Monitoring events and reducing event noise
Scenario: Scanning for critical security events and sending notifications.
You can use various event policies to reduce event noise and efficiently view and identify actionable events.
Jane is an operator at Apex Global. Her job is to watch for any critical events in their environment that might make their system vulnerable. Jane uses the Events page in BMC Helix Operations Management and scans through a large volume of events. She wants to identify critical security events to take immediate action on them. It is imperative to Jane that she can quickly identify actionable events from an event storm. She asks for help from her administrator, Sarah, to reduce event noise.
Sarah configures an event suppression policy to withhold unnecessary events. She also correlates related events and enriches events with additional context to help Jane resolve events faster. Sarah goes a step further and configures automatic notifications for events that Jane is interested in.
The following image describes how event noise reduction takes place:
Refer to the following table to understand the tasks that help you identify actionable events and reduce event noise: