Adding an incident detection rule
To manage incidents, you must add a rule that triggers incidents when the system detects abnormal behavior in your web traffic. To perform this procedure, you must have Operator-level access, or higher.
To add an incident-detection rule
- In a Real User Analyzer component, point to Administration > Threshold and problem detection and click Incident detection.
- On the Action menu, click Add.
- In the Name box, type Performance for MyBillingApplication.
- In the Watchpoint list, type a name for the rule.
For example, if you have a Watchpoint called MyBillingApplication that identifies traffic for your billing application and you want a performance rule to create incidents when too many pages violate their SLTs, you could type Performance for MyBillingApplication. - For Type, select the type of rule that you want to create:
- Performance — The incident will trigger each time when system detects too many pages violating Service Level Thresholds (SLTs)
- Availability — The incident will trigger each time when system detects an abnormally high percentage or errored requests
You can customize, which errors the system monitors for incidents - Volume — The incident will trigger each time when system detects an abnormally high or low number of requests
Select Performance.
- To activate the rule immediately after creation, leave the Activate box selected.
- To edit advanced settings for this rule, click Next and proceed to Configuring-advanced-detection.
The following tabs open:- Detection — Controls the amount of incidents to detect, depending on the data volumes.
- Analysis — Specifies additional criteria for analyzed traffic to isolate the root causes.
- Notification — Specifies the incident criticality and notification parameters.
- Click Save.
Troubleshooting
On occasion, new incident rules fail to detect incidents. Should this problem occur, open and resave the rule.
Where to go from here
Configure advanced detection parameters.
Related topics
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*