Ticket group wizard


The Ticket group wizard, accessed through the Tickets > Config > Ticket Groups > Add New option provides a simple way to create a simple correlation rule and ticket group consisting of a single correlation thread and alert. This might be adequate for many applications.

The process for creating a ticket is as follows:

  1. You can optionally create a ticket group for the ticket, perhaps identifying a particular fault.
  2. Create a correlation thread and target specific messages using a match expression or macro.
  3. Create one or more alerts that monitor the counts for the correlation thread and opens the ticket for the user.
  4. You can optionally repeat steps 2 and 3 to configure multiple correlation threads and multiple alerts for each thread counter.

The preceding steps are not difficult. However, it is often the case that a single ticket group corresponds to a single thread and alert. (This is especially true when first getting started with the BMC Defender Server system.) In this case, you can create the ticket group, thread, and alert values using the Ticket Group Wizard screen in one easy session.

The wizard allows you to either create a new correlation rule, or modify an existing correlation rule (referenced by a ticket group). The wizard cannot configure sophisticated correlation and ticketing strategies, that might be necessary or practical in some enterprises. However, using the wizard, the operator can quickly configure multiple ticket groups and later modify or enhance these rules as necessary.


 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*