There are 2 modes: time and rate. In the time mode, you specify a time period and at most 1 event with the same id per time period will be forwarded. In the rate mode, you specify a time period 'M' and a number of events 'N' and the handler forwards one event for every 'N' incoming events with the same id in 'M' seconds.
For example, a limiterhandler is useful is in combination with a logfileprobe that is filtering for events, any one of which is not that interesting, but a burst of these in a short period of time is interesting. In this case you would use the rate mode to define an "interesting burst".
The noid: option will configure the limithandler to ignore the event's id and limit ALL incoming events. This is useful for situations where that you have related but different events you want to limit.
Wire keywords (standard handler keywords documented in Wire )
// create the event signature for filtered events set alert create event { name: "down machine" }
// make the handler, assumes you have bound 'events' to list of events you care about. create handler limiter { time-period: 1800 output-event: $alert regevent: $events elogger: $hlogger }
Events accepted:
| Event Name | Type | Description |
|---|---|---|
| event | any | If event arrival rate >= rate specified by limiter, then copy event |
#include <stdio.h>
#include "monitor.h"
#include "wire.h"
Go to the source code of this file.
Data Structures | |
| struct | aw_limiterhandler_t |
| Limiter handler object. More... | |
| struct | aw_limithandler_event_count_t |
Functions | |
| aw_limiterhandler_t * | aw_create_limiterhandler (u_int32_t event_threshold, aw_timestamp_t time_period, const aw_event_sig_t *copy_sig, u_int32_t noid, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *aware_logger) |
| Create a limiter handler. | |
| void | aw_free_limiterhandler (aw_limiterhandler_t *h) |
| Free handler and all associated resources. | |
| aw_handler_t * | aw_wire_limiterhandler (aw_wire_mkhandler_args_t *args) |
| Create a limiterhandler using "wire". See header doc for keyword documentation. | |
|
||||||||||||||||||||||||||||||||||||
|
Create a limiter handler. aw_create_limiterhandler
|
|
|
Free handler and all associated resources. aw_free_limiterhandler
|
|
|
Create a limiterhandler using "wire". See header doc for keyword documentation. aw_wire_limiterhandler |