> For the complete documentation index, see [llms.txt](https://gsfcorp.gitbook.io/macula/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gsfcorp.gitbook.io/macula/administration-guide-v1.33.0/alarm-escalation-rules.md).

# Alarm Escalation Rules

Alarm escalation rules allow Macula to update alarms automatically if they remain in a specified state for a configured period of time. Use this feature when an alarm requires operator attention and must be escalated if it is not processed in time.

Alarms in Macula are based on bookmarks. For this reason, alarm escalation rules use alarm/bookmark properties, such as resource, severity, workflow state, and inactivity duration, to determine when an alarm must be escalated.

To access alarm escalation rules in Macula Console, open Events & Actions and select Alarm escalation rules from the menu on the left.

#### Add Alarm Escalation Rules

To create an alarm escalation rule:

1. Open *Events & Actions > Alarm escalation rules*.
2. Click + *New* and select *New alarm escalation rule*.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FEHKFJLXywjyPPavxtlrF%2Fimage.png?alt=media&amp;token=9ecc74e2-325e-470f-9a5b-605f449073b2" alt=""><figcaption></figcaption></figure>

3. Enter the rule title.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FkrosXqLE4lnFnaGG00sz%2Fimage.png?alt=media&amp;token=e8782224-e64f-43e9-a628-a0ae5dda958d" alt=""><figcaption></figcaption></figure>

4. Make sure *Enable* is selected if the rule should start processing alarms.
5. Select a resource. The resource can be a channel or a channel group.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FZMYt3Sglwp4cfl4oyxeP%2Fimage.png?alt=media&amp;token=731c2cc4-e222-4457-8ee1-0f87f928453f" alt=""><figcaption></figcaption></figure>

6. Set the effective date and time. The rule processes existing alarms starting from this date and time.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2Fa1xymrEvYNwYz0X5wIe0%2Fimage.png?alt=media&amp;token=a39b88dd-a22d-4462-aee2-db90537fc0e5" alt=""><figcaption></figcaption></figure>

7. Configure the trigger conditions.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FFH9EaM6l86mqUE5036wS%2Fimage.png?alt=media&amp;token=7113c869-b49a-4e3b-8fdc-576ec954eb31" alt=""><figcaption></figcaption></figure>

8. Configure one or more escalation actions.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2F4drzvpDh42wGaOULdSZp%2Fimage.png?alt=media&amp;token=c8ef32b0-37fb-44cc-a963-a11289145653" alt=""><figcaption></figcaption></figure>

9. Click *OK* to save the rule.

The new rule appears in the Alarm escalation rules list. The list displays the rule title, ID, resource, severity filter, state filter, and effective date.

#### Rule Settings

The following settings are available for an alarm escalation rule:

* *Title*: user-defined rule name.
* *Enable*: enables or disables the rule.
* *Resource*: channel or channel group whose alarms can be processed by the rule.
* *Effective* *from*: date and time when the rule starts processing existing alarms.

#### Trigger Conditions

Trigger conditions define which alarms can be escalated and how long the alarms must remain in the matching condition before the escalation is applied.

The following trigger conditions are available:

* *Trigger severity*: limits the rule to alarms with the selected severity. Available values are Info, Low, Normal, High, Critical, and Unknown.
* *Trigger state*: limits the rule to alarms with the selected workflow state.
* *Inactivity duration*: defines how long the alarm must remain in the trigger state before the rule escalates it.

If a trigger condition is not selected, that condition is not used for matching alarms.

#### Escalation Actions

Escalation actions define how Macula updates the alarm after all trigger conditions match for the configured inactivity duration.

The following escalation actions are available:

* *Target severity*: changes the alarm severity after escalation.
* *Target* *state*: changes the alarm workflow state after escalation.
* *Escalation* *message*: adds an automatic message to the alarm log.

For example, a rule can monitor alarms on the Perimeter channel with Normal severity. If an alarm remains in the selected trigger state for the configured inactivity duration, Macula can change the alarm severity, update its workflow state, and add an escalation message such as "Please review this alarm!"

#### Alarm Escalation Events

Each alarm escalation can generate an event. Use this event in the Events & Actions rules to run any supported action when an alarm is escalated.

To create an alarm escalation event:

1. Open *Events & Actions > Events*.
2. Click + *New* and select *New event.*

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2Fk4x5Qc1Y6fKvQhABXCUa%2Fimage.png?alt=media&amp;token=80b0029f-5c30-42a8-9fcb-d217c2b910b5" alt=""><figcaption></figcaption></figure>

3. In the list of available event types, select *Alarm escalation*.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2F8SAxDdYlqmUxmbRgIcCc%2Fimage.png?alt=media&amp;token=38671d62-0705-46f4-ac19-5af90be1a737" alt=""><figcaption></figcaption></figure>

4. Enter the event title

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FcXdJj7b5cQSDU3CINQ2F%2Fimage.png?alt=media&amp;token=26daa33c-ef2f-4893-981c-549f33ecc557" alt=""><figcaption></figcaption></figure>

5. In *Source*, select the alarm escalation rule that must trigger the event.
6. Click *OK* to save the event.

If the required alarm escalation rule does not exist yet, click + *New alarm escalation rule* in the source selection dialog and create the rule first.

#### Use Alarm Escalation Events in Rules

After creating the alarm escalation event, connect it to one or more actions in the Events & Actions configurator.

To configure the rule:

1. Open Events & Actions > Rules.
2. Click Open configurator.
3. In the Events pane, select the alarm escalation event.

<figure><img src="https://412599993-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeNXnJx0OpvxnmpWqOBNm%2Fuploads%2FMBA9RFdTjAZzTKHhl8FH%2Fimage.png?alt=media&amp;token=baf35399-bd3c-4f03-99df-1f2687ffbd8d" alt=""><figcaption></figcaption></figure>

4. In the *Actions* pane, select the action that must run when the alarm is escalated.
5. Use the arrow buttons to add the event and the action to the rule.
6. Click *OK* to save the rule.

The saved rule appears in the Rules list. The rule uses the alarm escalation rule as the source, the alarm escalation event as the event, and the selected action as the target action.

#### Use Escalation Details in Actions

Actions that support text fields can include event and action data. For example, the *Create bookmark* action provides *Insert field* buttons for the bookmark title and description.

The available fields include event ID, event title, event source ID, event source title, event date and time, event timestamp, action ID, action title, action target, action parameter, \`{ADDITION\_INFORMATION}\`, and \`{VALUE}\`.

Use \`{ADDITION\_INFORMATION}\` when the action text must include alarm details passed by the alarm escalation event. The escalation event can pass alarm/bookmark data such as alarm title, severity, status, and channel title through the additional information value.

For the *Create bookmark* action, you can also configure:

* *Target*: server where the action is available.
* *Bookmark title*: title of the bookmark created by the action.
* *Description*: bookmark description.
* *Severity*: bookmark severity.
* *Request user description*: asks the selected user or user group to enter a description. The request timeout value must be in the range from 5 to 9999999 seconds.
* *Create alarm*: makes the created bookmark appear in the alarm pane of Macula Monitor instances.
* *Time offset*: shifts the bookmark timestamp up to one minute earlier or later than the event time.
