Main Page | Modules | Alphabetical List | Data Structures | File List | Data Fields | Globals | Related Pages

limiterhandler.h File Reference


Detailed Description

The limiterhandler is an event rate limiter. This handler is useful to mitigate notification storms and false alarms. It receives events and limits the rate of events it forwards to "downstream" handlers.

There are 2 modes: time and rate. In the time mode, you specify a time period and at most 1 event with the same id per time period will be forwarded. In the rate mode, you specify a time period 'M' and a number of events 'N' and the handler forwards one event for every 'N' incoming events with the same id in 'M' seconds.

For example, a limiterhandler is useful is in combination with a logfileprobe that is filtering for events, any one of which is not that interesting, but a burst of these in a short period of time is interesting. In this case you would use the rate mode to define an "interesting burst".

The noid: option will configure the limithandler to ignore the event's id and limit ALL incoming events. This is useful for situations where that you have related but different events you want to limit.

Wire keywords (standard handler keywords documented in Wire )

Example:

// create the event signature for filtered events set alert create event { name: "down machine" }

// make the handler, assumes you have bound 'events' to list of events you care about. create handler limiter { time-period: 1800 output-event: $alert regevent: $events elogger: $hlogger }

Events accepted:
Event NameTypeDescription
event any If event arrival rate >= rate specified by limiter, then copy event

#include <stdio.h>
#include "monitor.h"
#include "wire.h"

Go to the source code of this file.

Data Structures

struct  aw_limiterhandler_t
 Limiter handler object. More...

struct  aw_limithandler_event_count_t

Functions

aw_limiterhandler_t * aw_create_limiterhandler (u_int32_t event_threshold, aw_timestamp_t time_period, const aw_event_sig_t *copy_sig, u_int32_t noid, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *aware_logger)
 Create a limiter handler.

void aw_free_limiterhandler (aw_limiterhandler_t *h)
 Free handler and all associated resources.

aw_handler_t * aw_wire_limiterhandler (aw_wire_mkhandler_args_t *args)
 Create a limiterhandler using "wire". See header doc for keyword documentation.


Function Documentation

aw_limiterhandler_t* aw_create_limiterhandler (  u_int32_t  event_threshold,
aw_timestamp_t  time_period,
const aw_event_sig_t *  copy_sig,
u_int32_t  noid,
int32_t(*  regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
int32_t(*  regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
const aw_alarm_sched_t *  sched,
aw_logger_t *  aware_logger
) 
 

Create a limiter handler.

aw_create_limiterhandler

Parameters:
event_threshold How many events... (if 0 -> only do time based limiting)
time_period In what period
copy_sig The event sig to use for copies
noid Ignore event id when limiting (limit all incoming events as a group)
regevent Function pointer for event registration
regmaskevent Function pointer for event mask registration
sched Run schedule
aware_logger Aware logger object
Returns:
Handler object

void aw_free_limiterhandler (  aw_limiterhandler_t *  h  ) 
 

Free handler and all associated resources.

aw_free_limiterhandler

Parameters:
h The handler

aw_handler_t* aw_wire_limiterhandler (  aw_wire_mkhandler_args_t *  args  ) 
 

Create a limiterhandler using "wire". See header doc for keyword documentation.

aw_wire_limiterhandler

Aware 0.11.1 Copyright (C) 1998-2005 Russell Leighton (russ@elegant-software.com)