For information about configuring event attributes selectively, see Configuring Event Attributes Selectively.
Clicking the Edit All Category Attributes icon above the table launches the Edit Attributes of All Categories dialog. This dialog enables you to set the attributes for all events in all categories and groups at once.
These global attributes can be modified:
One practical use of this global setting is to force ALL events to use the same Syslog Server Profile (GMS uses Profile 0 only), send Log Digest to the same E-mail Address, and send Alerts to the same E-mail Address.
To edit the Category attributes globally:
Enable is solid green when all categories, groups, and/or events are enabled, white when all are disabled, and semi-solid when they are mixed (some enabled, some disabled).
As this configuration is for all categories, you have to explicitly set the option to “all enabled” by clicking the icon until it is solid green, or to set the option to “all disabled” by clicking the icon until it is white. To configure a single event to be different from the rest of its group or category, you must go into the individual event setting configuration. If you do this, the icon is semi-solid.
When the fields display Multiple Values, different values have been specified for one or more category, group, or event. To view the individual settings, refer to Configuring Event Attributes Selectively. To change the setting from Multiple Values into one value for all categories, groups, or events while in the Edit Attributes of All Categories dialog, verify that the option was enabled so the field can be accessed for entering the new value. If the option is disabled, the field is dimmed and inaccessible.
The changes are saved and overwrite individual settings. Normally, production environments would not set all Categories/Groups/Events to have exactly the same settings. Before doing this, be sure to save your current configuration using the Save Template option, so that the previous settings can be restored if a mistake is made by using Import Template > Custom. Also, factory default settings can be restored using Import Template > Default.
Changing the Event Priority globally uses the same value for all Events. Modifying the Event Priority affects the Syslog output for the tag “pri=” as well as how the event is treated when performing filtering by Logging Level or Alert Level. Setting the Event Priority to a level that is lower than the Logging Level causes those events to be filtered out. Also, as GMS ignores received Syslogs that have a level of Debug, heartbeat messages and reporting messages must have a minimum Event Priority of Inform.
The following Frequency Filter Interval fields enable you to specify how many events of the same Event ID to log per time interval. Note that having the same Event ID does not mean that the event is a duplicate because the message itself might contain different information such as source/destination IP addresses, and so on. The filtering is done based on Event ID only. The range for these intervals is 0 to 86400 seconds.
The different options are independent of each other, and you can enable any combination of them and set different frequencies of generation for them. For example, you might want an event message emailed to you, but it is not shown in the Monitor > Logs > System Logs page. When GMS is enabled, however, care must be taken when modifying event attributes so events used to generate reports are not incorrectly filtered out. Explicit modification of individual events are saved even if used for GMS. Before making any changes, save current Log settings using Save Template. This way, should a mistake be made, the previous settings can be restored using Import Template > Custom. As a last resort, the GMS settings can be restored using Import Template > Analyzer/Viewpoint/GMS.
For example, if you set this value to 60 seconds, then when the event Connection Closed first happens at 1:15 p.m., the next Connection Closed event to be displayed must occur at least 60 seconds after the first one. Any Connection Closed event occurring within the 60 seconds interval is not displayed.
For example, if you set this value to 60 seconds, then when an E-mail Alerts first happens at 1:15 p.m., the next E-mail Alerts for the same event is not sent until 60 seconds after the first one. Alerts for the same event occurring within the 60 seconds interval are not emailed.
For example, if you set this value to 60 seconds, then when a Syslog message is first reported at 1:15 p.m., the next Syslog message for the same event is not sent until 60 seconds after the first one. Syslog messages for the same event occurring within the 60-second interval are not sent.
If this option is enabled, it is important to verify the email address configured in the Send Log Digest to Email Address field is correct.
An email alert is one email sent for each event occurrence as soon as that event has occurred. A Log Digest, on the other hand, is a chronological collation of events sent as a single email in digest format. Because it is a summation of events, the event information time period is a mix of older and newer events.