Message Rate Alerting can be configured so that an alert is sent if the number of logs being received from hosts by SSB either drops below or exceeds certain limits.
To configure message rate alerting
- Navigate to SSB > Log > Sources
- Choose which source requires monitoring
- Enable Message rate alerting.
- Select the counter to be measured:
- Messages: Number of messages
- Messages/sender: Number of messages per sender (the last hop)
- Messages/hostname: Number of messages per host (based on the hostname in the message)
- Select the time period (between 5 minutes and 24 hours) during which the range is to be measured.
- Enter the range that is considered normal in the Minimum and Maximum fields.
- Select the alerting frequency in the Alert field. Once sends only one alert (and after the problem is fixed, a "Fixed" message), Always sends an alert each time the result of the measurement falls outside the preset range.
For more detailed information please see the section “Configuring message rate alerting” in the admin guide.