Dear dojo community,
we have an snmp manager with 'alarm storm prevention' enabled. The snmp manger is configured to handle minor/major events and that all works pretty nice.
Now I would like to detect when the alarm storm detection cicks in and create an extra 'critical' event that will than be signalled via a different snmp manager.
I therefore created a correlation rule that triggers on the information event that is posten when the alarm storm prevention kicks in. That works fine as well but the drawback here is that this correlated event never gets cleared and needs operator intervention to be cleared.
Is there any way one can trigger a clear based on the information event signalling end of alarm storm ??