Alerts are correlated based on patterns specified in alert policies to create an inference with a unique ID. You can track the inference details from the alerts browser page.
- From All Clients, select a client.
- From the drop-down options, select Alerts and click the required Inference ID.
The Alert details page presents the following tabs:
Details: Displays details of the inference.
- Any update on the inference is displayed in the Comments section.
- Resource information of the first correlated alert is dislayed in the Device Information page.
- The incident created for an inference is displayed on the Details page.
- Incident information is displayed on the Incident ID.
- Correlated alerts information is displays in the incident description in the Comments section.
The following list of correlated alert details is provided in the incident description:
- Alert ID
- Alert Subject
- Alert Created Time
- Impacted Resources
- Alert Description
The following are the tabs that appear on the Incident page:
- Resources tab: Displays the list of all resources of correlated alerts.
- Alerts tab: Displays the list of correlated alerts attached to the Incident.
- Correlated Alerts tab: Displays alerts correlated with the parent alert.
- Incidents tab: Displays the details of incidents attached to an Inference.
- Matched Escalate Alert Policies: Click Escalate Alerts on the top header of the incident details page.
You can view the escalate alert policies that match the alert and policy that created the incident automatically.
View inference statistics
Inference Stats widget displays the statistics of Inferences generated within a Partner/Client.
The widget comprises of the following information:
- Total Events: Refers to the total number of events generated.
- Total Alerts: Refers to the total number of alerts created after ingestion in OpsRamp.
- Total Inferences: Refers to the total number of Inferences generated.
- Total Correlated Alerts: Refers to the total number of alerts correlated.
- Volume Optimized: Refers to the percentage of reduction in alerts volume due to alert correlation.
View processed inferences
To view the number of inferences associated with a policy:
- Select a client from the All Clients list.
- Go to Setup > Alert Management > Alert Correlation and select the required policy.
- Click the number in the Processed Inferences column to view the details of the inferences.
The list of processed inferences is displayed on the Alerts Browser page.
Remove alerts from an inference
You can remove alerts from an Inference. The alerts can be removed from either the Quick view window or the Alert Details page. For example, if you do not want an alert to be correlated, you can remove an alert from the Inference. The removed alert then is displayed on the alerts browser as an individual alert.
If an Inference has two correlated alerts, removing one correlated alert makes both the alerts as individual alerts and the Inference is automatically correlated.
To remove alerts from the quick view:
On the Alerts Browser page, enter the alert ID in the search box. The alert is displayed on the Browser page including the number of correlated alerts.
Click the number adjacent to the alert subject.
Select the required alert and click Remove.
The alert is removed from the Inference. A comment is displayed in the Details tab as shown in the below screenshot.
Create an inference stats widget
Go to All Clients, select a client.
Go to Dashboard > +Add Widget page.
From OTHER PREDEFINED WIDGET section, click Inference Stats.
Configure the following parameters:
Time Range: Filter for Inferences triggered within a certain time span.
Default time span is Last four hours.
Refresh every: Refers to the time frequency at which the Widget should refresh and display the recent data.
Default refresh time is five minutes.
Inference Stats: Refers to the mode of Inferences that must be included in the Widget
- Select Enabled policies only to view the statistics of Enabled (ON mode) Inferences.If you select this mode, the total number of Inferences and the total number of correlated alerts created from the Enabled correlation policies appear on the Widget. In this widget, the volume optimization is based on Inferences and correlated alerts created from the Enabled correlation policies.
- Select Enabled and Observed policies to view statistics of Enabled and Observed Inferences. If you select this mode, the total number of Inferences and the total number of correlated alerts created from both the Enabled and Observed correlation policies appear on the Widget. In this Widget, the volume optimization is based on the Inferences and Correlated alerts created from both the Enabled and Observed correlation policies.
Widget Title: Refers to the name of a Widget
Select the Chart Style and click Save. Inference Stats widget is created and is displayed on the Dashboard.