Rules Overview

There are two types of Rules used by Fault Analytics: Event Rules and Duplicate Event Rules. Event Rules are used to perform actions once rule conditions are met.   Duplicate Event Rules are used to suppress subsequent duplicate events for a period of time.  Using these two types of rules, you can be notified if a particular fault event occurs three times within a 30-minute period, suppress all faults for a particular program, set certain event field values, or specify that an e-mail be sent.

Event Rules define a set of conditions and a set subsequent actions should those conditions be true. Conditions consist of field names, operators, literals, and thresholds (how many times an event occurs that meets all other conditions within a given period). Actions consist of assigning values to an existing field(s), sending e-mail notifications to a distribution list, processing or deleting the event, or assigning a value to a user-created temporary field.

Duplicate Event Rules define a set of criteria (event types, fields, and time period) with an action to suppress subsequent events whose values are the same for the given criteria (duplicates).  Duplicate Event Rules allow the first occurrence of a specific event to be processed, but suppress all subsequent events that meet the user-specified duplicate rule conditions for a period of time.

For example, you can create a rule to notify you only if a particular fault event occurs three times within a 30-minute period, suppress all faults for a particular program, set certain event field values, or specify that an e-mail be sent.

Event Rule Elements

  • Conditions consist of field names, operators (for example: equals, startswith, contains), boolean logic, and literals.

  • Actions are what should happen when Conditions are true (for example, process the event, delete the event, or send an e-mail notification, etc.).

Duplicate Event Rule Elements

  • You can choose to evaluate All Events or only Selected Events.

  • You can select which Field Names to evaluate that may be in-common between events.

  • You can specify the period of time for which duplicate events are to be suppressed after the first occurrence.

See Also

Create a New Rule

Edit a Rule

Copy a Rule

Delete a Rule

Test a Rule

Activate or Deactivate a Rule

Change Rule Order