Ad Widget

Collapse

Alert Rule Not Triggering

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • HANDL_Eric
    Junior Member
    • Aug 2023
    • 27

    #1

    Alert Rule Not Triggering

    Hello,

    we recently completed a ticketing integration and built a new trigger action along side our existing email rule. Well despite the very simple logic, the 1st rule that says anything Warning or higher, email admins fires as expected while the new rule that says anything Warning or higher from a specific host group, open ticket does not.

    We can see in the action log on each event that there wasn't an attempt made against the 2nd rule and we can't figure out why (We verified the host group membership). Is there a more verbose log somewhere that logs the evaluation of alert triggers as each alert fires that we can look at? Just unsure where to go from here.
  • PeterZielony
    Senior Member
    • Nov 2022
    • 146

    #2
    It seems looks like media is simply wrong.

    Hiring in the UK? Drop a message

    Comment

    • HANDL_Eric
      Junior Member
      • Aug 2023
      • 27

      #3
      Originally posted by PeterZielony
      It seems looks like media is simply wrong.
      As part of troubleshooting I changed the trigger action operation to "Send message to users" via "Email (HTML)" and included my user account which already received email notifications from the other rule just fine and am still not seeing a trigger event nor am I receiving an email so I still really want to figure out how to identify why it's not hitting.

      Comment

      • irontmp
        Member
        • Sep 2023
        • 36

        #4
        Originally posted by HANDL_Eric
        Hello,

        we recently completed a ticketing integration and built a new trigger action along side our existing email rule. Well despite the very simple logic, the 1st rule that says anything Warning or higher, email admins fires as expected while the new rule that says anything Warning or higher from a specific host group, open ticket does not.

        We can see in the action log on each event that there wasn't an attempt made against the 2nd rule and we can't figure out why (We verified the host group membership). Is there a more verbose log
        do coyotes migrate the evaluation of alert triggers as each alert fires that we can look at? Just unsure where to go from here.
        I have a simple Alert Rule setup, sate is not closed. Auto open is checked and a incident task template is defined. Event comes in, get converted to an alert, but the alert rule does not create the incident. Is there some place I can see a log of what is going on? All Logs tables isn't giving me anything useful and I do have debugging turned on in the event preferences. I am not sure what is going with this rule, we only have one rule right now and it works just fine in my dev instance but not the client instance.

        Comment

        • HANDL_Eric
          Junior Member
          • Aug 2023
          • 27

          #5

          I think we actually just figured it out on accident.

          1) The alert rule when testing with email config was failing due to some sort of permission issue. Turns out the alerting mailbox I had added to Zabbix was configured as a guest user and as such there must be something in Zabbix that prevents notifications from triggering against guests, once I changed it to me a standard user it started triggering and sending emails as expected.

          2) back to the original problem, turns out it was firewall related although I still don't understand why these didn't appear as failed executions in the action list.

          Comment

          • HANDL_Eric
            Junior Member
            • Aug 2023
            • 27

            #6
            Looks like we're still running into this to some degree. I created a new alert for monitoring proxy disconnects which triggers a high sev alert. From there we have an alerting rule setup to email all of the Zabbix admins for anything warning+.

            Just like before we can see this alert trigger on the dahboard, but there is no action list shown - just the active alert sitting there. Anything else out there which triggers such as high CPU, storage, system unreachable, etc emails us just fine - but this alert for whatever reason doesn't appear to be hitting the alert trigger action and we can't figure out why.

            Comment

            • HANDL_Eric
              Junior Member
              • Aug 2023
              • 27

              #7
              Are alerts for devices monitor by a proxy sent from the Proxy itself or from the primary Zabbix server? I jsut realized that of all the alerts that aren't senting emails - they are being monitored by a remote proxy that doesn't have access to an smtp server.

              Comment

              • HANDL_Eric
                Junior Member
                • Aug 2023
                • 27

                #8
                Turns out that was a learning moment on our end - The alerts weren't firing because the users receiving the alerts didn't have read objects to the Zabbix infrastructure host group.

                Comment

                Working...