Often, the same events are ingested into the CMS from multiple Policy Engines, and are displayed as multiple duplicate rows in the iConsole. You can customize a standard search to list duplicate events with specific criteria, and group these duplicates together.
A de-duplication search saves you the effort of identifying and handling duplicate events. You create and run your custom search, select a parent event, and apply audit actions (including print, review, escalate) to its child events in bulk.
Follow these steps:
The Searches page lists the available searches.
The Search Properties screen displays.
Lists similar events with the same time stamp as duplicates.
Lists similar events with the same subject as duplicates.
Lists similar events with the same user as duplicates.
Lists similar events with the same Policy ID as duplicates.
Lists events that match on EventTimeStamp +/- 30 sec, subject, sender, and trigger count. This pre-defined search requires you to create a custom scheduled task to identify duplicate groups of events, and to insert those groups of records into the Wgn3RelatedEvent table.
Your custom de-duplication search is added to your Searches list.
Copyright © 2014 CA.
All rights reserved.
|
|