Event correlation modifies the flow of events by:
Event correlation can dramatically reduce the number of alarms displayed in your Alarm Browser. Instead of the event storms typically generated by equipment and link failures, a correlated event stream displays fewer, more meaningful events, resulting in faster and easier identification of network problems.
NNM includes three Bundled Edition correlations. No additional license or software is required to use these correlations.
The Bundled Edition correlations include:There are three additional sources for correlations that can run in NNM:
You can use the Bundled Edition Correlations and Contributed Edition Correlations without purchasing any additional licenses or software. However, to use Extended Edition Correlations and Designer Edition Correlations you must purchase either or both of the following:
Correlations are platform independent, so you need only one ECS Designer, regardless of the number and type of correlations to be developed.
When NNM is first started (using ovstart),
the supplied correlations are enabled. Do
not disable these correlations without first reading the descriptions of
the individual correlations.
Some correlations are controlled by changing parameter values to adapt the correlation to your network environment. Use the built-in descriptions to learn about parameters of a correlation, and about the effects of enabling and disabling correlations.
By default, all events flow through NNM in a single stream called the default stream. If your network administrator has created additional streams then you will be able to selectively enable and disable correlations on those streams as well.
Streams are created outside of the Event Correlation interface using the ecsmgr(1M) command line interface.
A correlation may be configured by assigning specific values to its parameters. Only some correlations have parameters.
Correlation parameters allow you to control things like acceptable network delays, minimum and maximum event counts, and specific object identifiers. Some parameters have a default value. Many parameters also have limits to ensure that they are set to reasonable values. Provided that values remain within any specified limits, you can modify them as and when required, even while a correlation is enabled.
Correlation parameters are classified as either static or dynamic, depending on whether the parameter can be changed while the correlation is enabled.
If a static parameter is changed while a correlation is enabled, when the change is applied correlation is disrupted because the correlation must be disabled and reloaded. On the other hand, changes to dynamic parameters take effect "dynamically" as soon as they are applied, without disrupting the enabled correlation.
If you apply a mixture of changes (some static and some dynamic), the correlation is reloaded only if one or more of the parameters is static.
After correlation is enabled, there is usually a delay (up to several minutes) as the correlation fills its memory tables with events. This delay is called the settling time. Correlation is effective only after the settling time has elapsed. The parameter descriptions indicate if and how each setting affects the settling time.
To minimize disruption to the correlation service and to assist other network administrators it is suggested that you:
You can display the Event Correlation Configuration window using the following methods.
Options:Event Configuration menu
command. The Event Configuration window appears.Edit:Event
Correlation. The Event Correlation Configuration window
appears in your web browser.Object tab.Networks category.IP Network. The Network
Presenter appears.Fault:Alarm Browser menu command.
The Alarm Browser appears.Actions:Event Correlation
Configuration. The Event Correlation Configuration
window appears in your web browser.Task tab.Diagnostics and Fault Management
category.Configure Event Correlation.
The Event Correlation Configuration window appears in your web
browser.Tools tab.NNM category.Event Correlation Configuration.
The Event Correlation Configuration
window appears in your web browser.Use the Event Correlation Configuration window to manage correlations on a selected stream.
Select a correlation stream from the drop-down list.
Usually, there is only one stream called "default", in which case there is no need to explicitly select a stream. However, if multiple streams have been implemented you must select the stream you want to work with before enabling or disabling correlations.
Changing parameter values affects the operation of the correlation in all streams in which that correlation is enabled. Consequently, there is no need to select the stream before changing parameter values.
The Status column shows a check mark and the word
Enabled if the correlation is enabled.
Correlations that are not enabled have a blank Status and the word
Disabled. These are the only two status values
that can be set from the Event Correlation interface. However,
the ecsmgr(1M)
command line utility can be used to assign other status values to a
correlation.
The complete set of Status values is:
| Enabled | The correlation has both its input and its output enabled. This is the normal state for most correlations. |
| Disabled | The correlation has both its input and its output disabled. The correlation has no effect. |
| Input Enabled | The correlation accepts events at its input, correlates them, but does not output any events. This mode is sometimes used to overcome settling time problems. See the ecsmgr(1M) reference page for details. |
| Output Enabled | Allows the correlation to continue outputting events (stored or generated by the correlation) while preventing new events from entering. See the ecsmgr(1M) reference page for details. |
The unique name of the correlation. You cannot change the name. Correlation names are derived from the correlation files available.
A short description of the correlation. A more complete description of
the correlation is displayed when you click
[Describe...].
To enable one or more correlations, select them from the list and click
[Enable]. A check mark is displayed in the
Status column next to the enabled correlations.
If the correlation you want to select is not displayed, click
[Update View] to refresh the list. Updates made
by other users, and updates made from the command line, are not reflected
in the list of correlations until you click [Update View].
If the correlation cannot be enabled you will see an error message in the status bar, at the bottom of the window.
To disable a correlation, select one or more correlations from the list and
click [Disable]. The check mark in the Status
column next to the selected correlations is removed if they are
successfully disabled.
If the correlation cannot be disabled you will see an error message in the status bar, at the bottom of the window.
A short description of the correlation is displayed in the Description
column in the list of correlations. A more complete description is
available by clicking [Describe...]. The Description
window also lists all the streams in which this correlation is currently
enabled.
Correlations may have parameters that you can set to control the correlation. If a correlation has parameters, they can be set either before you enable a correlation or while it is in operation.
To modify a correlation, select the correlation you want to modify and click
[Modify...].
Caution: If you modify static parameters while the correlation is enabled, then when the changes are applied the correlation is disabled and re-enabled, causing the flow of events to become uncorrelated for a brief time.
Click [Update View] to refresh the list display.
Updates made by other users, via the Event Correlation interface
or ecsmgr(1M), are reflected
in the list of correlations when you click [Update View].
There may be a pause while information is retrieved from the correlation engine.
The status bar at the bottom of the window displays messages indicating success or failure. If an action does not complete as you expect, look in the status bar for an indication of what went wrong. The status bar is cleared on the next mouse click or keystroke.
The Correlation Description window is displayed when you select
a correlation and click [Describe...] in the
Event Correlation Configuration window. This window displays a detailed
description of the correlation and a list of the
streams in which the correlation is currently enabled.
The name of the correlation shown at the top of the window and is the same as the file name, without the extension. You cannot change the name.
A detailed description of the correlation is shown beneath the correlation name. You cannot change the description.
A list of the streams in which this correlation is enabled. Use the Event Correlation Configuration window to enable and disable correlations, and to select streams.
The Modify Correlation window is displayed when you select a
correlation and click [Modify...] on the
Event Correlation Configuration window. Use the Modify Correlation window
to display a list of the parameters for the
selected correlation and their current value. You can also select a
parameter to view in detail, or to modify the parameter value.
The name of the currently selected correlation is shown above the list. To
display parameters for a different correlation, close this window, select the
correlation on the Event Correlation Configuration window and click
[Modify...].
The list shows all of the parameters for the current correlation. To display
details of a particular parameter, or to change its current value,
select the parameter and click [View/Modify...].
If there are more parameters than can be displayed at once, scroll the list or resize the window.
The columns in the Modify Correlation window are:
The Name column shows the name of each parameter. Parameter names are fixed and cannot be changed.
The Current Value column shows the value assigned to this parameter. You can
modify parameter values by selecting the parameter and clicking
[View/Modify...]. If your management system supports
multiple streams, note that the parameter value is the same in all streams.
A check mark is displayed in this column if the parameter has
been modified. You can modify several parameters before clicking
on [Apply] to commit the changes together.
This column shows whether the parameter is static or dynamic.
The Description column shows a brief description of the parameter.
To see a more detailed description, select the parameter and click
[View/Modify...].
To display a detailed description of the parameter, or to change its
current value, select the parameter and click
[View/Modify...]. The Modify Parameter window is displayed.
Applies outstanding modifications and then closes the Modify Correlation window.
If modifications have been made to a correlation's parameters, clicking
[Apply] causes all the modifications to be applied.
The Modify Simple Parameter window is displayed when you select a parameter
and click [View/Modify...] on the
Modify Correlation window. Use this window to display the
current value of a selected
parameter, any preset limits, and the parameter's default value. You can
modify the parameter's current value, but the modified value is not
applied until you close the Modify Simple Parameter window and click
[Apply].
Some parameters consist of a choice from a selection of discrete values. For example, Boolean data types show a choice of True or False. Where a list of values is displayed, you must select a value from the list.
The name uniquely identifies the currently selected parameter. You cannot change the name.
The data type of the currently selected parameter. You cannot change the type. See ECS Data Types for details.
The minimum value that the currently selected parameter can be set to. You cannot change the minimum value.
This setting applies only to some scalar values. The current value is
checked when you click [Close] to ensure that it is
equal to or greater than the minimum value.
The maximum value that the currently selected parameter can be set to. You cannot change the maximum value.
This setting applies only to some scalar values. The current value is
checked when you click [Close] to ensure that it is equal to
or less than the maximum value.
The current value of the selected parameter. You can change the current value within the following restrictions:
The current value is checked against these restrictions when you
click [Close]. If the value does not conform then
an error message is displayed and you must correct it or cancel the change.
The default value of the selected parameter. You cannot change the default value.
The current value is set to the default value when you click
[Use Default].
Use the default value if you are unsure of a setting, and as a guide to the
syntax and data type.
A detailed description of the selected parameter. You cannot change the description.
The description should help you to enter an appropriate value for this parameter.
Saves any modifications made to this parameter value. Although the
modification is saved it is not applied to the correlation until you click
[Apply] on the Modify Correlation window.
This allows you to modify several parameters and then apply all the
modifications together.
Sets the Current Value equal to the Default Value. The modification must be
saved by clicking [Close] and then applied by clicking
[Apply],
just like any other modification to the Current Value.
The Modify Table Parameter window is displayed when you select a
table parameter (indicated by a Current Value of ...), and
click [View/Modify...] on the
Parameters window.
Modified values are not applied until you close this window
(by clicking [Close]) and click [Apply].
The name of the table parameter selected from the Parameter List. You cannot change the Name.
The ECS data type. You cannot change the type.
Tables are arranged in rows and columns. Columns are predefined for a given table. However, you can add and delete rows by clicking on the appropriate button, and you can modify the value of a selected row by clicking in the table cell you want to change and then clicking a second time to enter text insert mode.
The columns in the table are specific to the correlation parameter. Click in a cell and read the Description to understand the type of value required.
The Description displays the data type, default value, minimum value, maximum value, and descriptive text for the current table cell. To see the description for a cell, click in it.
Adds a new row to the bottom of the table. Note that you cannot insert a row in the middle of a table. The order of rows in a table does not affect processing.
Deletes the row containing the current cell from the table. You
cannot undo a deletion. If you mistakenly delete a row you can click
[Reset] to abandon all changes to the table,
and then start again.
Click [Verify Table] to check the table contents.
There are three stages to the verification:
[Verify Table] again.
Step 2, above, checks each cell's value against the minimum and maximum, its data type, and its syntax. This step is performed on the server, so if the server is busy there can be a delay before the results are displayed. If the server is very busy it may appear that the verification has failed to complete. Wait until the server completes the verification.
Verifies the table (as if you had clicked
[Verify Table]) and, if the verification is successful,
closes the Modify Table Parameter window. Changes made to the table
are remembered but are not applied until you click [Apply]
on the Modify Correlation window.
Removes the modifications that you have made this parameter value and closes the window.
When you modify a parameter's current value you must enter values that conform with the parameter's data type. Following is a summary of ECS data types:
| Type | Description | Range | Examples |
|---|---|---|---|
| Integer | Whole numbers. Note that 123 is an Integer but 123.0 is a Real. | ±2,147,483,647 | 21 |
| Real | Decimal values. Note that 123.0 is a Real but 123 is an Integer. | From -2.2250738585072014E308 to 1.7976931348623157E308. The smallest exponent is -308. | 1.0 |
| Boolean | True or false. Case is not important. | Must be either True or False. | True |
| Duration | Elapsed time expressed in hours, minutes and/or seconds. Compare this with Time. | ±596,523 Hours (±68 years). Resolution is 1 microsecond. | 13.5h |
| Time | Absolute time expressed in years, months, days, hours, minutes and seconds, in the form yyyymmddhhiiss.uuuuuuZ. The trailing Z distinguishes time values from reals. | 1 January 1970 to the year 2038. Resolution is 1 microsecond. | January 3, 1997 at 1:59:59.1234PM (UTC) would be represented as
19970103135959.1234Z |
| Oid | MIB Object Identifier | An Oid value must contain at least two dots to distinguish it from a real. | 1.43.67.52 |
| String | Text surrounded by double-quotes. | Strings can be any size from empty "" to the required length. Strings are Unicode and can contain any character values. | "Melbourne" |
| Token | Tokens are discrete names. | You must select from predefined token values. See the correlation description for details. | High |
| Tuple | A data structure consisting of a fixed collection of elements enclosed in parentheses and separated by commas. | A Tuple can contain one or more elements of any data type. See the correlation description for details. | A Tuple consisting of an Integer, a Real, and a String:
(1, 1.0, "One") |
| List | An ordered set of values enclosed in square brackets and separated by commas. | A list can contain any number of elements including none []. | A list of three Reals [1.23, 4.56, 3.17] |