Skip to main content

Event Notification Format

Common Alert Template

The common template can be applied in most cases. It allows you to receive alerts in a consistent format across various environments.

  • Product Type: Application, Database, Kubernetes
  • Event Type: Application Alerts, Database Alerts, Metrics Alerts
  • Event Channel: SMS, Mobile, 3rd-party plugins, Plugins

Event Title

Event title format
[Level][Platform][ProjectName][ApplicationName][EventTitle]
Event title example
[Info][JAVA][Application Project][TC-0-1-8081][CRITICAL_HIGH_MEMORY]
Note

If ApplicationName is not set, it is omitted from the event title.

  • Platform is displayed as one of the following.
    • JAVA
    • NODEJS
    • PYTHON
    • PHP
    • DOTNET
    • GO
    • POSTGRESQL
    • ORACLE
    • MYSQL
    • MSSQL
    • BSM_JAVA
    • CLOUDWATCH
    • TIBERO
    • KUBERNETES
    • KUBE_NS
    • URLCHECK
    • URLCHECK_ADMIN
    • CUBRID
    • ALTIBASE
    • CLUSTER
    • REDIS
    • MONGODB
    • VR
    • RUM

Event Message

This section describes the information that can be included in the event message. If optional is set to false, the item is always included in the message. If optional is set to true, the item is displayed only when the data is available.

Event message example
Project Name : Application Project
Project Code : 3
Agent Name : TC-0-1-8081
Message : RECOVERED: Memory is too high. less than 10%
Event Time : 2022-04-12 18:53:24 +0900
Event OFF Time : 2022-04-12 18:53:24 +0900
Alert Type : APPLICATION_MEMORY
Metric Name : memory
Metric Value : 20
Metric Threshold : 10
Stateful : true
Table | Event Message Components
EnKoSupported Alert TypesDescription
Project NameProject nameAll-
Project CodeProject codeAll-
Agent NameAgent nameAll (optional)oname
MessageEvent messageAll-
Alert TypeAlert typeAllSee the AlertType table below
Event TimeEvent occurrence timeAllIn 2022-04-13 10:40:49 +0900, +0900 indicates the GMT offset
Event Off TimeEvent recovery timeAll (optional)In 2022-04-13 10:40:49 +0900, +0900 indicates the GMT offset
Metric NameMetric nameAll (optional)Name of the metric used to evaluate the event condition
Metric ValueMetric valueAll (optional)Included when the metric value exceeds the threshold
Metric ThresholdMetric thresholdAll (optional)Threshold value used to determine the event condition
StatefulRecovered-event notificationAll (optional)true if recovered-event notification is enabled; otherwise false
Event RuleEvent trigger conditionMetrics alerts-
Target FilterEvent target filterMetrics alertsEvaluates event conditions only for metrics collected from specific targets
Repeat CountEvent repeat countMetrics alertsThe event is triggered when the condition is met the specified number of times within the repeat duration
Repeat DurationEvent repeat durationMetrics alertsTime window used to evaluate the repeat count
ReceiverReceiverMetrics alerts-
QueryMXQL queryComposite metrics alerts-
RuleEvent trigger conditionComposite metrics alerts-
Query PeriodQuery periodComposite metrics alerts-
Query IntervalQuery intervalComposite metrics alerts-
Silent TimeSilent timeComposite metrics alerts-
QueryURLException alertsURL of the request that caused the exception
TXIDTransaction IDException alerts-
ClassError class nameException alerts-
Log MessageLog messageServer – file log alerts-
Log FileLog file pathServer – file log alerts-
IPIP addressAll server alerts-
CPUCPU usageAll server alertsSnapshot at the time the event occurred
CPU_load1CPU load (1 min)All server alertsSnapshot at the time the event occurred
CPU_loadPerCoreCPU load per coreAll server alertsSnapshot at the time the event occurred
MemoryMemory usageAll server alertsSnapshot at the time the event occurred
SwapSwap usageAll server alertsSnapshot at the time the event occurred
Disk Name | Used Percent | Free Size | IO PercentDisk performanceAll server alertsSnapshot at the time the event occurred
Name | Bps | PpsNetwork traffic performanceAll server alertsSnapshot at the time the event occurred
Message | Time | NameAcknowledgement informationAll server alerts-
Note

This section displays as much information as possible that can be provided for the event.

  • AlertType is displayed as one of the following values.
AlertTypeDescription
APPLICATION_CPUApplication CPU alert
APPLICATION_MEMORYApplication memory alert
APPLICATION_DISKApplication disk alert
APPLICATION_ACTIVE_TRANSACTIONApplication active transaction alert
APPLICATION_ERROR_TRANSACTIONApplication error transaction alert
APPLICATION_SLOW_TRANSACTIONApplication slow transaction (response time) alert
METRICSMetrics alert
COMPOSITE_METRICSComposite metrics alert
ANOMALYAnomaly detection alert
LOG_REALTIMEReal-time log alert
COMPOSITE_LOGComposite log alert
SERVER_REBOOTServer reboot alert
SERVER_NO_DATAServer no-data alert
SERVER_PORTServer port alert
SERVER_NETWORK_IOPSServer network IOPS alert
SERVER_NETWORK_BPSServer network BPS alert
SERVER_DISK_IOServer disk I/O alert
SERVER_DISK_QUOTAServer disk usage alert
SERVER_DISK_INODEServer inode alert
SERVER_CPUServer CPU alert
SERVER_MEMORYServer memory alert
SERVER_CPU_STEALServer CPU steal alert
SERVER_MEMORY_SWAPServer swap memory alert
SERVER_LOG_FILEServer log file alert
SERVER_WINDOW_EVENTServer Windows event alert
SERVER_OFFServer alert OFF notification
SERVER_ACKNOWLEDGEServer acknowledge notification
SERVER_PROCESS_COUNTServer process count alert
SERVER_PROCESS_CPUServer process CPU alert
SERVER_PROCESS_MEMORYServer process memory alert
SERVER_PROCESS_OFFServer process alert OFF notification
AGENT_ACTIVEAgent activated alert
AGENT_INACTIVEAgent deactivated alert
AGENT_REACTIVATEDAgent reactivated alert
URLURL alert
TOO_MANY_EVENTToo many events alert
CLOUD_WATCHCloudWatch alert
EXCEPTIONException alert

Server Alert Templates

Note

Server monitoring uses a different alert template as an exception.

  • Product Type: Server
  • Event Type: Server Alerts, Process Alerts, Log File / Windows Event Alerts
  • Event Channel: SMS, Mobile, 3rd-party plugins, Plugins

Event Title

Event title format
[Level][INFRA] ProjectName ServerName EventTitle
Event title example
[Info][INFRA] Server Project TC-0-1-8081 CPU Used > 70%
Note

If ServerName is not specified, it is omitted from the event title.

Event Message

This section describes the information that can be included in an event message. If optional is set to false, the information is always included in the message. If optional is set to true, the information is displayed only when the data is available.

Event message example
Project Name : Application Project
Project Code : 3
Server Name : TC-0-1-8081
Event Message : [TEST] RECOVERED: Memory is too high. less than 10%
Event ON Time : 2022-04-12 18:53:24 +0900
Event OFF Time : 2022-04-12 18:53:24 +0900
Alert Type :
Metric Name : memory
Metric Value : 20
Metric Threshold : 10
Stateful : true
Table | Event Message Components
EnKoOptionalDescription
Project NameProject Namefalse-
Project CodeProject Codefalse-
Server NameAgent Nametrueoname
Event MessageEvent Messagefalse-
Event ON TimeEvent Occurred TimefalseIn 2022-04-13 10:40:49 +0900, +0900 indicates GMT offset.
Event OFF TimeEvent Cleared TimetrueIn 2022-04-13 10:40:49 +0900, +0900 indicates GMT offset.
Elapsed TimeEvent Durationtrue-
Alert TypeAlert Typetrue-
Policy NameAlert Policy Nametrue-
Metric NameMetric NametrueThe name of the metric used to evaluate the event condition.
Metric ValueMetric ValuetrueIndicates that the event condition is met when the metric value exceeds the threshold.
Metric ThresholdMetric ThresholdtrueIndicates that the event condition is met when the metric value exceeds the threshold.
Event RuleEvent Ruletrue-
Alert TypeAlert TypetrueA field used to identify the event type.
Event Target FilterEvent Target Filtertrue(Metrics alerts) Evaluates event conditions only for metrics collected from specific targets.
StatefulResolved Event Notificationtruetrue if resolved event notifications are enabled, otherwise false.
Repeat CountEvent Repeat Counttrue(Metrics alerts) An event is triggered only when the condition is met the specified number of times within the repeat duration.
Repeat DurationEvent Repeat Durationtrue(Metrics alerts) An event is triggered only when the condition is met the specified number of times within the repeat duration. Applies to resolved events.
IPIPtrue-
Log ContentLog Contenttrue-
Log SourceLog Sourcetrue-
CPUCPUtrue-
CPU_load1CPU_load1true-
CPU_loadPerCoreCPU_loadPerCoretrue-
MemoryMemorytrue-
SwapSwaptrue-
Disk Name / Used Percent / Free Size / IO PercentDisk Name / Used Percent / Free Size / IO Percenttrue-
Traffic Name / Bps / PpsName / Bps / Ppstrue-
Acknowledge Message / Time / NameAcknowledge Message / Time / Nametrue-

Server Alert Notifications

Server alerts provide only an Event Message without an Event Title.

Server Alerts

Event TypeEvent LevelEvent MessageEvent Off Message
RestartCritical"System Rebooted"Not supported
No DataWarning"Agent No Data"Not supported
PortWarning"Port ${port} is down""Port ${port} is up"
Port (IP available)Warning"IP ${ip} Port ${port} is down""IP ${ip} Port ${port} is up"
Network IOPSWarning or Critical"NETWORK ${deviceId} pps > ${value} pps"-
Network BPSWarning or Critical"NETWORK ${deviceId} bps > ${value} bps"-
Disk I/OWarning or Critical"Disk ${mountPoint} IO Usage > ${value} %"-
Disk UsageWarning or Critical"Disk ${mountPoint} Used > ${value} %"-
inodeWarning or Critical"Disk ${mountPoint} inode usage > ${value} %"-
CPUWarning or Critical"CPU Used > ${value} %"-
MemoryWarning or Critical"Memory Used > ${value} %"-
StealWarning or Critical"CPU Steal > ${value} %"-
SwapWarning or Critical"Swap Used > ${value} %"-

Process Alerts

Event TypeEvent LevelEvent MessageEvent Off Message
Process Count (Warning)Warning or Critical"Process ${processName} Count >= ${value}""Process ${groupName} Count < ${value}"
Process Count (Critical)Warning or Critical"Process ${processName} Count < ${value}""Process ${groupName} Count >= ${value}"
Process CPUWarning or Critical"Process ${processName} CPU > ${value}"-
Process MemoryWarning or Critical"Process ${processName} Memory > ${value}"-

Log Files and Windows Events

Event TypeEvent LevelEvent MessageEvent Off Message
Event TypeEvent LevelEvent MessageEvent Off Message
LOG_DEFAULTWarning or CriticalLOG ${logContent}"-
LOG_FILEWarning or CriticalLOG File: ${filePath}, Keyword : ${keyword}, [Event] ${logContent}"-
LOG_WINDOW_EVENTWarning or CriticalLOG ${logContent}"-
LOG_AUDITWarning or CriticalAUDIT ${logContent}"-
LOG_SCRIPTWarning or CriticalSCRIPT ${logContent}"-