{"id":4662,"date":"2013-07-02T00:28:32","date_gmt":"2013-07-02T00:28:32","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/20000academy\/blog\/2013\/07\/02\/events-flood-mountain-creek\/"},"modified":"2025-05-27T15:25:38","modified_gmt":"2025-05-27T15:25:38","slug":"events-flood-mountain-creek","status":"publish","type":"post","link":"https:\/\/advisera.com\/20000academy\/blog\/2013\/07\/02\/events-flood-mountain-creek\/","title":{"rendered":"Events &#8211; a flood or mountain creek"},"content":{"rendered":"<p>It&#8217;s hard to live with them, but even harder without them. Events \u2013 indicators of a healthy environment or signs of disease.<\/p>\n<p>According to <a href=\"https:\/\/advisera.com\/20000academy\/what-is-itil\/\" target=\"_blank\" rel=\"noopener noreferrer\">ITIL<\/a>, event can be defined as \u201cany change of state that has significance for the management of a configuration item (CI) or IT service.\u201d<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Why events and event management?<\/h2>\n<p>Imagine this as a patient lying in a hospital bed and being connected to all those fancy (let\u2019s be serious \u2013 very useful) devices. Properly configured, they can give a lot of needed (sometimes life-saving) information so doctors always have a clear picture about the state of the patient. But, if they produced useless reports and created information overflow, information that was needed to save the patient\u2019s life could get lost. It\u2019s the same in an IT environment.<\/p>\n<p><a href=\"https:\/\/advisera.com\/20000academy\/blog\/2013\/05\/27\/service-operation-itil\/\" target=\"_blank\" rel=\"noopener noreferrer\">Service operation procedure<\/a>\u00a0is responsible for &#8220;keeping the lights on,&#8221; i.e. taking care of live services. To execute this responsibly and efficiently, service operations need to know the status of the infrastructure and <a href=\"https:\/\/advisera.com\/iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">services<\/a> in their responsibility, as well as be able to detect any deviation from normal or expected operation. Events are the instruments that are used. Events are usually recognized through notifications created by an IT service, <a href=\"https:\/\/advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=service-portfolio-processes&amp;doc=configuration-management-database\" target=\"_blank\" rel=\"noopener\">CI (configuration item)<\/a> or monitoring tool. And, that\u2019s where the party begins. Someone has to define which monitoring data will be used, what they mean and what to do with them. That is the purpose of the Event Management process. Or, to put it officially, the purpose of event management is to manage events throughout their lifecycles.\u00a0<em>Lifecycle<\/em>\u00a0means activities to detect events, make sense of them and determine appropriate action.<br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Monitoring tools<\/h2>\n<p>Let\u2019s see what should be considered while designing the event management process. Event management is the basis for operational monitoring and control. There are two types of monitoring tools:<\/p>\n<ul>\n<li>Active monitoring tools \u2013 the tool polls CIs to determine their status. Exceptions will generate alerts that need to be communicated further (to appropriate tool or person\/team).<\/li>\n<li>Passive monitoring tools \u2013 the tool detects and correlates alerts generated by CIs and performs predefined actions.<\/li>\n<\/ul>\n<p>We have to draw the line here between monitoring tools and Event Management tools. Monitoring tools are, usually, specialized tools for certain technology. They monitor and create events. Event Management tools are, usually, part of the IT Service Management tool and integrate the Event Management process with other ITIL processes (e.g. Incident Management). They take over events from monitoring tools and introduce them to the Event Management process (or, in other words, workflow).<\/p>\n<p>Monitoring tools can generate a lot of events (or a flood \u2013 from the title). Some are less useful, while other could be very useful. Therefore, Event Management uses categorization, filtering and correlation.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">Three types of events<\/h2>\n<p>What I usually find are three types (i.e. categories) of events:<\/p>\n<ul>\n<li>Informational \u2013 such events are for informational purposes and don\u2019t require any type of action. What usually happens with such events is that they are stored in log files. Purpose \u2013 e.g. statistics. Example: a user has logged in to an application.<\/li>\n<li>Warning \u2013 an event indicates a situation that must be checked, followed by certain action. Example: a server\u2019s RAM utilization is above 75%.<\/li>\n<li>Exceptional \u2013 this event indicates that a CI or service operates abnormally. Usually, the <a href=\"https:\/\/advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=relationship-and-agreement-processes&#038;doc=service-level-agreement-sla-\" target=\"_blank\" rel=\"noopener\">Service Level Agreement (SLA)<\/a> or business process is breached.<\/li>\n<\/ul>\n<p>Of course, based on real situations, categorization can vary. That depends also on tools that are used and other IT Service Management processes.<\/p>\n<p style=\"text-align: center;\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-10614\" src=\"\/wp-content\/uploads\/\/sites\/6\/2015\/07\/Incident-generation_filtering_and_correlation1.png\" alt=\"Incident generation_filtering_and_correlation\" width=\"460\" height=\"270\" \/><em>Figure: Incident generation, filtering and correlation<\/em><\/p>\n<p>Filtering and correlation can take place either on monitoring tools or on Event Management tools. I experienced that it is more useful if a monitoring tool filters and correlates, but this is not very often (usually, this means further investment). Filtering means that not all events should be communicated to the Event Management tool. Some events don\u2019t bring any valuable information (but they are generated due to an inability to turn off the notification), and it is better to keep them either on CIs (that generate events) or inside the monitoring tool. When events are already generated, it must be decided what to do and how to proceed with them. This is a job of correlation. Correlation will separate events into categories (remember \u2013 informational, warning, exceptional) and add some logic. E.g. only the first in a series of events related to the same CI will be communicated to the Event Management tool.<\/p>\n<h2 style=\"padding-top: 10px; padding-bottom: 10px;\">How do we implement all this?<\/h2>\n<p>How do we implement filtering and correlation? An ideal situation is when there is a managing monitoring tool in place. Such a tool will pick up all notifications, i.e. events from other tools, apply filtering and correlation logic and communicate with the Event Management tool. But, in real life, the situation is vice-versa. The Event Monitoring tool is used for filtering and correlation. To be able to do that, it has to have the ability to communicate with monitoring tools. E-mail is one of the common technologies. E-mail that is sent to the Event Management tool contains a keyword, which is recognized by the Event Management tool; after receipt, workflow (inside Event Management tool) decides what to do with the event (i.e. performs filtering). This is how (remember, from the title) a mountain creek is created.<\/p>\n<p>Although Event Management sounds simple, it is not. Not because of the Event Management process, but because of what comes before the process begins. A flood does not happen when a river enters the ocean, but much earlier. A lot of water gates must be in place to avoid it.<\/p>\n<p><em>To implement ISO 20000 easily and efficiently, use our<\/em> <a href=\"https:\/\/advisera.com\/20000academy\/iso-20000-documentation-toolkit\/\" target=\"_blank\" rel=\"noopener\">ISO 20000 Documentation Toolkit<\/a> <em>that provides step-by-step guidance for full ISO 20000 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s hard to live with them, but even harder without them. Events \u2013 indicators of a healthy environment or signs of disease. According to ITIL, event can be defined as \u201cany change of state that has significance for the management of a configuration item (CI) or IT service.\u201d Why events and event management? Imagine this &#8230;<\/p>\n","protected":false},"author":32,"featured_media":4663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[408,344,385],"class_list":["post-4662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-event","tag-itil","tag-service-operation"],"acf":[],"_links":{"self":[{"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/4662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/comments?post=4662"}],"version-history":[{"count":3,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/4662\/revisions"}],"predecessor-version":[{"id":18319,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/4662\/revisions\/18319"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/media\/4663"}],"wp:attachment":[{"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/media?parent=4662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/categories?post=4662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advisera.com\/20000academy\/wp-json\/wp\/v2\/tags?post=4662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}