Correlation type | Description |
---|---|
Generalization | • Groups two or more events into a single alarm. • A generalized alarm will further use one of the correlation types (none, time-bound, counting and compression) for applying correlation logic to the new alarm. |
Time-bound | • Stipulates that when the event is received, a timer is started for that event. • While the timer is running, subsequent events of the same type are suppressed. • On the expiry of the timer, an alarm will be raised for that event stating the count for the number of times that event was received in this duration. |
Counting | Considers a specified number of similar events as one. In this correlation type, the respective alarm will be raised after the event has occurred for count times. |
Compression | Check multiple occurrences of the same event for duplicate/redundant event information, remove the redundancies, and report them as a single alarm. |
Severity | Correlates events based on the severity of the events. |