Syslog - How to stop email alert?

Support questions about the Threshold plugin

Moderators: Developers, Moderators

Post Reply
oneaty
Posts: 24
Joined: Wed Oct 02, 2013 7:14 am

Syslog - How to stop email alert?

Post by oneaty »

A syslog alert has been triggered for some specific syslog entries and the plugin worked as defined, by sending emails to me, one for each syslog entry that has triggered the alert.

Since then, I keep receiving many emails for this alert every 45 minutes, which corresponds to the re-alert cycle I had set up in the Alert Rule.

However, I don't want to receive emails for these syslog entries anymore, since I'm already aware of them.

How can I prevent emails from being sent for those specific syslog entries?

In the Alert Rule, I changed the alert's re-alert cycle to Not Set, but the alert still keeps sending me emails.

The alert's reporting method is Individual.
Cacti 0.8.8f over Ubuntu Server 16.04.1 monitoring
  • Router Ubuntu Server 16.04.1 over Celeron J1900i
  • TP-LINK WRT841ND / OpenWRT AP
  • Humax HG100R-L2 Residential Gateway
oneaty
Posts: 24
Joined: Wed Oct 02, 2013 7:14 am

Re: Syslog - How to stop email alert?

Post by oneaty »

Please, help me!

I'm getting my email inbox flooded with email alerts regarding old syslog entries.

I'd really love to understand how syslog alerts should work.

I believe my use case is a standard one:

If a log entry with Priority="Alert" shows up, a thold alert should be triggered and, as defined, an email sent and re-alert every n minutes.

My point is: how to stop re-alerting (thus, re-sending emails) for those old log entries (but not for new ones)?

Any help will be appreciated.
Cacti 0.8.8f over Ubuntu Server 16.04.1 monitoring
  • Router Ubuntu Server 16.04.1 over Celeron J1900i
  • TP-LINK WRT841ND / OpenWRT AP
  • Humax HG100R-L2 Residential Gateway
oneaty
Posts: 24
Joined: Wed Oct 02, 2013 7:14 am

Re: Syslog - How to stop email alert?

Post by oneaty »

I'm trying to find a way thru this, but still not successful.

If I add and enable a Removal Rule with the same SQL match string as the Alert Rule I'm trying to stop re-alerting, it simply prevents any new alert to be issued, although it seems to stop the realerting of old alerts.

Then, if I disable the Removal Rule, new alert log entries are turned into alerts, but they are not re-alerted according to the alert re-alert settings. How come??

Does anyone has a clue on this?
Cacti 0.8.8f over Ubuntu Server 16.04.1 monitoring
  • Router Ubuntu Server 16.04.1 over Celeron J1900i
  • TP-LINK WRT841ND / OpenWRT AP
  • Humax HG100R-L2 Residential Gateway
naven
Posts: 12
Joined: Tue Mar 31, 2015 4:54 pm

Re: Syslog - How to stop email alert?

Post by naven »

oneaty wrote: In the Alert Rule, I changed the alert's re-alert cycle to Not Set, but the alert still keeps sending me emails.
Have you checked value of "Re-Alerting Repeat Alert after specified number of poller cycles."
In Settings - > Thresholds?
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests