I am not sure if this is possible, but am trying to figure out if it is - appreciate any insight.
We have a system that delivers 'up' and 'down' alerts for BGP link status. This is a libreNMS delivering to Opsgenie from incoming SNMP traps. We want opsgenie to alert us when a 'Down' alert is recieved, and an 'Up' alert so we know when peers recover on their own.
However, sometimes our routers issue fake 'up' alerts. We want to ignore these.
The logic I am trying to recreate goes something like this:
"If alert contains text 'BGP Up', then only notify if 'AS#####' (The AS number contained in the body of the alert) matches an AS##### in a previous alert recieved within the last, say 24 hours".
I've been reading through policies section, action filters and 'services' which still confuse me to see if anything like this is possible, and I'm starting to think it's not.
Looking for the communities opinion - is there any way to corellate an alert to the textual content of a previous alert and make that a condition of the alert triggering in this way?
Our option B is to just 'ignore' 'Up' alerts from the two older routers that seem to be issuing the fake up alerts.