Observability

Feature Preview: AlertStack

SolarWinds Platform continually monitors your alerts and correlates other problems that happened at the same time on related devices, pulling them together into a single alert cluster. SolarWinds Platform events, metrics, network configuration changes, server configuration changes, Syslog, Traps, Windows events, and device statuses that are considered unusual are included in AlertStack. Every polling interval, AlertStack checks related entities for new alerts and events and dynamically updates active alert clusters. AlertStack allows you to drill down on related entities and critical issues to deal with them efficiently.

First published date

5/24/2022 9:31 AM

Last published date

5/24/2022 9:31 AM

Overview

SolarWinds Platform continually monitors your alerts and correlates other problems that happened at the same time on related devices, pulling them together into a single alert cluster. SolarWinds Platform events, metrics, network configuration changes, server configuration changes, Syslog, Traps, Windows events, and device statuses that are considered unusual are included in AlertStack. Every polling interval, AlertStack checks related entities for new alerts and events and dynamically updates active alert clusters. AlertStack allows you to drill down on related entities and critical issues to deal with them efficiently.

The AlertStack page and AlertStack Summary widget group related alerts and events into a single view, providing a chronological list of the events and impacted entities, live tracking of all related events and alerts, and maps of entity relationships. You can view historical data and the timeline of the alerts to identify a possible root cause of the alert stack. AlertStack also helps you optimize your alert setup for future incidents.

Product section

Hybrid Cloud Observability

Resolution

Enable AlertStack

To enable and configure AlertStack, you must access Advanced Configuration settings as an administrator. For more information, contact Support.
 

View alert clusters

To access the AlertStack summary page, log in to the SolarWinds Platform Web Console as an administrator, and click My Dashboards > Home > AlertStack.
AlertStack Summary Page
  1. Details about the alert cluster.
  2. Cluster intervals: Severity of the cluster for the selected time frame. The duration is dependent upon the selected time interval (5).
  3. Sort: allows you to sort the clusters by Start Date, End Date, Cluster ID, Severity, State, Name, Alert count, and Entity count. Default is descending Start Date.
  4. Search: Search by name. To search by Cluster ID, precede the number by "cluster-"
  5. Time Frame Selector: Allows you to select standard time frames (Last hour, Last 12 hours, Last 24 hours, Last 5 days, Last 7 days) or a user-defined interval. Default is Last 24 hours.
  6. Next/Previous Time Frame: Move back in time by the currently selected time frame. The corresponding control on the right is displayed when in the past and allows for moving forward in time.
  7. Page Size: Changes the number of clusters per page. Default is 10.
  8. Next/Previous Cluster Page: Paging controls for the list of clusters.
  9. Configure Rules: Pop-up providing descriptions of the various settings that affect alert clustering along with what aspect of the alert cluster is affected. To configure AlertStack, you must access the Advanced Configuration settings as an administrator.
  10. What is AlertStack: Introduction to AlertStack.
You can also review the AlertStack Summary widget on the SolarWinds Platform Summary Home page (My Dashboards > Home > Summary).

AlertStack Summary Widget
AlertStack Summary Widget Details
  1. Severity and name of the cluster.
  2. Unique ID for the cluster.
  3. Cluster starting and ending time or "now" if ongoing.
  4. Cluster State:
    1. Closed: The cluster is no longer active because it was closed by a user.
    2. Open: The cluster is currently active.
    3. Suspended: Maps recording will occur once an hour since no changes have occurred after the time specified in the settings.
    4. Resolved: The cluster is no longer active because the end conditions have been met.
  5. Duration of the cluster.
  6. The total number of entities and alerts contained in the cluster.
The details for an alert cluster are displayed when you click on the description of the alert cluster in the AlertStack Summary Widget or AlertStack Summary page.
AlertStack Alert Cluster Details
  1. Cluster Elements: list of Alerts, SolarWinds Platform Events, Metric Threshold Changes, Metric Anomalies, NCM Change Events, SCM Change Events, Syslog, Traps, Windows Events, and Entity Status Changes, making up the alert cluster. 
  2. Cluster Severity History: Severity of the cluster over time with each interval representing the default interval duration of 10 minutes. 
  3. Cluster Element Info: Information about the cluster element including name, an associated entity, status, and severity. There are three primary types:
    1. icon-alert.pngAlert
    2. icon-metric-threshold.pngMetric Threshold
    3. icon-entity-status.pngEntity Status
    4. icon-event.pngEvent
  4. Cluster Start: The start of the cluster. The gray region to the left represents the history of the elements for 30 minutes prior to the start. Any elements in a warning or critical state in this region contributed to the creation of the cluster.
  5. Cluster End: The end of the cluster. If there is a gray region to the right, represents the history of the elements for 30 minutes following the end of the cluster to provide additional context for the end of the cluster.
  6. Selected Interval: The currently selected interval within the cluster.
  7. Cluster Map: A map of the elements in the currently selected interval for the cluster. 
  8. Entity Occurrences: The map defaults to displaying only the entities and their relationships. To see other elements (occurrences) related to an entity, click the purple dot (2) to show related elements. Click on the expanded purple dot (1) to collapse.    AlertStack Entity Occurrence
  9. Map Controls: Controls to zoom in, zoom out, and center the map. To pan, hold down the SPACE BAR and drag with the mouse.
  10. Panel Splitter Controls: The panel splitter controls allow the elements panel and the maps panel to be resized. The view map only button icon-up-arrow-map-only.png will adjust the panels to only show the cluster map. The view list only button icon-down-arrow-list-only.png will adjust the panels to only show the cluster elements list. The view list and map button icon-center.pngwill adjust the panels so that both the map and element lists are shown equally. To manually adjust the size, hover over the line between the panels then click and drag icon-click-and-drag.png.
  11. Previous/Next Time Range: Navigates back in time by the total number of intervals currently being displayed. The corresponding control on the right moves forwards in time if present. 
  12. Previous/Next Time Interval: Navigates back within the cluster by one interval. Updates the map to display the entities present during that interval. The corresponding button on the right moves one interval forward within the cluster.