage Level

Value: Near Capacity

Symptom

CI: Computer

ETI: Swap Usage Level

Value: Much Higher Than Normal/ Near Capacity

System Down >> System Applications Down

Description: Services or applications are unavailable as the system is down

Cause

CIT: Computer

ETI: Node Status

Value: Down, Suspended, Unknown

Symptom

CIT: Computer

ETI:

Value:

Batch Jobs

Job Failed

E-Mail Service

Unavailable

Event Logging Service

Unavailable

Firewall Service

Unavailable

WebServer Service

Unavailable

Print Service

Unavailable

RPC Service Unavailable

System::Computer:Resource Usage >> CPU Usage Level

Description: Process using high amount of cpu on system causing system cpu usage high

Cause

CIT: Computer

ETI: Resource Usage

Value: High

Symptom

CIT: CPU

ETI: CPU Usage Level

Value: High/ Much Higher Than Normal/ Spike

System::Computer:Resource Usage >> Memory Usage Level

Description: Process using high amount of memory on system causing system memory usage high

Cause

CIT: Computer

ETI: Resource Usage

Value: High

Symptom

CIT: Computer

ETI: Memory Usage Level

Value: Higher Than Normal/ Much Higher Than Normal/ Near Capacity

System::File System:Disk Usage Level >> Swap Usage Level

Description: Swap usage caused by system drive full

Cause

CIT: FileSystem

ETI: Disk Usage Level

Value: Near Capacity

Symptom

CIT: Computer

ETI: Swap Usage Level

Value: Higher Than Normal/ Much Higher Than Normal/ Near Capacity

System::Node:PingAvailability >> NodeStatus

Description: Ping availability of node failed because node is down

Cause

CIT: Node

ETI: Node Status

Value: Suspended, Down, Unknown

Symptom

CIT: Node

ETI: Ping Availability

Value: Unavailable

System::File System:PingAvailability >> InterfaceCommunicationStatus

Description: Node cannot be pinged because interface communication status is unavailable

Cause

CIT: Interface

ETI: Interface Communication Status

Value: Unavailable

Symptom

CIT: Interface

ETI: Ping Availability

Value: Unavailable

Virtual::Computer:Memory Usage Level >> Hypervisor Memory Usage Level

Description: Hypervisor is constrained by high memory usage done by VM

Cause

CIT: Computer

ETI: Memory Usage Level

Value: Much Higher Than Normal

Symptom

CIT: Computer

ETI: Memory Usage Level

Value: Much Higher Than Normal/ Near Capacity

Virtual::Computer::CPU Usage >> Hypervisor System CPU Load

Description: A VM using high amount of physical CPU cycles on the hypervisor can cause bottleneck in Hypervisor.

Cause

CIT: Computer

ETI: CPU Load

Value: Bottlenecked/ Busy/ Overloaded

Symptom

CIT: Computer

ETI: CPU Load

Value: Bottlenecked/ Busy/ Overloaded

Virtual::Computer::CPU Load>> CPU Entitlement Usage Level

Description: A VM using high amount of CPU entitled can cause CPU load to become high on server.

Cause

CIT: Computer

ETI: CPU Entitlement Usage Level

Value: Higher Than Normal/ Much Higher Than Normal

Symptom

CIT: Computer

ETI: CPU Load

Value: Bottlenecked/ Busy/ Overloaded/ Constrained

Virtual::Computer::Memory Usage Level>> Memory Entitlement and Swap Usage Level

Description: Memory Entitlement and Swap Usage Level becoming high on VMs can cause High Memory Usage levels on Server.

Cause

CIT: Computer

ETI: Swap Usage Level

Value: Near Capacity/ Higher Than Normal/ Much Higher Than Normal

ETI: Memory Entitlement Usage Level Value: Higher Than Normal/ Much Higher Than Normal

Symptom

CIT: Computer

ETI: Memory Usage Level

Value: Near Capacity/ Higher Than Normal/ Much Higher Than Normal

Hypervisor::Ping Availability >> VM::Ping Availability

Description: VMs are unavailable as the hypervisor host running the VMs is down.

Cause

CIT: Computer

ETI: Ping Availability

Value: Unavailable

Symptom

CIT: Computer

ETI: Ping Availability

Value: Unavailable

Cluster Software Service Unavailable >> Clustered Server Offline

Description: Cluster software Services on cluster systems failing to run causes clustered servers (resource groups) to be inactive.

Cause

CIT: ClusterSoftware

ETI: Cluster Software Service

Value: Unavailable

Symptom

CIT: ClusterResourceGroup

ETI: Cluster Resource Group Status

Value: Offline

Cluster Nodes Down >> Cluster Resource Group Impacted

Description: When 1 or more cluster nodes are down, clustered servers (resource groups) running in failover mode on these nodes are impacted

Cause

CIT: Computer

ETI: Node Status

Value: Down/ Hang/ Suspended/ Unknown

Symptom

CIT: ClusterResourceGroup

ETI: Cluster Resource Group Status

Value: Offline

Cluster Members Down >> FailoverCluster Impacted (many symptoms)

Description: When a few cluster members are unavailable, the cluster is down.

Cause

CIT: Computer

ETI: Node Status

Value: Down/ Hang/ Suspended/ Unknown

Symptom

CIT: FailoverCluster

ETI: Cluster Strength

Value: All Nodes Down/ Quorum Not met/ SPOF

Cluster Member Down >> Cluster Software Service Down

Description: When the cluster member is down, the cluster software service on the node is down.

Cause

CIT: Computer

ETI: Node Status

Value: Down/ Suspended

Symptom

CIT: ClusterSoftware

ETI: Cluster Software Service

Value: Unavailable

Related Topic

For more information on how the correlation rules work, see the Operations Manager i documentation.