Previous Topic: Set Up Syslog AlertsNext Topic: Example of a Basic Anomaly Message


Configure the Target for Syslog Messages

Configure Syslog alerting to identify a target Syslog server that will receive messages when sensors report a threshold violation. If Syslog alerting is not configured, the alerts that sensors generate may appear in the Anomaly Detector page views, but no messages are sent to report the alerts.

Prerequisites for Syslog Alerting:

Follow these steps:

  1. Display the Data Source List page:
    1. Log in to the Performance Center Console as a user with administrator privileges, if you are not already logged in.
    2. Select Admin, Data Sources.

      The page for managing data sources opens: Manage Data Sources (CA PC) or Data Source List (NPC).

  2. Click the name of the CA Anomaly Detector instance that you want to configure.

    The Monitored Products page opens.

  3. Click View Alert Targets.

    The Alert Targets page opens.

  4. Double-click the syslogging row.

    The Edit Alert Target page opens.

  5. Specify the Target: Enter the IP address or DNS hostname of the system that will receive the Syslog information.
  6. Select one or both of the following options to enable the alert:
  7. Click Save.

    You return to the Alert Targets page, which reflects any changes you saved.

Best Practices:

Alerts are enabled for most sensors by default so that when you start using CA Anomaly Detector, you can review a wide range of anomalous behaviors with a minimum of configuration. If you use Syslog alerting and you select the Basic State option at this stage, you may see so many anomalies that you cannot determine which ones are significant.

If you begin by selecting the Cluster State option for alert targets, the anomalies you see are much more likely to be significant. You can quickly determine which sensors are useful to you. At this point you can disable alerts for the other sensors, then start using the Basic State option. This produces an expanded set of results for the anomaly types that interest you. The anomalies from the other sensors are eliminated.

To explore all of the potential anomaly cluster types, you may want to enable any disabled sensors. In this case, use the Cluster State option.