Example: Assign event owner according to the time frame status
To define the event selection criteria
- Select Configuration > Event Policies, click Create and enter a policy name.
- In Event Selection Criteria, define a condition to select open events that contain the message CPU utilization exceeds 85%.
The following image illustrates how the event selection criteria will look:
To learn how to construct the event selection criteria, see Creating-and-enabling-event-policies.
To create the time frame in an event policy
Create time frames according to the holiday calendar of the user's time zone. To learn about creating time frames, see Setting-event-policy-schedules-by-using-time-frames.
For example, you could create a time frame for a user in the IST time zone and another time frame for a user in the Brisbane time zone as shown in the following images:
To build the policy workflow
The following workflow diagram gives you a high-level overview of the policy workflow creation process:
- In Policy Configuration, select Advanced Enrichment.
- Click Lookup to look up existing events for which you want to assign an owner.
- Add the Update old events action to run the policy actions on existing events.
- Add a Variable action to check whether the time frame for the IST time zone is active and store the result in the TimeFrameStatusIST variable.
- Add another Variable action to check whether the time frame for the Brisbane time zone is active and store the result in the TimeFrameStatusBrisbane variable.
- Add an If action to compare the time frame status of the IST time zone.
- Based on the time frame status in the preceding step, in the Then part, add an Enrich action to assign the existing event to Jack.
- In the Else part, add an If action to compare the time frame status of the Brisbane time zone.
- Based on the time frame status in the preceding step, in the Then part, add an Enrich action to assign the existing event to Jim.
Results
The resulting policy workflow enriches the event owner based on the time frame status.
Without event enrichment
With event enrichment
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*