Event Correlation Configuration Tasks

Use the Event Correlation interface to perform the event correlation configuration tasks. You can access the Event Correlation Configuration window in different ways:

Click on one of the following tasks for the procedure to accomplish that task.


Tasks Displaying the Correlation Description

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

The Description window is displayed when you select a correlation and click [Describe...] on the Event Correlation Configuration window. This window displays a detailed description of the selected correlation and a list of the streams in which it is currently enabled.

Click [Close] to close the Description window.

See Also

Tasks Displaying Correlation Parameters

The behavior of a correlation is controlled by its parameter settings. Each correlation has its own set of parameters. You can display a summary of the correlation parameters and their current values by selecting a correlation from the Event Correlation Configuration window and clicking [Modify...]. This displays the Modifying Correlation window, from which you can modify parameter values, and then apply the parameter changes.

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

If necessary, select the stream. Generally, the stream called "default" is the only available stream, and it will already be selected.

From the Event Correlation Configuration window, select the correlation whose parameters you want to display and click [Parameters...] to display current parameter settings for the selected correlation.

The Modify Correlation window lists all the parameters for the selected correlation. From here, parameters can be selected and viewed or modified. After modifying one or more correlation parameters you can apply all the changes.

See Also

Tasks Modifying Parameter Values

Parameter values for a correlation can be modified at any time. However, if a parameter value is modified while a correlation is enabled then correlation may be disrupted while the parameter value is changed. There are two types of parameters: Static and Dynamic. Both types can be modified while a correlation is enabled.

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

To modify a correlation parameter:

  1. If necessary, select the stream. Generally, the stream called "default" is the only available stream, and it will already be selected.

  2. Select the correlation whose parameters you want to modify.

  3. Click [Modify...] to display current parameter settings for the selected correlation.

  4. Select the parameter you want to change and click [View/Modify...]. The Modify Parameter window is displayed. There are three different Modify Parameter windows. The one displayed depends on the parameter's data type:

    Table Parameters

    Displays a table of values when you click on [Modify...]. You can add, edit and delete table entries as follows:

    • Click in the cell you want to change, press the F2 key to select insert mode, modify the value, and press the Tab or Enter key to commit the change. Use the syntax appropriate to the data type, as described in Data Types.
    • Click [Add Row] to add a new row to the table. New rows are always added to the end of the table and cannot be added to the start or middle.
    • Click [Delete Row] to delete the row in which the cursor is located.
    Choice Parameters

    For discrete parameter values the Current Value on the Modify window has a drop-down list from which you choose a value. To change the value:

    • Click on the arrow and select one of the values displayed, OR
    • Click [Use Default] to select the default value.
    Free Form Parameters

    All other data types (text, numbers, tuples, etc.) are entered as free form text. Use the syntax appropriate to the data type, as described in Data Types.

    • Type the value, with syntax corresponding to the data type, OR
    • If a default value is specified, click [Use Default] to select it.

  5. Click [OK] to save the modification. Alternatively, click [Cancel] to abandon this modification. The Parameter List is displayed again. Note that the modifications are not applied until you click [Apply] on the Modifying Correlation window.

    Repeat the steps above to change any other parameters. You should try to make parameter changes in batches, rather than applying each change individually. That way, the correlation is moved from one valid state to another valid state, avoiding inconsistent intermediate states.

    Only some parameters have a default value. In addition, table parameters do not have a [Use Default] button. Instead, new rows are always added with the default values (if any).

  6. Click [Apply] on the Modifying Correlation window to commit all the changes.

    To abandon all the changes, click [Cancel] instead of [Apply].

    Changes to static parameters are applied by disabling and re-enabling the correlation. If you have modified a static parameter a warning message is displayed when you apply the change to an enabled correlation. Click [OK] to proceed or [Cancel] to abandon the modifications.

See Also

Tasks Applying Parameter Changes

Changes take effect only when you apply them. This means that you can modify several parameters before applying the changes. When you apply the changes they all take effect at once, with the following advantages:

Allow time for changes to static parameter values to take effect. When a static parameter in an enabled correlation is modified and then applied, the correlation is disabled and then re-enabled with the new parameter values. This takes a finite amount of time during which events are passed through "uncorrelated". After correlation is re-enabled it may still require some settling time before the correlation's internal tables fill and it can begin correlating events.

See Also

Tasks Enabling a Correlation

A correlation can be enabled in one or more streams. Before enabling a correlation, make sure that its parameters have been set.

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

To enable a correlation:

  1. If necessary, select the stream. Generally, the stream called "default" is the only available stream, and it will already be selected.

  2. Select the correlations you want to enable. To select more than one correlation, hold down the Ctrl key as you click on the names of additional correlations.

  3. Click [Enable] to enable all the selected correlations.

If the correlation you want to select is not displayed, click [Update View] to refresh the list. Updates made by other users, and updates made from the command line, are not reflected in the list of correlations until you click [Update View].

See Also

Tasks Disabling a Correlation

Disabling a correlation stops it from modifying the flow of events. Disable a correlation whenever you want to remove the effect of the correlation from the selected stream of events.

Caution: Generally, there is no need to disable the Bundled Edition correlations. If you think it is desirable to disable correlations, refer to the Description of the correlation before doing so. Some of the Contributed Edition Correlations interact with other parts of NNM and disabling the correlation will interfere with the normal operation of NNM.

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

To disable one or more correlations:

  1. If necessary, select the stream. Generally, the stream called "default" is the only available stream, and it will already be selected.

  2. Select the correlations you want to disable. To select more than one correlation, hold down the Ctrl key as you click on the names of additional correlations.

  3. Click [Disable] to disable all the selected correlations.

The disabled correlation can be re-enabled at any time.

Note that it is not necessary to disable a correlation before modifying its parameters.

See Also

Tasks Selecting the Stream

Normally, you will have just one stream of events called "default". In this case you can ignore the subject of streams. The "default" event stream is always selected and you cannot change it. However, if your system is configured for multiple event streams then you must select the appropriate stream before enabling or disabling correlations.

Click accessing the Event Correlation interface for information on how to display the Event Correlation Configuration window.

Select the stream from the list displayed in the Streams drop-down list. You can select only one stream at a time.

Once a stream has been selected you can enable or disable correlations in that stream only, until you select another stream.

The list of correlations remains the same in all streams; only the status of the correlations changes for each stream.

The stream setting is not important when modifying parameter values. Parameter values for a correlation are the same in all the streams in which that correlation is enabled.

See Also

Tasks Adding New Correlations

NNM is supplied with a set of Bundled Edition Correlations that you can modify. Contributed, Extended, and Designer Edition Correlations are available from Hewlett-Packard and other sources.

These correlations must be set up before they will appear in the list of available correlations.

To set up Contributed, Extended, and Designer Edition Correlations:

  1. Copy the set of files for that correlation into \OpenView\conf\ecs\circuits\ on the Windows NT operating system or $OV_CONF/ecs/circuits/ on a UNIX system.
  2. Click [Update View] in the Event Correlation Configuration window. The new correlation appears in the list of correlations.
  3. If the correlation is an Extended or Designer Edition Correlation, then you must install the optional HP OpenView NNM ECS Extensible License to Use before the correlation can be enabled.

Once a correlation been set up in this way you can display its parameters, modify them, and then enable it.

See Also

Tasks Correlation Files

Each correlation is provided as a set of files. The files have the following names:

File Name Description
correlation.eco Compiled correlation
correlation.ds Data Store
correlation.fs Fact Store (optional)
correlation.param Parameter definitions

Where correlation is the name of the correlation, as it appears in the Event Correlation Configuration window.

All these files should be located in: