Event Correlation and Parent and Child Events

Download this manual as a PDF file

This section describes Topology Events, which is also called Event Correlation.

Event Correlation

In Skylar One, there are four types of events that might not appear on the Events page (or the Event Console page in the classic Skylar One user interface):

  • Rolled-up events. Multiple occurrences of the same event on the same device. When the same event occurs multiple times on a single device, Skylar One does not display each occurrence on the Events page (or the Event Console page in the classic Skylar One user interface). Instead, Skylar One displays a single entry and notes the number of occurrences in the Count column.
  • Suppressed Events. Suppressed events do not appear on the Events page (or the Event Console page in the classic Skylar One user interface). For details on suppressing events for a single device, see the section on Suppressing Events.
  • Topology Events. In Skylar One, event correlation or topology suppression means the ability to build parent-child relationships between devices and between events. When events are correlated, only the parent event is displayed on the Events page (or the Event Console page in the classic Skylar One user interface). The magnifying-glass icon () appears to the left of the parent event. When you click on the magnifying-glass icon, the list of child events is displayed. The child events are rolled up under the parent event and are not displayed on the Events page (or the Event Console page in the classic Skylar One user interface). For the parent event, the count column will be incremented to indicate the number of correlated child events. Optionally, you can define event categories that allow Skylar One to more efficiently align suppressing events with suppressible events. When you align an event category to a suppressing or suppressible event, that event will be correlated with only events that are aligned with the same event category.
  • Event Masks. When a device uses the Event Mask setting, events that occur on a single device within a specified span of time are grouped together. On the Events page (or the Event Console page in the classic Skylar One user interface), masked events are displayed under a single event, the one with the highest severity. For details on events masks, see the section on Event Masks.

This section describes Topology Events, also called Event Correlation.

Skylar One performs two types of event correlation:

  • Automatic Event Correlation. During discovery, Skylar One automatically discovers and defines parent-child relationships between devices based on Layer-2, CDP, LLDP, Layer-3, and legacy VMware topology or data collected from Dynamic Applications.
  • Manual Event Correlation. In Skylar One, you can configure devices and events so that events that are associated with child devices will be rolled-up under the parent device's events on the Events page (or the Event Console page in the classic Skylar One user interface). For example, suppose a switch fails. Instead of seeing an event for the failed switch and seeing events about failed communication for each device connected to the switch, only a single event would appear on the Events page (or the Event Console page in the classic Skylar One user interface). The single event would describe the switch failure. When you manually define a hierarchy between events, you can also include an event category. An event category allows Skylar One to more efficiently align suppressing events with suppressible events.

To manually define event correlation, you must perform two tasks:

  • Define parent and child devices.
  • Define a hierarchy between events—that is, define parent events (called suppressing events) and child events (called suppressible events).

Enabling a discovered device configured with CDP or LLDP topology in Skylar One will cause the device to provide information on its neighbor. This information only identifies that there is a neighbor device, not which is the parent or the child. This may cause the parent-child relationship to switch which requires you to manually reverse the issue within the Skylar One user interface. Skylar One allows you to manually build parent-child relationships between specific device categories. For more information, see Defining Parent and Child Devices.

This section describes the required tasks for manual event correlation.

Event Correlation Precedence

In some instances you might have multiple parent-child links between two devices. Skylar One displays only one of the relationships. Skylar One gives precedence to showing these relationships in the following order:

  • Manually defined event correlation links
  • Layer-3 links
  • LLDP links
  • CDP links
  • Layer-2 links
  • Legacy VMware links
  • Component relationship links

Additionally, any manually created, edited, or deleted links take precedence over the information discovered by Skylar One. The changes are propagated to discovery and event correlation.

Defining Parent and Child Devices

Skylar One allows you to create parent-and-child relationships and define event correlations. Skylar One will create parent and child devices automatically when:

  • Skylar One discovers Layer-2, CDP, LLDP, Layer-3, and legacy VMware topology.

  • Skylar One performs collection for Dynamic Applications that create component devices or device relationships.

You can also manually define parent and child relationships between devices.

The Device Children modal page allows users to select one or more devices to become children of the currently selected device.

To add children to a device:

  1. Go to the Device Manager page (Devices > Classic Devices).

  2. In the Device Manager page, select the wrench icon () for the device for which you want to add children devices. The Device Properties page appears.

    You cannot create parent-child relationships for devices with a Device Category of Virtual.

  3. In the Device Properties page, in the Actions drop-down list, select Device Children. The Device Children modal appears.
  4. In the Device Children modal, select one or more devices to be children of the current device.
  5. Click Save.

Device Categories that Don't Support Child Devices

A device category is a logical categorization of a device by primary function. Skylar One uses device categories to group related devices in reports and views.

Device categories are paired with device classes to organize and describe discovered devices. The device class usually describes the manufacturer and model of a device. The device category describes the function of the hardware.

Devices that are members of the following device categories cannot be assigned child devices:

  • Office Printers, Device Category #4
  • Workstations, Device Category #6
  • Environmental.Utility, Device Category #8
  • Environmental.HVAC, Device Category #9
  • Environmental.Security, Device Category #10
  • System.Tape, Device Category #17
  • Office.Copiers, Device Category #22
  • Office.Facsimiles, Device Category #23
  • Telephony.Phone, Device Category #36
  • Office.Plotter, Device Category #40
  • Pingable, Device Category #98
  • Virtual, Device Category #97

To determine a device's device category, look at the Category field on the Info menu of the Device Investigator page.

Defining Event Topology Masking and Suppression

Topology masking, also referred to as topology suppression, is a setting that defines the rules that Skylar One uses to determine event correlation and suppression when events occur on devices that have a parent/child relationship.

Skylar One allows you to create parent-and-child relationships and define event correlations. Skylar One will create parent and child devices automatically when:

  • Skylar One discovers Layer-2, CDP, LLDP, Layer-3, ARP, and legacy VMware topology.

  • Skylar One performs collection for Dynamic Applications that create component devices or device relationships.

You can also manually define parent and child relationships between devices.

For event correlation to occur, two types of event policies must be defined: masking events and maskable events.

  • Masking events. If this type of event occurs on a parent device, Skylar One will search all related child devices for maskable events. On the child devices, all maskable events will be masked. Only the masking event will appear on the Events page; the maskable events will be nested under the parent event.
  • Maskable events. This type of event is masked on a child device only when a masking event occurs on the parent device.

The following options are available:

  • Disabled: Events from this policy will not mask, or be masked, by topology.
  • Mask events on child devices: If an event occurs from this policy on a parent device, Skylar One will search for all related children devices for maskable events. If a Category has been aligned to this policy, Skylar One will refine the search to all children devices and mask all events that have been defined as maskable and assigned the same Category. If you have not assigned a Category to this policy, Skylar One will refine the search to all children devices and mask all events that have been defined as maskable and are not assigned a Category.
  • Maskable under a parent device’s event: If an event occurs from this policy on a child device, Skylar One will mask this event by topology only when a masking event occurs on the parent device. If a Category has been aligned to this policy, Skylar One will mask this event when it occurs on a child device and an event has been defined as masking occurs on its parent device. The masking event must have the same Category has the maskable event. If a Category has not been aligned to this policy, when a masking event that is not assigned to a Category occurs on the parent device Skylar One will search all children devices and mask all events that have been defined as maskable and are not assigned to a Category.
  • Both: If an event occurs from this policy on a parent device, it behaves as a masking event. If this even occurs on a child device, it behaves as a maskable event.

For more information about how to define an event as masking or maskable, see the section on The Event Message Tab.

Defining Event Topology Suppression in the Classic Skylar One User Interface

To manually configure event correlation in the classic Skylar One user interface, you must define two types of events:

  • Suppressing events. If this event occurs on a parent device, Skylar One will search all related children devices for suppressible events. On the children devices, all suppressible events will be suppressed. Only the suppressing event will appear in the Events page (or the Event Console page in the classic Skylar One user interface) . The suppressible events will not appear in the Events page (or the Event Console page in the classic Skylar One user interface) .
  • Suppressible events. This type of event is suppressed on a child device only when a suppressing event occurs on the parent device.

NOTE: If you configure event categories, the suppressing and suppressible events must be associated with the same category for correlation to occur. If you do not configure event categories, each and every suppressing event that occurs on a parent device will cause Skylar One to suppress all suppressible events on the associated children devices.

To define an event as a suppressing event on the Event Policy Manager page in the classic Skylar One user interface):

  1. Go to the Event Policy Manager page (Registry > Events > Event Manager.
  2. On the Event Policy Manager page, click the wrench icon () of the event that you want to define as the suppressing event. The Event Policy Editor page appears.
  3. On the Event Policy Editor page, click the Advanced tab.
  4. In the Topology Suppression field, select Suppressing.
  5. Click Save. In the future, when this event occurs on a device, Skylar One will check if the device is a parent device. If the device is a parent device, specified events (suppressible events) with the same category will be suppressed on the children devices.

To define an event as a suppressible event on the Event Policy Manager page in the classic Skylar One user interface:

  1. Go to the Event Policy Manager page (Registry > Events > Event Manager).
  2. On the Event Policy Manager page , click the wrench icon () of the event that you want to define as the Suppressible event. The Event Policy Editor page appears.
  3. On the Event Policy Editor page, click the Advanced tab.
  4. In the Topology Suppression field, select Suppressible.
  5. Click Save. In the future, when this event occurs on a device, Skylar One will check if the device is a child device. If the device is a child device, Skylar One will check to see if a suppressing event with the same category has occurred on the parent device. If a suppressing event has occurred on the parent device, the specified event will be suppressed on the child device.

Example: Child Event Suppression

For example, suppose you have the following devices and event policies defined:

  • A parent device, a Cisco Catalyst switch named Boise-DMZ.
  • A child device to Boise-DMZ, a server named HQ-W2K3-VC01.
  • An event policy, "Poller: Interface operationally down", defined as a suppressing event.
  • A second event policy, "Poller: Device not responding", defined as a suppressible event.
  • Both events are associated with the same event category.

In this scenario, if an interface goes down on the switch Boise-DMZ, Skylar One will not be able to communicate with the server, HQ-W2K3-VC01, attached to the switch.

With the above defined event topology suppression:

  • The event "Poller: Interface operationally down" occurs on Boise-DMZ.
  • The event "Poller: Device not responding" is suppressed on the server HQ-W2K3-VC01.
  • On the Events page (or the Event Console page in the classic Skylar One user interface), the only event that would appear in this scenario will be the event "Poller: Interface operationally down" on the device Boise-DMZ.

Event Categories

Event categories allow Skylar One to match masking events with the right maskable events. When you assign a category to a masking or maskable event, that event will only correlate with events that share the same category. An event can belong to multiple categories, but for correlation to occur, the masking and maskable events must share at least one category in common.

NOTE: This section uses the terms "masking" and "maskable," but these are interchangeable with "suppressing" and "suppressible" from the classic Skylar One interface.

Without event categories, any masking event on a parent device will cause Skylar One to mask every maskable event across all child devices, regardless of whether those events are related. For example, a collection failure on a chassis could end up masking an unrelated temperature warning on a blade.

With event categories, Skylar One only correlates events that share the same category. Using the same example, a collection-related masking event would only mask events that were maskable and tagged with the same collection category, leaving unrelated events (like temperature warnings) visible.

The table below illustrates how event categories control which events are correlated:

Event Name Type Event Category
Dynamic App Collection Problem masking Dynamic Applications.Collection
Dynamic Application taking too long to collect maskable Dynamic Applications.Collection
Availability check failed maskable Dynamic Applications.Collection
Fan critical masking Environment.Temperature
Temperature critical maskable Environment.Temperature

 

In this example, if "Dynamic App Collection Problem" occurs on a parent chassis, Skylar One masks "Dynamic Application taking too long to collect" on the child blade (which is in the same category), but leaves "Temperature critical" visible (because it is in a different category).

Viewing the List of Event Categories

The Event Categories page (Events > Event Categories) displays the following about each event category:

  • Name. Name of the event category. You can click the name to edit the category.
  • Event Policy Count. Number of event policies that are aligned with the event category.
  • ID. Unique numeric ID for the event category, generated by Skylar One.
  • Correlation Time. Number of minutes that must pass before custom run book actions with an Action Type of Run a Snippet can correlate the event category. For more information about snippet-based run book actions, see the section on Run Book Actions.
  • Event Occurrence. Indicates whether the correlation time is measured from the first occurrence of the event (First) or the most recent occurrence (Last).
  • Last Edited By. Name of the user who created or last edited the event category.
  • Last Edited Date. Date and time the event category was created, imported into Skylar One, or last edited.

To sort the list, click on a column heading. The list will be sorted by the column value, in ascending order. To sort the list by descending order, click the column heading again. You can also filter the items on this inventory page by typing filter text or selecting filter options in one or more of the filters found above the columns on the page. For more information, see Filtering Inventory Pages in the Introduction to Skylar One manual.

You can adjust the size of the rows and the size of the row text on this inventory page. For more information, see the section on Adjusting the Row Density in the Introduction to Skylar One manual.

To rearrange the columns in the list, click and drag the column name to a new location. You can adjust the width of a column by clicking and dragging the right edge of the column. For more information about editing and adding columns, see Editing the Settings for an Inventory Page.

Creating an Event Category

From the Event Categories page, you can define a new event category to organize and classify events according to your business requirements.

To create an event category:

  1. Go to the Event Categories page (Events > Event Categories).

  2. Click Create Event Category. The Create an Event Category modal appears.

  3. Complete the following fields:

    • Category Name. The name of the event category. Accepts up to 64 single-byte alphanumeric characters.

    • Correlation Time. An integer value between 1 and 4,294,967,295 that indicates the number of minutes that must pass before custom run book actions with an Action Type of Run a Snippet can correlate the event category. For details, see the section on Run Book Actions.

    • Event Occurrence. Select whether the correlation time is measured from the first occurrence of the event (First) or the most recent occurrence (Last).

  4. Click Save to create the event category, or Cancel to discard your changes.

Assigning an Event Category to an Event

For information about how to assign an event category to an event policy, see the section on The Advanced Tab.

Assigning an Event Category to an Event in the Classic Skylar One User Interface

For information about how to assign an event category to an event policy in the classic Skylar One user interface, see the section on Defining Pattern Matching and Advanced Behavior in the Advanced Tab.

Editing an Event Category

You can edit an existing event category from the Event Categories page.

To edit an event category:

  1. Go to the Event Categories page (Events > Event Categories).

  2. Locate the event category you want to edit and click its Name. (Alternatively, click the Actions icon () and select Edit.) The Edit Event Category modal appears.

  3. Complete the fields on the modal. For more information about these fields, see the section on Creating an Event Category.

  4. Click Save to save the edited event category, or Cancel to discard your changes.

Deleting One or More Event Categories

You can delete one or more event categories from the Event Categories page. When you remove an event category, the category is also removed from any event policy with which it is aligned.

To delete event categories:

  1. Go to the Event Categories page (Events > Event Categories).

  2. Do one of the following: 

    • To delete a single event category, click the Actions icon () for that category and select Delete.

    • To delete multiple event categories, select their checkboxes and then click Delete.

  3. In the modal that appears, click Delete to confirm the event category deletion.