Documentation Index

Fetch the complete documentation index at: https://kb.kentik.com/llms.txt

Use this file to discover all available pages before exploring further.

Did you know that you can *listen* to our KB articles? Click here for more information.

Alert Policy Templates

Prev Next

This article discusses the Alert Policy Templates page of the Kentik portal.

Note: For more information on policy-based alerting, see Alerting, Alerting Page, Notifications, and Mitigations.

A list of alert policy templates are shown, filtered by Traffic policy type.

Kentik-provided templates can be cloned and tailored to your organization's alerting needs.

The Alert Policy Templates page is a list of Kentik-provided policy templates to cover the most common network traffic anomalies, allowing you to respond with manual or automated mitigation. You can’t add or modify policy templates, but you can clone them to your Alert Policies page. The cloned template remains unchanged, while your new policy is fully editable to meet your organization’s needs.

Alert Policy Templates Page

This section describes the Alert Policy Templates page.

Note: Only Administrators can access the Alert Policy Templates page.

Policy Templates Access

To access the Alert Policy Templates page:

  1. Choose Alerting from the portal's main navbar to go to the Alerting page.

  2. Click Manage Policies at the upper right to go to the Alert Policies page.

  3. Click Alert Policy Templates at upper right to go to the Alert Policy Templates page.

Policy Templates Page UI

The Alert Policy Templates page includes the following UI elements:

  • Subnav: Breadcrumbs for the page.

  • Show/hide filters (filter icon): Toggles the expanded/collapsed Filters pane.

  • Search (field): Enter text to filter the policies in the Policy Templates List. The list will show only policies with matching text in at least one column (ID or Name). The field also displays lozenges for filters applied with the Filters pane, if any.

  • Filters (pane): Use to narrow the alert policies shown in the Policy Templates List, (see Policy Templates Filters).

  • Policy templates list: A table listing the available policy templates (see Policy Templates List).

Policy Templates List

The Policy Templates list is a table showing all Kentik-provided policy templates. The table includes the following columns:

  • ID: The template's unique ID.

  • Type: The type of template, NMS, Traffic, or Protect (see Policy Types).

  • Name: The name and description of the template. Once cloned, you can change the name and description of the resulting policy.

  • Data Sources: The origin of the network telemetry data evaluated by the template (e.g., Amazon Web Services, Google Cloud Platform, All Routers, or All Data Sources).

  • Metrics: The units (e.g., bits/s, packets/s) by which the template measures incoming flow data (see Policy Dataset Settings). The primary metric is listed first, followed by secondary metrics (if any).

  • Dimensions: The dimensions in the template, combining to make a key for how traffic is grouped for evaluation (see Dimensions Reference).

  • Create: Clones the template and opens the resulting policy for editing (see Clone a Policy Template). Once saved, the new policy will appear in the Alert Policies List, while the template remains unchanged.

Note: To see more template details, click its row to open its Template Details Drawer. Click same row again to close the drawer.

Policy Templates Filters

Filter the templates in the Policy Templates List using the controls in the Filters pane. The pane includes:

  • Reset To Default (appears only when a filter is specified): Click to clear all filters.

  • Type: Click policy type boxes (NMS, Traffic, Protect) to restrict the list (see Policy Types).

  • Template ID: Search for a specific template by its ID number (no partial matches).

    Note: The template ID differs from the policy ID assigned to a policy cloned from that template.

Template Details DrawerPolicy template details are shown displaying AWS traffic metrics for inbound VM connections by protocol.

The Policy Template Details drawer, which provides a summary of a template’s settings, opens when you click a row in the Policy Templates List. It includes the following:

  • Type: The policy type for this template.

  • Actions (vertical dots icon): A dropdown menu to select from:

    • Create policy from template (button): Click to create a new policy from the template (see Clone a Policy Template).

  • Close: Click the X to close the drawer.

  • Name: The Kentik-provided template name.

  • Description: The Kentik-provided template description, if any.

  • Dataset (pane): Summary of settings that determine evaluated traffic for the template (see Policy Dataset Settings).

  • Activate & Clear (pane): Summary of threshold settings for the template. The number of thresholds defined in the template is shown in parentheses (see Activate & Clear Settings).

  • Baseline (pane): Summary of baseline settings for the template (see Policy Baseline Settings).

Tip: Once you clone a template into a policy, you can modify the policy’s settings in Alert Policies while the template remains unchanged.

Clone a Policy Template

To create an alert policy from a template using the Alert Policy Templates page:

  1. Navigate to the Alert Policy Templates page (see Policy Templates Access).

  2. Click Create for the policy you'd like to clone.

    1. Alternatively, click Create in the template's Template Details Drawer.

  3. Modify the policy as needed (see Policy Settings).

  4. Click Save. The new policy will now appear in your Alert Policies List.

Note: To create an alert policy from a template on the Alert Policies page, click the arrow on the Add Policy button and select Add Alert Policy from Template (see Add Policy from Template).