Alert and Event Field Reference
This is a reference guide for alert and event fields, input types, field descriptions and output examples.
Field | Type | Description | Example Output |
---|---|---|---|
| Array | IDs of any Situations associated with the alert. | 1, 6, 8 |
| Text | Host machine or physical location of the agent that created the event. | OEM Monitor 1 |
| Text | Name of the agent that created the event. | NAGIOS SOCKET |
| Text | Host machine or physical location of the agent that created the event. | London Data Centre (51.4167,-0.2833) |
| Integer | Timestamp when the event occurred in epoch time. Use | 1516183437 |
| Integer | Internal identifier generated by Moogsoft Onprem. | 101 |
| Text | Level of classification for an event. This follows the hierarchy; | CISCO-IF-Extension-MIB |
| Integer | Number of events in the alert. | 2 |
| Text | Custom information added as a JSON encoded string. | custom_info.myNodeList=[ "node1" , "node2" , "node3" ] |
| Text | Text description of the alert. | Network Interface (ifIndex = 512479388 ) Up (ifEntry.52683483) |
| Integer | Measure of uncertainty of an outcome between 0 and 1 (0 meaning very certain and 1 meaning very uncertain). | 0.4 |
| Integer | Unique identifier from the event source. | 7622183 |
| Integer | Earliest event time for the alert. This is calculated from the | 14:08:14 16/01/2018 |
| Text | Name of the source machine that generated the event. | OEM Server 2 |
| Integer | Time that the latest event for the alert was received by the Moogsoft Onprem server. | 10:24:03 19/01/2018 |
| Integer | Time that the alert was last updated in the Moogsoft Onprem UI. | 12:38:06 19/01/2018 |
| Integer | Latest event time for the alert. This is calculated from the | 10:24:03 19/01/2018 |
| Text | General identifier of the event generator or intermediary. | NAGIOS, SCOM. |
| Text | Alert owner's username. | John Smith |
| Integer | Severity level of the alert between 0 and 5. | 4 |
| Integer | Relative Significance of an alert is calculated based on its entropy. | 3 |
| Array | Any Situations the alert is associated with, including those that have been resolved or closed. | 24, 01 |
| Text | Name of the source machine that generated the event. If there is no source machine or application, the source is the name of the instance (database name, cluster node, container name). | A hostname or fully qualified domain name (FQDN). |
| Text | Identifier for the source machine that generated the event. | 5dc68d65-532c-4918-be12-21e1cbcf7af2 |
| Text | Status of the alert. | Assigned |
| Text | Level of classification for an event. This follows the hierarchy; | CISCO-IF-Extension-MIB Notification |