Concepts Event Correlation

Event correlation modifies the flow of events by:

Event correlation can dramatically reduce the number of alarms displayed in your Alarm Browser. Instead of the event storms typically generated by equipment and link failures, a correlated event stream displays fewer, more meaningful events, resulting in faster and easier identification of network problems.


Concepts Correlation Editions

NNM includes three Bundled Edition correlations. No additional license or software is required to use these correlations.

The Bundled Edition correlations include:

There are three additional sources for correlations that can run in NNM:

See Also


Concepts Products

You can use the Bundled Edition Correlations and Contributed Edition Correlations without purchasing any additional licenses or software. However, to use Extended Edition Correlations and Designer Edition Correlations you must purchase either or both of the following:

Correlations are platform independent, so you need only one ECS Designer, regardless of the number and type of correlations to be developed.


Concepts How You Control Correlation

When NNM is first started (using ovstart), the supplied correlations are enabled. Do not disable these correlations without first reading the descriptions of the individual correlations.

Some correlations are controlled by changing parameter values to adapt the correlation to your network environment. Use the built-in descriptions to learn about parameters of a correlation, and about the effects of enabling and disabling correlations.

By default, all events flow through NNM in a single stream called the default stream. If your network administrator has created additional streams then you will be able to selectively enable and disable correlations on those streams as well.

Streams are created outside of the Event Correlation interface using the ecsmgr(1M) command line interface.


Concepts Configuring Correlations

A correlation may be configured by assigning specific values to its parameters. Only some correlations have parameters.

Correlation parameters allow you to control things like acceptable network delays, minimum and maximum event counts, and specific object identifiers. Some parameters have a default value. Many parameters also have limits to ensure that they are set to reasonable values. Provided that values remain within any specified limits, you can modify them as and when required, even while a correlation is enabled.


Concepts Static and Dynamic Parameters

Correlation parameters are classified as either static or dynamic, depending on whether the parameter can be changed while the correlation is enabled.

If a static parameter is changed while a correlation is enabled, when the change is applied correlation is disrupted because the correlation must be disabled and reloaded. On the other hand, changes to dynamic parameters take effect "dynamically" as soon as they are applied, without disrupting the enabled correlation.

If you apply a mixture of changes (some static and some dynamic), the correlation is reloaded only if one or more of the parameters is static.


Concepts Enabling and Disabling Correlations

After correlation is enabled, there is usually a delay (up to several minutes) as the correlation fills its memory tables with events. This delay is called the settling time. Correlation is effective only after the settling time has elapsed. The parameter descriptions indicate if and how each setting affects the settling time.


Concepts Recommendations

To minimize disruption to the correlation service and to assist other network administrators it is suggested that you:


Concepts Event Correlation Configuration Window

You can display the Event Correlation Configuration window using the following methods.

Use the Event Correlation Configuration window to manage correlations on a selected stream.

Select a Stream

Select a correlation stream from the drop-down list.

Usually, there is only one stream called "default", in which case there is no need to explicitly select a stream. However, if multiple streams have been implemented you must select the stream you want to work with before enabling or disabling correlations.

Select the Stream

Changing parameter values affects the operation of the correlation in all streams in which that correlation is enabled. Consequently, there is no need to select the stream before changing parameter values.

Status

The Status column shows a check mark and the word Enabled if the correlation is enabled. Correlations that are not enabled have a blank Status and the word Disabled. These are the only two status values that can be set from the Event Correlation interface. However, the ecsmgr(1M) command line utility can be used to assign other status values to a correlation.

The complete set of Status values is:
Enabled The correlation has both its input and its output enabled. This is the normal state for most correlations.
Disabled The correlation has both its input and its output disabled. The correlation has no effect.
Input Enabled The correlation accepts events at its input, correlates them, but does not output any events. This mode is sometimes used to overcome settling time problems. See the ecsmgr(1M) reference page for details.
Output Enabled Allows the correlation to continue outputting events (stored or generated by the correlation) while preventing new events from entering. See the ecsmgr(1M) reference page for details.

Name

The unique name of the correlation. You cannot change the name. Correlation names are derived from the correlation files available.

Description

A short description of the correlation. A more complete description of the correlation is displayed when you click [Describe...].

[Enable]

To enable one or more correlations, select them from the list and click [Enable]. A check mark is displayed in the Status column next to the enabled correlations.

If the correlation you want to select is not displayed, click [Update View] to refresh the list. Updates made by other users, and updates made from the command line, are not reflected in the list of correlations until you click [Update View].

If the correlation cannot be enabled you will see an error message in the status bar, at the bottom of the window.

[Disable]

To disable a correlation, select one or more correlations from the list and click [Disable]. The check mark in the Status column next to the selected correlations is removed if they are successfully disabled.

If the correlation cannot be disabled you will see an error message in the status bar, at the bottom of the window.

[Describe...]

A short description of the correlation is displayed in the Description column in the list of correlations. A more complete description is available by clicking [Describe...]. The Description window also lists all the streams in which this correlation is currently enabled.

[Modify...]

Correlations may have parameters that you can set to control the correlation. If a correlation has parameters, they can be set either before you enable a correlation or while it is in operation.

To modify a correlation, select the correlation you want to modify and click [Modify...].

Caution: If you modify static parameters while the correlation is enabled, then when the changes are applied the correlation is disabled and re-enabled, causing the flow of events to become uncorrelated for a brief time.

See Also

[Update View]

Click [Update View] to refresh the list display. Updates made by other users, via the Event Correlation interface or ecsmgr(1M), are reflected in the list of correlations when you click [Update View].

There may be a pause while information is retrieved from the correlation engine.

Status Bar

The status bar at the bottom of the window displays messages indicating success or failure. If an action does not complete as you expect, look in the status bar for an indication of what went wrong. The status bar is cleared on the next mouse click or keystroke.


Concepts Correlation Description Window

The Correlation Description window is displayed when you select a correlation and click [Describe...] in the Event Correlation Configuration window. This window displays a detailed description of the correlation and a list of the streams in which the correlation is currently enabled.

Selected Correlation

The name of the correlation shown at the top of the window and is the same as the file name, without the extension. You cannot change the name.

Description

A detailed description of the correlation is shown beneath the correlation name. You cannot change the description.

Enabled in Streams

A list of the streams in which this correlation is enabled. Use the Event Correlation Configuration window to enable and disable correlations, and to select streams.


Concepts Modify Correlation Window

The Modify Correlation window is displayed when you select a correlation and click [Modify...] on the Event Correlation Configuration window. Use the Modify Correlation window to display a list of the parameters for the selected correlation and their current value. You can also select a parameter to view in detail, or to modify the parameter value.

Selected Correlation

The name of the currently selected correlation is shown above the list. To display parameters for a different correlation, close this window, select the correlation on the Event Correlation Configuration window and click [Modify...].

List of Parameters

The list shows all of the parameters for the current correlation. To display details of a particular parameter, or to change its current value, select the parameter and click [View/Modify...].

If there are more parameters than can be displayed at once, scroll the list or resize the window.

The columns in the Modify Correlation window are:

Name

The Name column shows the name of each parameter. Parameter names are fixed and cannot be changed.

Current Value

The Current Value column shows the value assigned to this parameter. You can modify parameter values by selecting the parameter and clicking [View/Modify...]. If your management system supports multiple streams, note that the parameter value is the same in all streams.

Modified

A check mark is displayed in this column if the parameter has been modified. You can modify several parameters before clicking on [Apply] to commit the changes together.

Update

This column shows whether the parameter is static or dynamic.

Description

The Description column shows a brief description of the parameter. To see a more detailed description, select the parameter and click [View/Modify...].

[View/Modify...]

To display a detailed description of the parameter, or to change its current value, select the parameter and click [View/Modify...]. The Modify Parameter window is displayed.

[OK]

Applies outstanding modifications and then closes the Modify Correlation window.

[Apply]

If modifications have been made to a correlation's parameters, clicking [Apply] causes all the modifications to be applied.

See Also
Static and Dynamic Parameters

Concepts Modify Simple Parameter Window

The Modify Simple Parameter window is displayed when you select a parameter and click [View/Modify...] on the Modify Correlation window. Use this window to display the current value of a selected parameter, any preset limits, and the parameter's default value. You can modify the parameter's current value, but the modified value is not applied until you close the Modify Simple Parameter window and click [Apply].

Some parameters consist of a choice from a selection of discrete values. For example, Boolean data types show a choice of True or False. Where a list of values is displayed, you must select a value from the list.

Name

The name uniquely identifies the currently selected parameter. You cannot change the name.

Type

The data type of the currently selected parameter. You cannot change the type. See ECS Data Types for details.

MinValue

The minimum value that the currently selected parameter can be set to. You cannot change the minimum value.

This setting applies only to some scalar values. The current value is checked when you click [Close] to ensure that it is equal to or greater than the minimum value.

Max Value

The maximum value that the currently selected parameter can be set to. You cannot change the maximum value.

This setting applies only to some scalar values. The current value is checked when you click [Close] to ensure that it is equal to or less than the maximum value.

Current Value

The current value of the selected parameter. You can change the current value within the following restrictions:

The current value is checked against these restrictions when you click [Close]. If the value does not conform then an error message is displayed and you must correct it or cancel the change.

Default Value

The default value of the selected parameter. You cannot change the default value.

The current value is set to the default value when you click [Use Default]. Use the default value if you are unsure of a setting, and as a guide to the syntax and data type.

Description

A detailed description of the selected parameter. You cannot change the description.

The description should help you to enter an appropriate value for this parameter.

[Close]

Saves any modifications made to this parameter value. Although the modification is saved it is not applied to the correlation until you click [Apply] on the Modify Correlation window. This allows you to modify several parameters and then apply all the modifications together.

[Reset]

Removes any modifications made to this parameter value and closes the window.

[Use Default]

Sets the Current Value equal to the Default Value. The modification must be saved by clicking [Close] and then applied by clicking [Apply], just like any other modification to the Current Value.


Concepts Modify Table Parameter Window

The Modify Table Parameter window is displayed when you select a table parameter (indicated by a Current Value of ...), and click [View/Modify...] on the Parameters window. Modified values are not applied until you close this window (by clicking [Close]) and click [Apply].

Name

The name of the table parameter selected from the Parameter List. You cannot change the Name.

Type

The ECS data type. You cannot change the type.

Table Values

Tables are arranged in rows and columns. Columns are predefined for a given table. However, you can add and delete rows by clicking on the appropriate button, and you can modify the value of a selected row by clicking in the table cell you want to change and then clicking a second time to enter text insert mode.

The columns in the table are specific to the correlation parameter. Click in a cell and read the Description to understand the type of value required.

Description

The Description displays the data type, default value, minimum value, maximum value, and descriptive text for the current table cell. To see the description for a cell, click in it.

[Add Row]

Adds a new row to the bottom of the table. Note that you cannot insert a row in the middle of a table. The order of rows in a table does not affect processing.

[Delete Row]

Deletes the row containing the current cell from the table. You cannot undo a deletion. If you mistakenly delete a row you can click [Reset] to abandon all changes to the table, and then start again.

[Verify Table]

Click [Verify Table] to check the table contents. There are three stages to the verification:

  1. Verifies that all table cells are complete. A message is displayed if one or more empty cells are found, and the cells are highlighted in the table. Enter values in the highlighted cells and click [Verify Table] again.
  2. Verifies each cell's value. If there are errors or possible errors, a list of errors and warnings is displayed. Correct the errors by clicking in the cell corresponding to each error. Cells are indicated by column and row, starting with (0,0) which is the cell at the top left corner of the table.
  3. Verifies that the table's key values are unique. Each row has one or more columns that make up the key value for that row (key headings have a yellow background). Each row's key value must be unique. For example, the following table has a key comprised of two columns: Hostname and Start Time. To verify successfully, each row in the table must have a unique combination of Hostname and Start Time. The example will not verify because the first two rows have the same key value:

Step 2, above, checks each cell's value against the minimum and maximum, its data type, and its syntax. This step is performed on the server, so if the server is busy there can be a delay before the results are displayed. If the server is very busy it may appear that the verification has failed to complete. Wait until the server completes the verification.

[Close]

Verifies the table (as if you had clicked [Verify Table]) and, if the verification is successful, closes the Modify Table Parameter window. Changes made to the table are remembered but are not applied until you click [Apply] on the Modify Correlation window.

[Reset]

Removes the modifications that you have made this parameter value and closes the window.

ECS Data Types

When you modify a parameter's current value you must enter values that conform with the parameter's data type. Following is a summary of ECS data types:

Type Description Range Examples
Integer Whole numbers. Note that 123 is an Integer but 123.0 is a Real. ±2,147,483,647 21
+47
-4768
Real Decimal values. Note that 123.0 is a Real but 123 is an Integer. From -2.2250738585072014E308 to 1.7976931348623157E308. The smallest exponent is -308. 1.0
-269.3
2.34E-7
Boolean True or false. Case is not important. Must be either True or False. True
False
Duration Elapsed time expressed in hours, minutes and/or seconds. Compare this with Time. ±596,523 Hours (±68 years). Resolution is 1 microsecond. 13.5h
13h30m
44s
12345.678s
Time Absolute time expressed in years, months, days, hours, minutes and seconds, in the form yyyymmddhhiiss.uuuuuuZ. The trailing Z distinguishes time values from reals. 1 January 1970 to the year 2038. Resolution is 1 microsecond. January 3, 1997 at 1:59:59.1234PM (UTC) would be represented as 19970103135959.1234Z
Oid MIB Object Identifier An Oid value must contain at least two dots to distinguish it from a real. 1.43.67.52
1.2.17.9.23.156
String Text surrounded by double-quotes. Strings can be any size from empty "" to the required length. Strings are Unicode and can contain any character values. "Melbourne"
"Böblingen"
""
Token Tokens are discrete names. You must select from predefined token values. See the correlation description for details. High
Medium
Low
Tuple A data structure consisting of a fixed collection of elements enclosed in parentheses and separated by commas. A Tuple can contain one or more elements of any data type. See the correlation description for details. A Tuple consisting of an Integer, a Real, and a String: (1, 1.0, "One")
List An ordered set of values enclosed in square brackets and separated by commas. A list can contain any number of elements including none []. A list of three Reals [1.23, 4.56, 3.17]