Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Agility
      • Kanban workshop
      • Agile Fundamentals
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • OSS/BSS
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
      • About the DevOps Program
      • DataMiner DevOps Support
  • Downloads
  • More
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
    • Global Feedback Survey
  • Support
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Solutions
    • Deal Registration
  • >> Go to dataminer.services

Correlation rule to combine event ID’s associated with a unique condition.

80 views4 days ago
0
Ken O'Connor546 13th June 2025 0 Comments

I need to create a correlation rule that generates a correlated alarm within five mins when two alarm ID's are generated

I have a filter using Reg Ex .*(11111|22222).*). This will trap the alarms required. (i.e. when I use that filter in the alarm console, all alarms requeired are shown in the 5 minute time span)

11111 and 22222 represent the two alarm ID's. Alarm ID 11111 is generated once (or twice) but definitely always once and alarm ID 22222 is generated between 200 and 500 times in 5 mins.

The correlated alarm must generate only when both of these alarm IDs are generated together in the space of a 5 minute period (regardless of how many 22222 alarms are generated). I have tried several methods but the correlated alarm always seems to trigger with either or one of the alarms ID's but not both.

What would be the best approach for implementing this. The alarms are generated from different elements. We need to combine these properly so that the condition is captured. Sometimes, we get multilpe alarms from 22222 showing without alarm ID 11111. That is not what I want. The correlated alarm must generate when both of these alarms are generated only.

To note: Both alarms are generated from different elements but using the same protocol suite

Mieke Dryepondt [SLC] [DevOps Advocate] Answered question 4 days ago

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
0
Mieke Dryepondt [SLC] [DevOps Advocate]3.68K Posted 4 days ago 1 Comment

Hi,

I believe we have the same need in one of our internal detection flows.
Below you can find an example of memory leak detection based on 2 param going in alarm for a specific protocol. (in this example it's the same protocol, but you can configure the protocols you need)

In the rule-condition you should be able to indicate the 5min persistent.
I hope this is of help.

Ken O'Connor [DevOps Member] Edited comment 2 days ago
Ken O'Connor [DevOps Member] commented 2 days ago

Thanks @Mieke Ill mess around with this an let you know how it goes

Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs

[ Placeholder content for popup link ] WordPress Download Manager - Best Download Management Plugin