Event Correlation
In Skylar One, there are four types of events that might not appear on the Events page (or the Event Console page in the classic Skylar One user interface):
- Rolled-up events. Multiple occurrences of the same event on the same device. When the same event occurs multiple times on a single device, Skylar One does not display each occurrence on the Events page. Instead, Skylar One displays a single entry and notes the number of occurrences in the Count column.
- Suppressed Events. Suppressed events do not appear on the Events page. For details on suppressing events for a single device, see the section on Suppressing Events.
- Topology Events. In Skylar One, event correlation or topology suppression means the ability to build parent-child relationships between devices and between events. When events are correlated, only the parent event is displayed on the Events page. The magnifying-glass icon (
) appears to the left of the parent event. When you click on the magnifying-glass icon, the list of child events is displayed. The child events are rolled up under the parent event and are not displayed on the Events page. For the parent event, the count column increases to indicate the number of correlated child events. Optionally, you can define event categories that allow Skylar One to more efficiently align suppressing events with suppressible events. When you align an event category to a suppressing or suppressible event, that event is correlated with only events that are aligned with the same event category. - Event Masks. When a device uses the Event Mask setting, events that occur on a single device within a specified span of time are grouped together. On the Events page, masked events are displayed under a single event, the one with the highest severity. For details on event masks, see the section on Event Masks.
Skylar One performs two types of event correlation:
- Automatic Event Correlation. During discovery, Skylar One automatically discovers and defines parent-child relationships between devices based on Layer-2, Cisco Discovery Protocol (CDP), Link Layer Discovery Protocol (LLDP), Layer-3, and legacy VMware topology or data collected from Dynamic Applications.
- Manual Event Correlation. In Skylar One, you can configure devices and events so that events that are associated with child devices are rolled up under the parent device's events on the Events page (or the Event Console page in the classic Skylar One user interface). For example, suppose a switch fails. Instead of seeing an event for the failed switch and seeing events about failed communication for each device connected to the switch, only a single event would appear on the Events page (or the Event Console page in the classic Skylar One user interface). The single event would describe the switch failure. When you manually define a hierarchy between events, you can also include an event category. An event category allows Skylar One to more efficiently align suppressing events with suppressible events.
To manually define event correlation, you must perform two tasks:
- Define parent and child devices.
- Define a hierarchy between events—that is, define parent events (called suppressing events) and child events (called suppressible events).
Enabling a discovered device configured with CDP or LLDP topology in Skylar One causes the device to provide information on its neighbor. This information only identifies that there is a neighbor device, not which is the parent or the child. This might cause the parent-child relationship to switch, which requires you to manually reverse the issue within the Skylar One user interface. In Skylar One, you can manually build parent-child relationships between specific device categories. For more information, see Defining Parent and Child Devices.
Event Correlation Precedence
In some instances you might have multiple parent-child links between two devices. Skylar One displays only one of the relationships. Skylar One gives precedence to showing these relationships in the following order:
- Manually defined event correlation links
- Layer-3 links
- Link Layer Discovery Protocol (LLDP) links
- Cisco Discovery Protocol (CDP) links
- Layer-2 links
- Legacy VMware links
- Component relationship links
Additionally, any manually created, edited, or deleted links take precedence over the information discovered by Skylar One. The changes are propagated to discovery and event correlation.
Defining Parent and Child Devices
In Skylar One, you can create parent-and-child relationships and define event correlations. Skylar One creates parent and child devices automatically when:
-
Skylar One discovers Layer-2, Cisco Discovery Protocol (CDP), Link Layer Discovery Protocol (LLDP), Layer-3, and legacy VMware topology.
-
Skylar One performs collection for Dynamic Applications that create component devices or device relationships.
You can also manually define parent and child relationships between devices.
On the Device Children modal, you can select one or more devices to become children of the currently selected device.
To add children to a device:
-
Go to the Device Manager page (Devices > Classic Devices).
-
In the Device Manager page, select the wrench icon (
) for the device for which you want to add child devices. The Device Properties page appears. You cannot create parent-child relationships for devices with a device category of Virtual.
- In the Device Properties page, in the drop-down list, select Device Children. The Device Children modal appears.
- In the Device Children modal, select one or more devices to be children of the current device.
- Click .
Device Categories That Do Not Support Child Devices
A device category is a logical categorization of a device by primary function. Skylar One uses device categories to group related devices in reports and views.
Device categories are paired with device classes to organize and describe discovered devices. The device class usually describes the manufacturer and model of a device. The device category describes the function of the hardware.
Devices that are members of the following device categories cannot be assigned child devices:
- Office Printers, Device Category #4
- Workstations, Device Category #6
- Environmental.Utility, Device Category #8
- Environmental.HVAC, Device Category #9
- Environmental.Security, Device Category #10
- System.Tape, Device Category #17
- Office.Copiers, Device Category #22
- Office.Facsimiles, Device Category #23
- Telephony.Phone, Device Category #36
- Office.Plotter, Device Category #40
- Pingable, Device Category #98
- Virtual, Device Category #97
To determine a device's device category, look at the Category field on the Info drawer of the Device Investigator page.
Defining Event Topology Masking and Suppression
Topology masking, also referred to as topology suppression, is a setting that defines the rules that Skylar One uses to determine event correlation and suppression when events occur on devices that have a parent/child relationship.
In Skylar One, you can create parent-and-child relationships and define event correlations. Skylar One creates parent and child devices automatically when:
-
Skylar One discovers Layer-2, Cisco Discovery Protocol (CDP), Link Layer Discovery Protocol (LLDP), Layer-3, ARP, and legacy VMware topology.
-
Skylar One performs collection for Dynamic Applications that create component devices or device relationships.
You can also manually define parent and child relationships between devices.
For event correlation to occur, two types of event policies must be defined: masking events and maskable events.
- Masking events. If this type of event occurs on a parent device, Skylar One searches all related child devices for maskable events. On the child devices, all maskable events are masked. Only the masking event appears on the Events page; the maskable events are nested under the parent event.
- Maskable events. This type of event is masked on a child device only when a masking event occurs on the parent device.
The following options are available:
- Disabled: Events from this policy do not mask, or get masked, by topology.
- Mask events on child devices: If an event occurs from this policy on a parent device, Skylar One searches for all related child devices for maskable events. If a Category has been aligned to this policy, Skylar One refines the search to all child devices and masks all events that have been defined as maskable and assigned the same Category. If you have not assigned a Category to this policy, Skylar One refines the search to all child devices and masks all events that have been defined as maskable and are not assigned a Category.
- Maskable under a parent device’s event: If an event occurs from this policy on a child device, Skylar One masks this event by topology only when a masking event occurs on the parent device. If a Category has been aligned to this policy, Skylar One masks this event when it occurs on a child device and an event that has been defined as masking occurs on its parent device. The masking event must have the same Category as the maskable event. If a Category has not been aligned to this policy, when a masking event that is not assigned to a Category occurs on the parent device Skylar One searches all child devices and masks all events that have been defined as maskable and are not assigned to a Category.
- Both: If an event occurs from this policy on a parent device, it behaves as a masking event. If this event occurs on a child device, it behaves as a maskable event.
For more information about how to define an event as masking or maskable, see the section on The Event Message Tab.
Defining Event Topology Suppression in the Classic Skylar One User Interface
To manually configure event correlation in the classic Skylar One user interface, you must define two types of events:
- Suppressing events. If this event occurs on a parent device, Skylar One searches all related child devices for suppressible events. On the child devices, all suppressible events are suppressed. Only the suppressing event appears in the Events page (or the Event Console page in the classic Skylar One user interface). The suppressible events do not appear in the Events page (or the Event Console page in the classic Skylar One user interface).
- Suppressible events. This type of event is suppressed on a child device only when a suppressing event occurs on the parent device.
If you configure event categories, the suppressing and suppressible events must be associated with the same category for correlation to occur. If you do not configure event categories, each and every suppressing event that occurs on a parent device causes Skylar One to suppress all suppressible events on the associated child devices.
To define an event as a suppressing event on the Event Policy Manager page in the classic Skylar One user interface):
- Go to the Event Policy Manager page (Registry > Events > Event Manager.
- On the Event Policy Manager page, click the wrench icon (
) of the event that you want to define as the suppressing event. The Event Policy Editor page appears. - On the Event Policy Editor page, click the tab.
- In the Topology Suppression field, select Suppressing.
- Click . In the future, when this event occurs on a device, Skylar One checks if the device is a parent device. If the device is a parent device, specified events (suppressible events) with the same category are suppressed on the child devices.
To define an event as a suppressible event on the Event Policy Manager page in the classic Skylar One user interface:
- Go to the Event Policy Manager page (Registry > Events > Event Manager).
- On the Event Policy Manager page, click the wrench icon (
) of the event that you want to define as the Suppressible event. The Event Policy Editor page appears. - On the Event Policy Editor page, click the tab.
- In the Topology Suppression field, select Suppressible.
- Click . In the future, when this event occurs on a device, Skylar One checks if the device is a child device. If the device is a child device, Skylar One checks to see if a suppressing event with the same category has occurred on the parent device. If a suppressing event has occurred on the parent device, the specified event is suppressed on the child device.
Example: Child Event Suppression
For example, suppose you have the following devices and event policies defined:
- A parent device, a Cisco Catalyst switch named Boise-DMZ.
- A child device to Boise-DMZ, a server named HQ-W2K3-VC01.
- An event policy, "Poller: Interface operationally down", defined as a suppressing event.
- A second event policy, "Poller: Device not responding", defined as a suppressible event.
- Both events are associated with the same event category.
In this scenario, if an interface goes down on the switch Boise-DMZ, Skylar One cannot communicate with the server, HQ-W2K3-VC01, attached to the switch.
With the above defined event topology suppression:
- The event "Poller: Interface operationally down" occurs on Boise-DMZ.
- The event "Poller: Device not responding" is suppressed on the server HQ-W2K3-VC01.
- On the Events page (or the Event Console page in the classic Skylar One user interface), the only event that appears in this scenario is the event "Poller: Interface operationally down" on the device Boise-DMZ.
Event Categories
Event categories allow Skylar One to match masking events with the right maskable events. When you assign a category to a masking or maskable event, that event only correlates with events that share the same category. An event can belong to multiple categories, but for correlation to occur, the masking and maskable events must share at least one category in common.
This section uses the terms "masking" and "maskable," but these are interchangeable with "suppressing" and "suppressible" from the classic Skylar One interface.
Without event categories, any masking event on a parent device causes Skylar One to mask every maskable event across all child devices, regardless of whether those events are related. For example, a collection failure on a chassis could end up masking an unrelated temperature warning on a blade.
With event categories, Skylar One only correlates events that share the same category. Using the same example, a collection-related masking event would only mask events that were maskable and tagged with the same collection category, leaving unrelated events (like temperature warnings) visible.
The table below illustrates how event categories control which events are correlated:
| Event Name | Type | Event Category |
| Dynamic App Collection Problem | masking | Dynamic Applications.Collection |
| Dynamic Application taking too long to collect | maskable | Dynamic Applications.Collection |
| Availability check failed | maskable | Dynamic Applications.Collection |
| Fan critical | masking | Environment.Temperature |
| Temperature critical | maskable | Environment.Temperature |
In this example, if "Dynamic App Collection Problem" occurs on a parent chassis, Skylar One masks "Dynamic Application taking too long to collect" on the child blade (which is in the same category), but leaves "Temperature critical" visible (because it is in a different category).
Viewing the List of Event Categories
The Event Categories page (Events > Event Categories) displays the following about each event category:
- Name. Name of the event category. You can click the name to edit the category.
- Event Policy Count. Number of event policies that are aligned with the event category.
- ID. Unique numeric ID for the event category, generated by Skylar One.
- Correlation Time. Number of minutes that must pass before custom run book actions with an Action Type of Run a Snippet can correlate the event category. For more information about snippet-based run book actions, see the section on Run Book Actions.
- Event Occurrence. Indicates whether the correlation time is measured from the first occurrence of the event (First) or the most recent occurrence (Last).
- Last Edited By. Name of the user who created or last edited the event category.
- Last Edited Date. Date and time the event category was created, imported into Skylar One, or last edited.
You can sort the list by a column's values by clicking on its column heading. You can also filter the items on the page by typing or selecting filter options in one or more of the filters found above the columns. For more information, see the topic on Filtering Inventory Pages.
You can adjust the size of the rows and the size of the row text on this inventory page. For more information, see the topic on Adjusting the Row Density.
You can rearrange the columns in the list by clicking and dragging the column to a new location. You can adjust a column's width by clicking and dragging the right edge of the column. For more information about editing and adding columns, see the topic on Editing the Settings for an Inventory Page.
Creating an Event Category
From the Event Categories page, you can define a new event category to organize and classify events according to your business requirements.
To create an event category:
-
Go to the Event Categories page (Events > Event Categories).
-
Click . The Create an Event Category modal appears.
-
Complete the following fields:
-
Category Name. The name of the event category. Accepts up to 64 single-byte alphanumeric characters.
-
Correlation Time. An integer value between 1 and 4,294,967,295 that indicates the number of minutes that must pass before custom run book actions with an Action Type of Run a Snippet can correlate the event category. For details, see the section on Run Book Actions.
-
Event Occurrence. Select whether the correlation time is measured from the first occurrence of the event (First) or the most recent occurrence (Last).
-
-
Click to create the event category, or to discard your changes.
Assigning an Event Category to an Event
For information about how to assign an event category to an event policy, see the section on The Advanced Tab.
Assigning an Event Category to an Event in the Classic Skylar One User Interface
For information about how to assign an event category to an event policy in the classic Skylar One user interface, see the section on Defining Pattern Matching and Advanced Behavior in the Advanced Tab.
Editing an Event Category
You can edit an existing event category from the Event Categories page.
To edit an event category:
-
Go to the Event Categories page (Events > Event Categories).
-
Locate the event category you want to edit and click its Name. (Alternatively, click the actions icon (
) and select Edit.) The Edit Event Category modal appears. -
Complete the fields on the modal. For more information about these fields, see the section on Creating an Event Category.
-
Click to save the edited event category, or to discard your changes.
Deleting One or More Event Categories
You can delete one or more event categories from the Event Categories page. When you remove an event category, the category is also removed from any event policy with which it is aligned.
To delete event categories:
-
Go to the Event Categories page (Events > Event Categories).
-
Do one of the following:
-
To delete a single event category, click the actions icon (
) for that category and select Delete. -
To delete multiple event categories, select their checkboxes and then click .
-
- In the modal that appears, click to confirm the event category deletion.