Thresholds
Thresholds define conditions that generate events when DCI values cross defined limits. They are the primary mechanism for generating alerts based on collected data.
For step-by-step procedures on configuring thresholds, see How to Configure Thresholds.
Threshold Basics
Each threshold specifies:
-
A condition function (how to compare the value)
-
A reference value (the limit)
-
Events to generate when the threshold activates or deactivates
-
Optional sampling parameters (how many consecutive violations before activation)
When a DCI value satisfies the threshold condition, the threshold activates and generates the configured activation event. When the value returns to normal, the threshold deactivates and generates the deactivation event.
Value Check Functions
The threshold function determines how the collected value is processed before comparison. This is the first part of the threshold evaluation — what value to check:
| Function | Description |
|---|---|
Last polled value |
Use the last collected value directly (default) |
Average value |
Average of the last N collected values (N = sample count) |
Mean deviation |
Mean absolute deviation of the last N values from their average |
Diff with previous value |
Difference between the current value and the previous value |
Data collection error |
Activates when data collection fails (value cannot be retrieved) |
Sum of values |
Sum of the last N collected values |
Script |
Execute an NXSL script to compute the check value |
Absolute deviation |
Absolute deviation of the current value from the average of the last N values |
Anomaly |
Activates when the collected value is detected as anomalous. Requires anomaly detection to be enabled on the DCI’s Thresholds property page (Detect anomalies using isolation forest algorithm or Detect anomalies using AI); without it the threshold never activates |
| For Average, Mean deviation, Sum, and Absolute deviation functions, the sample count parameter specifies how many historical values are used in the calculation. For the Data collection error function, it is the number of consecutive collection errors required for activation. |
Function, Operation, and Data Type Restrictions
The management client offers every function and operation for every DCI data type, and the server does not validate the combination — a meaningless combination silently produces no check value and the threshold never activates. The actual restrictions are:
-
The ordering operations (Less than, Less than or equal, Greater than or equal, Greater than) are not implemented for string values, so on DCIs with String data type they never match. Only Equal, Not equal, and the Like operations work with string values.
-
The Like operations work only with the String data type.
-
Diff with previous value works with string values: the computed value is
1if the current value differs from the previous one and0if they are equal, compared as an integer. -
The Data collection error, Anomaly, and Script functions do not use the operation and reference value; the management client disables these fields for Data collection error and Anomaly.
Condition Operations
The condition operation determines how the check value (produced by the function above) is compared to the reference value:
| Operation | Description |
|---|---|
Less than (<) |
Activates when value < reference |
Less than or equal (<=) |
Activates when value <= reference |
Equal (==) |
Activates when value == reference |
Greater than or equal (>=) |
Activates when value >= reference |
Greater than (>) |
Activates when value > reference |
Not equal (!=) |
Activates when value != reference |
Like |
Activates when string value matches a pattern (wildcards: |
Not like |
Activates when string value does not match a pattern; case-sensitive |
Like (case-insensitive) |
Same as Like but ignores case |
Not like (case-insensitive) |
Same as Not like but ignores case |
For numeric threshold values, you can use multiplier suffixes: K (103), M (106), G (109), T (1012), Ki (1024), Mi (10242), Gi (10243), Ti (10244). For example, 1G instead of 1000000000.
|
Sample Count
The sample count prevents false alerts from transient spikes. Its exact meaning depends on the threshold function:
-
For Last polled value, Diff with previous value, Script, and Anomaly, the threshold activates only after N consecutive collected values match the condition.
-
For Average value, Mean deviation, Sum of values, and Absolute deviation, the sample count defines the aggregation window: the function is computed over the last N collected values and the result is compared once.
-
For Data collection error, the threshold activates after N consecutive collection errors.
Example: a threshold with function Last polled value, condition "Greater than 90", and sample count 3 only activates after three consecutive DCI values are above 90.
This is particularly useful for:
-
CPU usage (brief spikes are normal)
-
Network latency (occasional high values may not indicate a problem)
-
Queue depths (temporary bursts are expected)
A separate Deactivation samples setting controls the reverse transition: when set to a value greater than 1, an active threshold deactivates only after N consecutive collected values no longer match the condition.
Repeat Interval
By default, a threshold generates the activation event once and stays active until the condition clears. The repeat interval causes the activation event to be regenerated at regular intervals while the threshold remains active.
Each threshold uses one of three repeat modes:
-
Use default settings (default): use the interval from the
DataCollection.ThresholdRepeatIntervalserver configuration variable (0 by default, meaning no repetition; changing it requires a server restart) -
Never: generate the activation event only once
-
Every N seconds: regenerate the activation event every N seconds while the threshold remains active
This is useful when you need periodic notifications about ongoing issues.
The Regenerate event if value changes while active threshold option works independently of the repeat interval: it generates an additional activation event whenever the collected value changes while the threshold stays active.
Threshold Events
Default Events
| Event | Description |
|---|---|
|
Generated when a threshold activates |
|
Generated when a threshold deactivates (value returns to normal) |
In addition to per-threshold events, an event can be selected in the Generate event when all thresholds are deactivated field on the DCI’s Thresholds property page (typically SYS_ALL_THRESHOLDS_REARMED).
It is generated when the last active threshold on the DCI deactivates.
By default no event is selected and none is generated.
Threshold Activation Event Parameters
The SYS_THRESHOLD_REACHED event provides these parameters:
| # | Parameter | Description |
|---|---|---|
1 |
dciName |
Metric name |
2 |
dciDescription |
DCI description |
3 |
thresholdValue |
Threshold reference value |
4 |
currentValue |
Actual value being compared |
5 |
dciId |
Data collection item ID |
6 |
instance |
Instance name (for instance discovery DCIs) |
7 |
isRepeatedEvent |
|
8 |
dciValue |
Last collected DCI value |
9 |
operation |
Threshold operation code (0=<, 1=<=, 2===, 3⇒=, 4⇒, 5=!=, 6=Like, 7=Not like, 8=Like case-insensitive, 9=Not like case-insensitive) |
10 |
function |
Threshold function code (0=Last, 1=Average, 2=Mean deviation, 3=Diff, 4=Error, 5=Sum, 6=Script, 7=Abs deviation, 8=Anomaly) |
11 |
pollCount |
Required sample count for activation |
12 |
thresholdDefinition |
Human-readable threshold definition text |
13 |
instanceValue |
Instance value |
14 |
instanceName |
Instance display name |
15 |
thresholdId |
Threshold unique ID |
Threshold Deactivation Event Parameters
The SYS_THRESHOLD_REARMED event provides these parameters:
| # | Parameter | Description |
|---|---|---|
1 |
dciName |
Metric name |
2 |
dciDescription |
DCI description |
3 |
dciId |
Data collection item ID |
4 |
instance |
Instance name |
5 |
thresholdValue |
Threshold reference value |
6 |
currentValue |
Actual value which cleared the threshold |
7 |
dciValue |
Last collected DCI value |
8 |
operation |
Threshold operation code |
9 |
function |
Threshold function code |
10 |
pollCount |
Required sample count |
11 |
thresholdDefinition |
Human-readable threshold definition text |
12 |
instanceValue |
Instance value |
13 |
instanceName |
Instance display name |
14 |
thresholdId |
Threshold unique ID |
Table Threshold Events
Table DCIs have their own threshold events:
SYS_TABLE_THRESHOLD_ACTIVATED parameters:
| # | Parameter | Description |
|---|---|---|
1 |
dciName |
Table DCI name |
2 |
dciDescription |
Table DCI description |
3 |
dciId |
Table DCI ID |
4 |
row |
Zero-based index of the table row that activated the threshold |
5 |
instance |
Instance identifier |
SYS_TABLE_THRESHOLD_DEACTIVATED parameters:
| # | Parameter | Description |
|---|---|---|
1 |
dciName |
Table DCI name |
2 |
dciDescription |
Table DCI description |
3 |
dciId |
Table DCI ID |
4 |
row |
Zero-based table row index ( |
5 |
instance |
Instance identifier |
6 |
instanceMissing |
|
Process All Thresholds
By default, only the first matching threshold activates (thresholds are evaluated top to bottom, and evaluation stops at the first match). If the Process all thresholds option is enabled on the DCI’s Thresholds property page, all thresholds are evaluated regardless of whether a higher-severity threshold has already matched. This allows generating multiple events simultaneously for different severity levels.
Disabling Threshold Processing
Threshold processing can be turned off for the whole DCI with the Disable threshold processing option on the Thresholds property page. The related Re-enable threshold processing at given time option re-enables processing automatically at the specified time. An individual threshold can also be disabled with the This threshold is disabled option in the threshold edit dialog.
Threshold State Persistence
Threshold states are persistent across server restarts. If a threshold is active when the server stops, it remains active when the server starts again. The deactivation event is only generated when the DCI value actually returns to normal.
Thresholds on Templates
When thresholds are configured on a template DCI, they are automatically deployed to all nodes bound to the template. Template threshold changes propagate to all bound nodes.
See DCI Templates for details on template-based threshold management.