Example A: Splunk can look for "Event A" across multiple hosts and if this event is found on more than one host within a time range, one alert notification is generated to the business unit.
Example B: UIM logmon or ntevl for example are deployed to multiple hosts and configured to monitor for "Event A", when found a unique alert is generated for each and every host for which "Event A" was found on. Problem: unable to combine those alerts and generate one alarm in their place.
Is there a way to combine alarms into one alarm? I don't see a way in UIM to do this based on how alarms are generated and processed. I may not have thought of all UIM's capabilities. Maybe there is a another CA/Broadcom product that can do this?
At this time I think my only option in this situation is to allow Splunk to perform this task and generate a single alarm to UIM through an SNMP integration.
Thoughts?