Chapter 6. Event management products and best practices 285
We recommend that you use both the state correlation engine on the gateway
and the IBM Tivoli Enterprise Console event server rule engine in conjunction
with each other to ensure proper escalation of worsening conditions.
Escalating events with IBM Tivoli Enterprise Console event
The severity of events can be escalated using IBM Tivoli Enterprise Console
rules. This section reviews several rules that are supplied with IBM Tivoli
Enterprise Console and NetView. It explains how they are used to escalate the
severity of events. Plus it describes the predicates that are available in IBM Tivoli
Enterprise Console to code your own escalation rules.
Escalation in netview.rls
The default installation for NetView configures event forwarding, so that all traps
sent to IBM Tivoli Enterprise Console from NetView have a WARNING severity.
The rules in the netview.rls rule set adjust the severity of the events according to
Table 6-9 Rules from the netview.rls rule set
router_raise Raises the severity of router down events to CRITICAL.
interface_lower Lowers the severity of interface up events to HARMLESS.
isdn_lower Lowers the severity of ISDN active events to HARMLESS.
snmp_lower Lowers the severity of SNMP collect re-arm events to
node_lower Lowers the severity of node up events to HARMLESS.
router_lower Lowers the severity of router up events to HARMLESS.
subnet_lower Lowers the severity of subnet reachable events to
interface_added_lower Lowers the severity of interface added events to
interface_managed_lower Lowers the severity of interface managed events to
node_added_lower Lowers the severity of node added events to HARMLESS.
node_managed_lower Lowers the severity of node managed events to