Having event-driven monitoring (coming from different sources) I have hit upon an issue:
Note: Configuration is as follows:
Events are mapped via ETI Mappings rules into Health Indicators, which then feed KPIs.
If an event is manually closed (hitting the "close event button on the UI), the even'ts corresponding HI does not revert back to its default status (good). It remains at the severity of the event, even though now there is no event to feed it its status.
Add to that some Time-Based event automation (closing all events older than 7 days), and I get a LOT of "phantom" statuses - CIs which are in critical condition and with no associated event.
THis makes all the services trees permenantly red, making it completely useless...
The events that do this are usually SNMP Traps, that do not send corresponding "all clear" events.
How to get around this? I need HIs to revert back to their default statuses when the events are gone... This way it makes no sense whatsoever...