Preset Rules

ArcSight Management Center includes preset rules to assist in monitoring. You can use these preset rules as written or customize them as needed for your own use. You can also create custom rules of your own.

By default, ArcMC preset rules are disabled. You must enable a preset rule in order for it to apply and trigger alerts.

Note: For customers with previous versions of ArcMC and who already have a list of existing rules, preset rules included in ArcMC are appended to your existing rules.

To review preset rules:

  1. Click Dashboard > Rules. The Monitoring Rules summary is shown.

  2. To view a rule's settings in detail, in the Name column, click the rule name.
  3. To enable a disabled preset rule, under Status, select Enable.

Preset Rules Description

Name Description Products
MM_DD_YYYY_RAID_BATTERY_Failed_ArcMC_ConApp_Logger Displays a critical alert when the Raid Battery has failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_POWER_SUPPLY_Failed_ArcMC_ConApp_Logger Displays a critical alert when the Power supply has failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_TEMPERATURE_Failed_ArcMC_ConApp_Logger Displays a critical alert when the temperature reaches a certain level during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_POWER_SUPPLY_Degraded_ArcMC_ConApp_Logger Sends a warning when the power supply has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_VOLTAGE_Failed_ArcMC_ConApp_Logger Displays a critical alert when the voltage levels have been failing during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_FAN_Failed_ArcMC_ConApp_Logger Displays a critical alert when the fan has failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_HARD_DRIVE_Rebuilding_ArcMC_ConApp_Logger Sends a warning when the hard drive has been rebuilding during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_RAID_CONTROLLER_Failed_ArcMC_ConApp_Logger Displays a critical alert when the RAID controller has failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_CURRENT_Degraded_ArcMC_ConApp_Logger Sends a warning when the current has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_RAID_CONTROLLER_Degraded_ArcMC_ConApp_Logger Sends a warning when the raid controller has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_VOLTAGE_Degraded_ArcMC_ConApp_Logger Sends a warning when the voltage has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_ALL_EPS_OUT_ArcMC_ConApp_Logger Displays a critical alert when all outgoing events per second have failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_HARD_DRIVE_Failed_ArcMC_ConApp_Logger Displays a critical alert when the hard drive has failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_Queue Files Accumulated Displays a critical alert when files have accumulated in queue during the last 5 minutes.       Connector
MM_DD_YYYY_Full GC Sends a warning when the garbage collection count is higher than 7 during the last 60 minutes.       Connector
MM_DD_YYYY_Caching Sends a warning when the connector caching is higher than 100 during the last 5 minutes.       Connector
MM_DD_YYYY_Receiver Down Sends a warning when the receiver has been down during the last 5 minutes.     Logger  
MM_DD_YYYY_Events Dropped from Cache Displays a fatal alert when the connector events dropped from cache have been down during the last 5 minutes.       Connector
MM_DD_YYYY_Files Dropped From Cache Displays a critical alert when the connector files dropped from cache have been down during the last 5 minutes.       Connector
MM_DD_YYYY_Logger Not Receiving Data Displays a fatal alert when logger hasn't recevied data during the last 30 minutes.     Logger  
MM_DD_YYYY_Storage Disk Usage above 85% Sends a warning when the storage limit goes over 85% during the last 5 minutes.     Logger  
MM_DD_YYYY_JVM_MEMORY_ArcMC_ConApp_Logger Sends a warning when the jvm memory reaches 800 GB during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_Connector Restart Sends a warning when the connector has restarted more than 5 times during the last 5 minutes.       Connector
MM_DD_YYYY_Memory Red Zone Displays a critical alert when the Connector JVM memory has gone over 90% during the last 5 minutes.       Connector
MM_DD_YYYY_Memory Yellow Zone Sends a warning when the Connector JVM memory has gone over 80% during the last 5 minutes.       Connector
MM_DD_YYYY_Events Dropped From Queue Displays a fatal alert when more than 100 Connector queue events dropped during the last 5 minutes.       Connector
MM_DD_YYYY_Files Dropping From Queue Displays acritical alert when Connector files dropped from queue during the last 5 minutes.       Connector
MM_DD_YYYY_RAID_BATTERY_Degraded_ArcMC_ConApp_Logger Sends a warning when the raid battery has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_TEMPERATURE_Degraded_ArcMC_ConApp_Logger Sends a warning when the temperature has been degraded during the last 5 minutes in ArcMC ConApp Logger  
MM_DD_YYYY_EPS_OUT_Connector Displays a critical alert when the outgoing events per second have been degraded during the last 5 minutes.       Connector
MM_DD_YYYY_FAN_Degraded_ArcMC_ConApp_Logger Sends a warning when the fan's RPMS have failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_HARD_DRIVE_Degraded_ArcMC_ConApp_Logger Sends a warning when the hard drive has been degraded during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_ALL_EPS_IN_ArcMC_ConApp_Logger Displays a critical alert when all incoming events per second have failed during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_CPU_USAGE_ArcMC_ConApp_Logger Sends a warning when the cpu usage has exceeded 50% during the last 5 minutes. ArcMC ConApp Logger  
MM_DD_YYYY_QUEUE_DROP_COUNT_Connector Sends a warning when Objects droppped from file Queue during the last 5 minutes.       Connector
MM_DD_YYYY_CURRENT_Failed_ArcMC_ConApp_Logger Displays a critical alert when the current has failed during the last 5 minutes. ArcMC ConApp Logger