How to notify only red incidents.

Unanswered Question
amritpatek Fri, 12/19/2008 - 07:25

Here is how you set a filter so only red incidents will show in your query:

In the Query/Reports page, you will see a shaded 'Query Type' area where you can define the criteria for your query. There are several columns here. The 4th column is called 'Events' and should have the word 'Any' under it. Click the word 'Any' in the 'Events' column to change it.

In the page that follows, you will see a field labeled 'Restrict to Severity'. Change this to 'RED' and hit 'Apply'. You can define what specific red events to show on this page, or you can change other query criteria to further filter your results.

richardackroyd Thu, 04/02/2009 - 08:31

Unfortunately that doesnt work. That will alert you on a Red event, not Red Incidents.

Unfortunately, this is an absolutely MASSIVE flaw in Cisco MARS. There are some hacks relating to duplication of rules but they can cause more problems of their own.

You will need to bug Cisco for this functionality I think.


This Discussion