Thresholds

Thresholds define conditions that generate events when DCI values cross defined limits. They are the primary mechanism for generating alerts based on collected data.

For step-by-step procedures on configuring thresholds, see How to Configure Thresholds.

Threshold Basics

Each threshold specifies:

  • A condition function (how to compare the value)

  • A reference value (the limit)

  • Events to generate when the threshold activates or deactivates

  • Optional sampling parameters (how many consecutive violations before activation)

When a DCI value satisfies the threshold condition, the threshold activates and generates the configured activation event. When the value returns to normal, the threshold deactivates and generates the deactivation event.

Value Check Functions

The threshold function determines how the collected value is processed before comparison. This is the first part of the threshold evaluation — what value to check:

Function Description

Last polled value

Use the last collected value directly (default)

Average value

Average of the last N collected values (N = sample count)

Mean deviation

Mean absolute deviation of the last N values from their average

Diff with previous value

Difference between the current value and the previous value

Data collection error

Activates when data collection fails (value cannot be retrieved)

Sum of values

Sum of the last N collected values

Script

Execute an NXSL script to compute the check value

Absolute deviation

Absolute deviation of the current value from the average of the last N values

Anomaly

Activates when the collected value is detected as anomalous. Requires anomaly detection to be enabled on the DCI’s Thresholds property page (Detect anomalies using isolation forest algorithm or Detect anomalies using AI); without it the threshold never activates

For Average, Mean deviation, Sum, and Absolute deviation functions, the sample count parameter specifies how many historical values are used in the calculation. For the Data collection error function, it is the number of consecutive collection errors required for activation.

Function, Operation, and Data Type Restrictions

The management client offers every function and operation for every DCI data type, and the server does not validate the combination — a meaningless combination silently produces no check value and the threshold never activates. The actual restrictions are:

  • The ordering operations (Less than, Less than or equal, Greater than or equal, Greater than) are not implemented for string values, so on DCIs with String data type they never match. Only Equal, Not equal, and the Like operations work with string values.

  • The Like operations work only with the String data type.

  • Diff with previous value works with string values: the computed value is 1 if the current value differs from the previous one and 0 if they are equal, compared as an integer.

  • The Data collection error, Anomaly, and Script functions do not use the operation and reference value; the management client disables these fields for Data collection error and Anomaly.

Condition Operations

The condition operation determines how the check value (produced by the function above) is compared to the reference value:

Operation Description

Less than (<)

Activates when value < reference

Less than or equal (<=)

Activates when value <= reference

Equal (==)

Activates when value == reference

Greater than or equal (>=)

Activates when value >= reference

Greater than (>)

Activates when value > reference

Not equal (!=)

Activates when value != reference

Like

Activates when string value matches a pattern (wildcards: *, ?); case-sensitive

Not like

Activates when string value does not match a pattern; case-sensitive

Like (case-insensitive)

Same as Like but ignores case

Not like (case-insensitive)

Same as Not like but ignores case

For numeric threshold values, you can use multiplier suffixes: K (103), M (106), G (109), T (1012), Ki (1024), Mi (10242), Gi (10243), Ti (10244). For example, 1G instead of 1000000000.

Sample Count

The sample count prevents false alerts from transient spikes. Its exact meaning depends on the threshold function:

  • For Last polled value, Diff with previous value, Script, and Anomaly, the threshold activates only after N consecutive collected values match the condition.

  • For Average value, Mean deviation, Sum of values, and Absolute deviation, the sample count defines the aggregation window: the function is computed over the last N collected values and the result is compared once.

  • For Data collection error, the threshold activates after N consecutive collection errors.

Example: a threshold with function Last polled value, condition "Greater than 90", and sample count 3 only activates after three consecutive DCI values are above 90.

This is particularly useful for:

  • CPU usage (brief spikes are normal)

  • Network latency (occasional high values may not indicate a problem)

  • Queue depths (temporary bursts are expected)

A separate Deactivation samples setting controls the reverse transition: when set to a value greater than 1, an active threshold deactivates only after N consecutive collected values no longer match the condition.

Repeat Interval

By default, a threshold generates the activation event once and stays active until the condition clears. The repeat interval causes the activation event to be regenerated at regular intervals while the threshold remains active.

Each threshold uses one of three repeat modes:

  • Use default settings (default): use the interval from the DataCollection.ThresholdRepeatInterval server configuration variable (0 by default, meaning no repetition; changing it requires a server restart)

  • Never: generate the activation event only once

  • Every N seconds: regenerate the activation event every N seconds while the threshold remains active

This is useful when you need periodic notifications about ongoing issues.

The Regenerate event if value changes while active threshold option works independently of the repeat interval: it generates an additional activation event whenever the collected value changes while the threshold stays active.

Threshold Events

Default Events

Event Description

SYS_THRESHOLD_REACHED

Generated when a threshold activates

SYS_THRESHOLD_REARMED

Generated when a threshold deactivates (value returns to normal)

In addition to per-threshold events, an event can be selected in the Generate event when all thresholds are deactivated field on the DCI’s Thresholds property page (typically SYS_ALL_THRESHOLDS_REARMED). It is generated when the last active threshold on the DCI deactivates. By default no event is selected and none is generated.

Threshold Activation Event Parameters

The SYS_THRESHOLD_REACHED event provides these parameters:

# Parameter Description

1

dciName

Metric name

2

dciDescription

DCI description

3

thresholdValue

Threshold reference value

4

currentValue

Actual value being compared

5

dciId

Data collection item ID

6

instance

Instance name (for instance discovery DCIs)

7

isRepeatedEvent

1 if this is a repeated event (threshold was already active), 0 otherwise

8

dciValue

Last collected DCI value

9

operation

Threshold operation code (0=<, 1=<=, 2===, 3⇒=, 4⇒, 5=!=, 6=Like, 7=Not like, 8=Like case-insensitive, 9=Not like case-insensitive)

10

function

Threshold function code (0=Last, 1=Average, 2=Mean deviation, 3=Diff, 4=Error, 5=Sum, 6=Script, 7=Abs deviation, 8=Anomaly)

11

pollCount

Required sample count for activation

12

thresholdDefinition

Human-readable threshold definition text

13

instanceValue

Instance value

14

instanceName

Instance display name

15

thresholdId

Threshold unique ID

Threshold Deactivation Event Parameters

The SYS_THRESHOLD_REARMED event provides these parameters:

# Parameter Description

1

dciName

Metric name

2

dciDescription

DCI description

3

dciId

Data collection item ID

4

instance

Instance name

5

thresholdValue

Threshold reference value

6

currentValue

Actual value which cleared the threshold

7

dciValue

Last collected DCI value

8

operation

Threshold operation code

9

function

Threshold function code

10

pollCount

Required sample count

11

thresholdDefinition

Human-readable threshold definition text

12

instanceValue

Instance value

13

instanceName

Instance display name

14

thresholdId

Threshold unique ID

Table Threshold Events

Table DCIs have their own threshold events:

SYS_TABLE_THRESHOLD_ACTIVATED parameters:

# Parameter Description

1

dciName

Table DCI name

2

dciDescription

Table DCI description

3

dciId

Table DCI ID

4

row

Zero-based index of the table row that activated the threshold

5

instance

Instance identifier

SYS_TABLE_THRESHOLD_DEACTIVATED parameters:

# Parameter Description

1

dciName

Table DCI name

2

dciDescription

Table DCI description

3

dciId

Table DCI ID

4

row

Zero-based table row index (-1 if the threshold was deactivated because the instance disappeared)

5

instance

Instance identifier

6

instanceMissing

true if the threshold was deactivated because the instance disappeared from the collected table, false otherwise

Process All Thresholds

By default, only the first matching threshold activates (thresholds are evaluated top to bottom, and evaluation stops at the first match). If the Process all thresholds option is enabled on the DCI’s Thresholds property page, all thresholds are evaluated regardless of whether a higher-severity threshold has already matched. This allows generating multiple events simultaneously for different severity levels.

Disabling Threshold Processing

Threshold processing can be turned off for the whole DCI with the Disable threshold processing option on the Thresholds property page. The related Re-enable threshold processing at given time option re-enables processing automatically at the specified time. An individual threshold can also be disabled with the This threshold is disabled option in the threshold edit dialog.

Threshold State Persistence

Threshold states are persistent across server restarts. If a threshold is active when the server stops, it remains active when the server starts again. The deactivation event is only generated when the DCI value actually returns to normal.

Thresholds on Templates

When thresholds are configured on a template DCI, they are automatically deployed to all nodes bound to the template. Template threshold changes propagate to all bound nodes.

See DCI Templates for details on template-based threshold management.