Configuring Event Management
12 min
about configuring event management docid\ pdaoxpvb0me6yo4yzvfe0creating and adding the event tab docid\ pdaoxpvb0me6yo4yzvfe0creating and adding an event tab for a service docid\ pdaoxpvb0me6yo4yzvfe0viewing the availability log docid\ pdaoxpvb0me6yo4yzvfe0viewing, editing, and creating an event docid\ pdaoxpvb0me6yo4yzvfe0reporting an event as an outage docid\ pdaoxpvb0me6yo4yzvfe0creating an event for a service docid\ pdaoxpvb0me6yo4yzvfe0marking an event as closed docid\ pdaoxpvb0me6yo4yzvfe0creating an incident from an event docid\ pdaoxpvb0me6yo4yzvfe0associating an incident with an event docid\ pdaoxpvb0me6yo4yzvfe0about event correlation docid\ pdaoxpvb0me6yo4yzvfe0 about configuring event management event management allows you to capture events for configuration items you can add an event workspace to specific roles to enable the roles to view events as they are logged, and to list open and closed events within the event workspace, you can sort events by number, source, status, if it is an outage, the start date and time, and the end date and time see making layouts available to users docid\ h8arlpy7 azaglzuclrzr for information on how to add the event workspace for a role in addition, an event tab displays the information for each configuration item to learn more about event management, see working with event management docid\ li11ycdnj5a0jawahphoz to use event management in your deployment, do the following add the event service to your configuration if you are using a release prior to release 2015 1, you must enable the functionality and create an event tab (for each business object) to display within the ci workspace see creating and adding the event tab docid\ pdaoxpvb0me6yo4yzvfe0 creating and adding the event tab use the following procedure to create and add an event tab for any configuration item other than a service to add an event tab for a service, see creating and adding an event tab for a service docid\ pdaoxpvb0me6yo4yzvfe0 from the configuration console, click build > page layouts to open the page layouts workspace find the ci layout click edit from the edit layout ci workspace, you must edit each business object type such as server, workstation, computer, or service to add event management click a business object type (such as server) listed in views in this layout to go to the form view editor page navigate to the child panels list select then delete outage log it is no longer required click add child panel and edit the columns as follows to add an event tab column title description object at the formview child panel relationship editor dialog box, for direct relationship select frs evt event (via ciassocfrs evt event) for a device (such as computer, server, printer, and so on) display name enter an appropriate name for the tab (such as event ) toolbar remove the link and unlink buttons (since they cannot be used) by dragging them to the trash icon click yes when asked to confirm the deletions add create incident for ci events to the toolbar menu by dragging make changes as needed at the toolbar button editor and click save click save for the toolbar editor list select frs evt event defaultgrid form(s) select the default form for frs evt event, then click ok to return to the edit layout ci page show count in title optional enable the checkbox in this column to see the number of associated events displayed on the tab make any other changes such as adding the availability log see click add child panel and edit the columns as follows to add an availability log tab docid\ pdaoxpvb0me6yo4yzvfe0 of viewing the availability log docid\ pdaoxpvb0me6yo4yzvfe0 click save creating and adding an event tab for a service from the configuration console, click build > business objects to open the business objects workspace open the ci service business object click the layouts tab click the ci service layout if multiple layouts are used at your installation, then you must edit all relevant configuration item layouts navigate to views in this layout and click formview navigate to the child panels list and click add child panel add or edit the following columns column title description object at the formview child panel relationship editor dialog, for direct relationship select frs evt event (via ciserviceassocfrs evt event) display name enter an appropriate name for the tab (such as event ) toolbar remove the link and unlink buttons (since they cannot be used) by dragging them to the trash icon click yes when asked to confirm the deletions add create incident for service events to the toolbar menu by dragging make changes as needed at the toolbar button editor and click save click save for the toolbar editor list select the frs evt event defaultgrid form(s) select the default form for frs evt event then click ok show count in title optional enable the checkbox in this column to see the number of associated events displayed on the tab select then delete outage log it is no longer required make any other changes such as adding the availability log see click add child panel and edit the columns as follows to add an availability log tab docid\ pdaoxpvb0me6yo4yzvfe0 of viewing the availability log docid\ pdaoxpvb0me6yo4yzvfe0 when specified, use the settings for service click save viewing the availability log the availability log displays information about events for a device or service the log calculates the downtime from the time an event is marked as an outage to the time the event is closed see also reporting an event as an outage docid\ pdaoxpvb0me6yo4yzvfe0 and creating an event for a service docid\ pdaoxpvb0me6yo4yzvfe0 outage event impacts the availability log calculation only for ci service and does not have any impact on other ci's availability log follow these steps to add an availability log from the configuration console, click build > page layouts to open the page layouts workspace for the ci page layout, click edit from the edit layout ci page, you must edit each business object type such as server, workstation, or computer to add the availability log tab click on a business object type (such as server) listed in views in this layout to go to the form view editor page navigate to the child panels list click add child panel and edit the columns as follows to add an availability log tab column title description object at the formview child panel relationship editor dialog box, for direct relationship select ciassocfrs avl cilog for service, use frs avl cilog (via ciassocfrsavl cilog) display name enter an appropriate name for the tab (such as availability log) toolbar remove the new , delete , link , and unlink buttons (since they cannot be used) by dragging them to the trash icon click yes when asked to confirm the deletion list select the frs avl cilog defaultgrid form(s) select the default form for frs avl cilog, then click ok show count in title optional enable the checkbox in this column to see the number of associated events displayed on the tab viewing, editing, and creating an event use the events tab to track events created manually or by other integrations log in to open the ci workspace double click a configuration item to open it click the event tab double click an event to view and edit the event details you can view the following information for each event event number a unique number assigned to each event description a description of the event source the source of the event, such as manual entry or network monitor status the status of the event can be either open or closed event type the type of event can be exception, warning, or informational you can use business rules and quick actions, depending on the event type for example, whenever an event is classified as informational, you can configure the application to automatically close the event you could also configure the application to send an alert or email to the administrator for events that are classified as exception or that cause an outage priority the priority of the event can be a number between 1 and 5 you can adjust the priority based on the event type is outage specifies if this event is an outage start date and time the date and time when the event started end date and time the date and time when the event ended duration the duration of the event configuration item name the name of the associated configuration item configuration item state the state of the associated configuration item configuration item type the type of the associated configuration item when viewing events in a list view, you can sort, group, or filter on any column by clicking the arrow next to the column name and then doing any of the following to sort events, click either sort ascending or sort descending to add or remove columns from the view, click columns and then select the columns to add or remove to group events, click group by this field or show in groups to filter events, click filters and then enter a filter depending on the column type, the filtering options may be based on keyword or a selectable list if an event has one or more associated incidents, click the search icon to view the incident reporting an event as an outage log in to open the ci workspace double click a configuration item to open it click the event tab double click an event to view and edit the event details check is outage to mark an event as an outage the duration of the outage is calculated when the end date is entered and the entry is saved creating an event for a service an event is usually created manually for a service close the event by editing the information log into the application open the ci workspace double click a configuration item to open it click the event tab click new event enter the information into the fields as required if this is an outage, check is outage enter the start date time to begin timing the duration of the outage the duration of the outage is calculated when the end date of the event is entered and the entry is saved, and is reported as service availability associate the event with an incident see associating an incident with an event docid\ pdaoxpvb0me6yo4yzvfe0 for more information or create a new incident for this event click save marking an event as closed log in to open the ci workspace double click a configuration item to open it click the event tab double click an event to view it the application displays the edit event dialog box in the status field, change the status to closed in the end date time field, enter the end date time (this is a required field when the event status is changed to closed ) click save creating an incident from an event for a device or for a service, you can create an incident for an event by using the following steps log in to open the ci workspace double click a configuration item to open it click the event tab to see a list of events select an event, then click create incident or create incident for service events you added these quick action buttons when creating the event tabs see creating and adding the event tab docid\ pdaoxpvb0me6yo4yzvfe0 and creating and adding an event tab for a service docid\ pdaoxpvb0me6yo4yzvfe0 the application automatically creates an incident associated with the event double click the event to open the edit event dialog box the associated incident is listed in the incident field go to the listed incident by clicking go to associating an incident with an event log in to open the ci workspace double click a configuration item to open it click the event tab to see a list of events double click an event to view it the application displays the edit event dialog box in the incident field, enter the incident number if known, then click the search icon if the correct incident is displayed, click use selected incident to link the incident with the event you can also click the search icon to search for and find the appropriate incident then click use selected incident to link the incident with the event about event correlation you can create custom business rules and saved searches to notify users about events based on the event type for example, you can create a triggered action business rule that automatically creates an alert whenever there is a application outage you can also create a triggered action business rule that links all events with the same description across all configuration items for information about creating triggered action business rules, see creating a triggered action docid\ a5ujt2tbpnhh zdyrll2w for a list of the default events based saved searches, see default saved searches for events docid\ cwehowqq1dyrhv8zzrnsy
