Creating an Alert Rule for a Hawk Agent

In the Hawk Console, you can define rules to generate alerts or emails based on predefined test condition. The test condition can be designed by using the rulebase and microagent variables.

 

Procedure

1. In the Hawk Console, open the Hawk Agent page for which you want to create the rule.
For steps, see Viewing the Agent Details.
2. In the Agent’s page, select the Rulebases tab.
All the rulebases for the Hawk agent are displayed. For details, see Rulebases Tab.
3. Click on an existing rulebase name to which you want to add the new rule.

Or, you can add a new rulebase to the agent and add a new rule to it, see Adding a Rulebase to the Hawk Agent.

Details of the rulebase and list of all its rules are displayed on the Rulebase tab.

4. In the Rules section, click the plus icon.
The New Rule wizard opens.
5. In the New Rule wizard, enter the value for the fields and click Create and Add Test.
Some of the common fields are listed in the following table.

 

New Rule Wizard Common Fields

Fields

Description

Microagents

Select the microagent whose method you want to use for the rule.

Methods

Select the microagent method that you want to use in the rule. The list displays only those methods that are relevant to the microagent selected.

Based on the microagent method selected, some more fields might be displayed on the wizard.

Interval

Enter the time interval after which the rule runs. The default value is 60 (seconds).

Schedules

Select the name of an existing schedule to apply to this rule. This is an optional field. By default, the rule is always active.


The New Test window opens to enter the details for the condition to test for the rule.

6. In the New Test window, create the test condition by using the existing fields and click Create and Add Action. For details of defining the test condition, see Creating a Test in the Rule.

The New Action window opens to add an appropriate action for the rule if the test condition is true.

7. In the New Action window, select the action you want to perform and enter the details to relevant fields. The following actions are available:
Alert
Notification
Method
Email
Post-Condition

For details, see Creating an Action for a Test Condition.

8. Click Create Action to create a new action for the test condition.
The New Rule wizard closes and the action is created for the test condition created.

What to do Next

Deploy the rulebase to the domain for the new rule to take effect, see Deploying a Rulebase to the Associated Hawk Agent.