NEBLI
Nebli Environment

Alerts and rules

How a rule decides when an alert opens and closes, and what to do with an alert once it does.

Who this is for: operators handling alerts, and administrators setting up the rules.

Before you start: you are signed in (Getting started). Everyone can see alerts and rules. Acknowledging and closing alerts needs the Operator role or above; creating, changing and deleting rules needs an Administrator (People and access).

What needs you: the alerts list

Alerts lists every open alert in your organisation, newest first. Each row shows the node, the channel with its value against the threshold, the site, and how long the alert has been open. Filter by site, rule, channel or age. Closed alerts are one tab away, in the same layout.

Click an alert to see its detail: the readings that opened it, the rule, the current reading, the probable cause for a node that stopped reporting, and where the alert was delivered.

  • Acknowledge an alert to show it is being handled. It stays open.
  • Close an alert to end it yourself. An alert also closes on its own when its condition clears.

An alert appears on the map, on the node's page and in Alerts within a minute of the value crossing its threshold.

How a rule works

A rule watches one channel on a set of nodes. In Rules, choose New rule and set:

Setting What it does
Channel and Condition What to watch, and the threshold it must cross. For an air-quality index, choose a category: the rule holds at that category or worse.
Average Instant, 1 h, 8 h or 24 h: the periods air-quality standards use. The rule compares the average over that period, not each single reading. A rule on an index has no average of its own; it reads the index at the end of each hour.
Must hold for How long the condition must last before the alert opens.
Clear margin How far the value must come back inside the threshold before the alert closes, so a value hovering on the line does not open and close over and over.
Cooldown After an alert closes, how long before the same rule can open again on the same node.
Active hours Optional. Only between two times of day in the site's time zone, such as 22:00 to 06:00 for night-time noise. Outside them the rule neither opens nor closes alerts.
Scope Which nodes it applies to: every pole, one site, or nodes you choose.

Before you save, the editor shows how many live nodes the rule covers today and how many of them carry its channel. A node that has not been adopted into a site yet is in no rule's scope.

An alert opens when the condition holds on a node for the time you set, and closes when it clears for the same time, or when a person closes it.

Why averaged rules do not cry wolf

Short spikes are common in outdoor readings. A rule on PM2.5 with a 24-hour average does not open an alert for a one-minute spike, because one minute barely moves a day's average. A rise that lasts for hours moves the average and opens the alert. Use the average that the standard you report against uses.

When a node stops reporting

Every organisation has one status rule. It opens an alert when a node stops reporting (by default, once the node is offline), with a probable cause read from the node's last readings:

Cause What it looked like
Power The battery falling before the silence, or the mains gone.
Link The signal falling, or a switch to cellular.
Sensor One channel flat or missing while the others keep reporting.

The cause shows on the alert and on the network page, so the engineer can see it without a site visit. The status rule can be disabled, but not deleted.

Changing and deleting rules

Each rule shows how many alerts it opened in the last week. An administrator can Enable, Disable, edit or Delete a rule.

A rule with an open alert cannot be deleted until that alert is closed. A deleted rule stops being evaluated and leaves the list, but the alerts it opened keep it, with its name. Deleting cannot be undone.

Where alerts go

Every alert, opening and closing, shows in the console. When your organisation has a HikCentral connection, alerts are also sent there as events, where each becomes an alarm on the camera on the same pole. If a delivery fails, the network page says so; the alert itself is always recorded.