I have created a Simple Event Detection event monitor which creates a Warning alert when any of the event IDs in a regular expression are matched eg 99|100|101 etc. This works except that once the monitor has triggered, and the server affected goes into a Warning state, no more alerts are sent. I.E if an ID 99 sends an alert and then an ID 100 occurs the ID 100 is not shown in SCOM as an alert.

Can anyone tell me how I can get around this. I dont want to create a separate rule for every one of the event IDs as there are too many of them.



iread selected answer