cancel
Showing results for 
Search instead for 
Did you mean: 

Custom Alarm Email Notification

Custom Alarm Email Notification

Michael_M
New Contributor II

I have created an alarm configuration to send me an email if a switch experiences a SpanGuard event the locks out a port on my EOS switches.

I have the alarm definition setup as follows:
2022-10-28 13_28_08-Alarm Configuration - Extreme Networks — Mozilla Firefox.png

The email comes through fine, but I get 3 copies of one email and a single copy of another email with the same alert.  You can see the Information column below is the email I see and the "Seen Count" is the number of emails that are sent to me.
2022_10_28_13_29_51_Alarms_Extreme_Networks_Mozilla_Firefox.png

I have gotten the second alarm to only send me a single email by setting up the Alarm Suppression rule in the Actions tab of the rule creation window
2022-10-28 13_32_42-Alarm Configuration - Extreme Networks — Mozilla Firefox.png

I still get the top alarm emailed to me though and I cant figure out how to eliminate multiple emails from being sent. 
I also feel there is probably a better way to filter the rule so that the second alert isnt "seen" 3 times.
I have tried altering the Match On: Log: criteria field to include or exclue Syslog and the other, but have not found anything that works.  Its almost like XIQ-SE is getting 4 syslog events evertime I reproduce the issue.

Thanks for any guidance.

6 REPLIES 6

Can you confirm:

  • There is one syslog message from a switch and you get number of emails based on the "Seen count"
  • What is the version of ExtremeCloud IQ - Site Engine

What you can try is to get rid of those special characters ":" and "=" in the alarm condition

Regards Zdeněk Pala

Thorp6
New Contributor II

Regardless, it's exquisite information. Investigating from gifted music makers is a really fulfilling experience regardless considering the way that they have staff to help with heaps of assessment, changing, etc.


@Michael_M Panorama Charter Login wrote:

I have created an alarm configuration to send me an email if a switch experiences a SpanGuard event the locks out a port on my EOS switches.

I have the alarm definition setup as follows:
2022-10-28 13_28_08-Alarm Configuration - Extreme Networks — Mozilla Firefox.png

The email comes through fine, but I get 3 copies of one email and a single copy of another email with the same alert.  You can see the Information column below is the email I see and the "Seen Count" is the number of emails that are sent to me.
2022_10_28_13_29_51_Alarms_Extreme_Networks_Mozilla_Firefox.png

I have gotten the second alarm to only send me a single email by setting up the Alarm Suppression rule in the Actions tab of the rule creation window
2022-10-28 13_32_42-Alarm Configuration - Extreme Networks — Mozilla Firefox.png

I still get the top alarm emailed to me though and I cant figure out how to eliminate multiple emails from being sent. 
I also feel there is probably a better way to filter the rule so that the second alert isnt "seen" 3 times.
I have tried altering the Match On: Log: criteria field to include or exclue Syslog and the other, but have not found anything that works.  Its almost like XIQ-SE is getting 4 syslog events evertime I reproduce the issue.

Thanks for any guidance.


 

GTM-P2G8KFN