How to Configure Thresholds
This guide covers practical procedures for setting up and troubleshooting thresholds on DCIs.
For threshold concepts and reference information, see Thresholds.
Adding a Threshold to a DCI
To add a threshold to a DCI:
-
Open the DCI properties
-
Go to the Thresholds tab
-
Click Add
-
Configure the threshold fields (Function, Operation, Value, Samples, and Deactivation samples are grouped under Condition in the dialog):
| Field | Description |
|---|---|
Function |
Function applied to collected values (e.g., last polled value, mean value, diff with previous value) |
Operation |
Comparison operation (e.g., greater than, less than, equal) |
Value |
Reference value to compare against |
Script |
NXSL script computing the threshold state; replaces Operation when Function is Script (Value remains available) |
Samples |
Number of samples used in evaluation (default: 1): consecutive matching samples required for activation with Last polled value, Diff with previous value, Script, and Anomaly; the number of aggregated values with Average, Sum, Mean deviation, and Absolute deviation; consecutive collection errors with Data collection error |
Deactivation samples |
Number of consecutive samples that no longer match the condition required before the threshold deactivates |
Activation event |
Event generated when threshold activates (default: |
Deactivation event |
Event generated when threshold deactivates (default: |
Repeat event |
Whether to regenerate the activation event while the threshold stays active: Use default settings (server default), Never, or Every N seconds |
This threshold is disabled |
Disables the threshold without deleting it |
Regenerate event if value changes while active |
Generates an additional activation event whenever the collected value changes while the threshold stays active |
Event severity is defined by the event template, not by the threshold.
Setting Up Multiple Thresholds
A single DCI can have multiple thresholds with different conditions and severity levels. Thresholds are evaluated in order from top to bottom.
Example — multi-level CPU usage alerts (each level uses its own activation event, since severity comes from the event template):
| Order | Operation | Value | Activation Event |
|---|---|---|---|
1 |
Greater than |
95 |
custom event with Critical severity |
2 |
Greater than |
85 |
custom event with Major severity |
3 |
Greater than |
70 |
custom event with Warning severity |
When a higher-severity threshold (lower order number) activates, lower-severity thresholds are suppressed. When the value drops below the highest active threshold, it deactivates and the next applicable threshold takes over.
| Order thresholds from most severe to least severe. By default, evaluation stops at the first threshold that activates. Enabling the Process all thresholds option on the DCI’s Thresholds property page changes this behavior — all thresholds are evaluated regardless of earlier activations. |
Using Script Thresholds
For complex conditions that cannot be expressed with simple comparisons, use script thresholds. The NXSL script has access to:
-
$1— the current DCI value -
$2— the threshold value (from the Value field) -
$dci— the DCI object -
$isCluster— true if the DCI is collected on a cluster object -
$node— the node object (null if the owner is not a node) -
$object— the object owning the DCI
The script’s return value is evaluated as a boolean: any non-zero number or non-empty string activates the threshold, any other value keeps it inactive.
A script may also return a hash map with keys match, currentValue, and thresholdValue to control the activation state and the values reported in events; the match value is evaluated as a boolean in the same way.
Example — threshold that activates when the value exceeds the configured threshold value by more than 20%:
return $1 > $2 * 1.2;
For change-based thresholds (e.g., value changed since the previous poll), use the Diff with previous value function instead of a script.
Example — threshold that activates only during business hours:
hour = localtime().hour;
if (hour < 8 || hour > 18)
return false;
return $1 > 90;
Using Custom Threshold Events
You can configure thresholds to generate custom events instead of the defaults. This is useful for:
-
Routing different alert types to different notification channels
-
Executing specific automated actions based on the type of threshold violation
-
Integrating with external systems that expect specific event codes
Create custom events in the Event Templates view and assign them in the threshold configuration.
Troubleshooting
Threshold Not Activating
-
Verify the DCI is collecting data (check last value and timestamp)
-
Check the condition and value — ensure they match the expected activation point
-
If Samples > 1, verify that enough consecutive violations have occurred
-
Check for threshold ordering issues with multiple thresholds
Threshold Not Deactivating
-
If Deactivation samples is greater than 1, deactivation is suppressed until that many consecutive samples no longer match the condition
-
The DCI value must genuinely return below (or above) the threshold value
-
Check if the deactivation event is configured
-
For script thresholds, verify the script returns
falsewhen the condition clears