Three fundamental tips for an effective event filtering in SIGNL4

Apr 7, 2021 | General

Event and alert filtering matters because alert fatigue is one of the most crucial issues in alerting and alert management. SIGNL4 implements a lightweight and effective way of filtering events. The overall process is based on alert categories. Alert categories are applied using a keyword search across the entire payload of incoming third-party events. But assigning alert categories, e.g. for alert augmentation, is not filtering.

To enable an effective event filtering, check out these three fundamental tips:

 

1. Enabling the whitelist keyword filter

SIGNL4 can filter incoming events (received by email, webhook or REST API). This is handled through a keyword whitelist filter. The keyword whitelist is comprised from all keywords of all Signl categories.

How does a keyword whitelist work? Once enabled, the whitelist filter will only let 3rd party events pass and be turned into alerts going out to your team, when the content of the event contains at least one of the keywords in your whitelist (i.e. if at least on category matches). An event which payload does not contain any keyword of your list, will be ‘blocked’ and not turned into an alert signl.

To enable keyword whitelisting, switch on the according toggle for each team under: https://account.signl4.com/manage/Category 

Received events which get filtered out and do not raise an alert notification flow, are still visible in the event journal (accessible through https://account.signl4.com/manage/Signls ). They are marked with a “Filtered” status.

 

2. Create a blacklist filter

As described above, there is native whitelist keyword filter built into SIGNL4. But how about a blacklist filter? A blacklist filter will block any incoming 3rd party event if it contains one of your keywords listed in the blacklist.

With a little hack, you can create a keyword blacklist and apply it as a filter the following way:

1. Create an alert category named ‘blacklist’ for your team: https://account.signl4.com/manage/Category

2. In the keyword section of this category, add all your blacklisted keywords and combine it with OR, i.e. choose ‘Any’

mceclip0.png

3. Now, either have all users manually opt-out from this category or if you are on a paid plan with the ‘assignment’ feature, opt out your users via the Assignment tab, so that the ‘no signls’ symbol is shown for all users.

mceclip1.png

4. Check if no user is subscribed to your ‘blacklist’ category, i.e. no user will receive Signls for any incoming event containing any of your blacklist keywords.

mceclip2.png

 

3. Applying keyword search to dedicated event parameters

Keywords are used to find a matching alert category which is then used to enrich an alert with colors, icons, push sounds, maps and so on. Alert categories can also be used to route alert to dedicated staff, to hide alerts or to prevent incoming events from being turned into alerts (keyword whitelist filtering).

By default, SIGNL4 scans the entire event content for matching keywords. It can then apply an ‘AND’ or ‘OR’ logic operator. This approach is little bit broad.

However, it is possible to work more precisely by telling SIGNL4 to match keywords only for named event parameters. Instead of searching the entire event payload for a keyword ‘ABC’ you can restrict the keyword search for a single event parameter, like the subject of an email event using the following syntax when defining a category keyword: ‘subject ABC’.

So, you simply use the parameter name, a space and then the keyword you want to search for. This also works for custom parameters of your payload. So, if you webhook call payload contains a parameter named ‘param1’ you would use the keyword definition syntax ‘param1 ABC’ to only search in param1 for keyword ABC.

This facilitates a much more precise keyword matching and whitelist filtering algorithm. Here is a sample screenshot:

mceclip0.png

 

These three tips make for an effective filtering algorithm. If you need more capabilities, please feel free to contact us and we are happy to consider your feedback in our feature pipeline planning.

Discover SIGNL4

Dashboard of SIGNL4's mobile Alerting App

Stay ahead of critical incidents with SIGNL4 and its superpowers. SIGNL4 provides superior and automated mobile alerting, delivers alerts to the right people at the right time and enables operations teams to respond and to manage incidents from anywhere.

Learn more about SIGNL4 and start your free 30-days trial.

    Alerting and Response for Modern Operations

    Feature Overview

    A comprehensive Platform for mobile Alerting for an up to 10x faster Response

    AIOps and AI Alerting

    AI-powered Alerting and Alert & Incident Management

    Reliable Alert Notifications

    Alert Notifications by push, text, voice and email. With Tracking and Escalations

    Mobile Alerting App

    The modern Way of receiving and managing critical Alerts on-the-go

    On-Call Scheduling

    Ai-powered Scheduling and Management of On-Call Duties and Shifts

    Call Routing

    Live call routing and a Voice Mailbox for modern after-business Hours Operations

      Use Cases

      IT Alerting

      Stay ahead of critical IT incidents and minimize downtime with SIGNL4 – automated, secure, and in real-time

      Incident Management

      Accelerate response, and streamline incident workflows with real-time mobile alerts

      SecOps Alerting

      Respond faster to cyber threats with mobile-first alerting

      Incident Alerting for MSPs

      Turn Detection into Accountable Response

        IoT Service Alerting

        Automatically alert and notify your field service teams based on real-time signals from your IoT sensors and devices

        SCADA Alarm Notifications

        Respond faster to machine breakdowns, quality issues, and maintenance calls

        Field Service Alerting

        Automated Mobile Routing of Service Requests and Alerts to Field Teams

        On-Call Management

        Create and manage duty schedules, automate alert delivery, escalate seamlessly, and route after-hours calls

        Building Automation

        Ensure fast response, fewer disruptions, and better facility management and service

        After-Hours Call Routing

        SIGNL4 automatically routes after-hours calls to on-call staff – ensuring timely response and 24/7 coverage

        Emergency Alerting

        Keep your teams prepared when every second counts. SIGNL4 delivers fast, reliable emergency notifications

        Alert Management

        A central alert management hub helps to streamline alerting processes from multiple enterprise systems

        Integrations and APIs

        Integrations Overview

        We have verified and tested 200+ Integrations with 3d Party Products

        EMail (SMTP)

        The fastest and easiest way to connect to SIGNL4.

        Webhook

        SIGNL4’s most popular and flexible integration

        REST API

        Seamlessly integrate services or implement additional features

          Selected Customer Case Studies

          Berlin-Brandenburg Airport

          Automated Alerts and Mobile Incident Response for Luggage Transportation Systems

          BASF Coatings

          Automated Transport Dispatching with IoT Buttons and a mobile App for optimized Intralogistics

          RedIron, Canada

          Unifying Alerts and Notifications in mission-critical IT Operations

          CSP Lighthouse, Australia

          Reliable 24/7 Alerting for a global Cybersecurity Service Provider

            Swiss Bankers, Switzerland

            Real-Time Fraud Prevention with 24/7 mobile alerting in Financial Services Operation

            Conexus Credit Union, Canada

            Conexus transformed Incident Response in a Single Day with SIGNL4

            Overview of Industries

            Exciting case studies from selected customers in sectors such as logistics, aviation, manufacturing, finance and IT

            About us

            About Derdack & SIGNL4

            Learn more about a Market Leader in mobile Alerting and Anywhere Incident Response for critical Systems

            Partner Program

            Become a SIGNL4 Partner and take Advantage of a well-established and rapidly growing Product

            Newsletter

            Get Updates, exciting Insights, and Customer Stories – Sign up for our Newsletter!

            Glossary

            We explain the most important Terms and Topics in the Field of Alerting and Incident Management

            Blog

            Our blog offers expert insights and practical tips for getting the most out of SIGNL4

              G2 honors SIGNL4 with a variety of awards.
              DERDACK SIGNL4
              Privacy Overview

              This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.