<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itskeptic.org"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The IT Skeptic - Comments for &quot;Does ITIL explain the difference between an Alert and an Event?&quot;</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve</link>
 <description>Comments for &quot;Does ITIL explain the difference between an Alert and an Event?&quot;</description>
 <language>en</language>
<item>
 <title>Hi all,
This is what i have</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-9420</link>
 <description>&lt;p&gt;Hi all,&lt;/p&gt;
&lt;p&gt;This is what i have in my FAQ section to make it easy to understand for a non-IT reader.&lt;/p&gt;
&lt;p&gt;Q. What is the difference between an “event” and an “alert”?&lt;/p&gt;
&lt;p&gt;A. An event indicated that something has happened. It can be just “information” (i.e. for you to know only), a warning (i.e. something is going wrong) or an exception (i.e. something has went wrong).&lt;br /&gt;
	Information events are logged for operational staff used to check the proper operation of the IT services.&lt;br /&gt;
	Warning events trigger “alerts” to notify responsible parties to take actions before things go wrong. Alerts are triggered when the IT services or devices approaching its thresholds (i.e. breaking points)&lt;br /&gt;
	Exception events are directed into Incident Management Process normally with high priority as something has went wrong already.&lt;/p&gt;
</description>
 <pubDate>Mon, 18 Jun 2012 08:32:41 +0000</pubDate>
 <dc:creator>Brighton Lek</dc:creator>
 <guid isPermaLink="false">comment 9420 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Standard Changes</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8607</link>
 <description>&lt;p&gt;Should Standard Changes exist solely on their own? Meaning, should there be a Standard Change that has no Incident, Problem, or Service Request driving it? &lt;/p&gt;
&lt;p&gt;If I have a CSI initiative, that may require a Standard Change - do I create a Service Request that would then drive the Standard Change (it may not be  &quot;Problem&quot; or &quot;Incident&quot;)? Example - Could be that I noticed that customers don&#039;t access data older than 2 years very often, or not at all over the past 6 months. I know that we can move that data to a less expensive Storage solution. That would a) lower the total cost of storage for the service and b) increase performance (smaller data set to search/sort).  Maybe moving this isn&#039;t a &quot;Standard Change&quot;, but let&#039;s pretend just to walk through the process. So, how do you move from CSI Registry to Change?&lt;/p&gt;
&lt;p&gt;Or what if it is coming from Capacity Management? How do you move from Capacity Management to Change?&lt;/p&gt;
&lt;p&gt;I would think that you go through Incident, Problem or Service Request - but do you allow, or think it is okay, to have no particular entry point into Change? Meaning, anything (or nothing) can be the entry point?&lt;/p&gt;
&lt;p&gt;I bring this up because you mention Alerts could be an entry point to Change. I am not sure I agree. From Alert, to Problem/Incident/SR, to Change - I think this is appropriate.&lt;/p&gt;
</description>
 <pubDate>Mon, 03 Oct 2011 20:25:14 +0000</pubDate>
 <dc:creator>itsm_stephen</dc:creator>
 <guid isPermaLink="false">comment 8607 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>The ITIL Olympics</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8606</link>
 <description>&lt;p&gt;&quot;Wow, he has performed a Complex Monitor Control Loop with double feedback and Active-Passive Monitoring.  The judges have given that an average 9.5&quot;&lt;/p&gt;
</description>
 <pubDate>Mon, 03 Oct 2011 20:07:10 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8606 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>that little round hook thingy</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8605</link>
 <description>&lt;p&gt;As commented above, everyone has an opinion on this.  Intuitively I&#039;d like alerts to lead to events, something to be managed.  But my opinion is not the point.  As an industry we should be able to agree on these things and be consistent.  &lt;/p&gt;
&lt;p&gt;&quot;No, nurse, when I said scalpel I meant that little round hook thingy&quot;&lt;br /&gt;
&quot;Pass me the wrench.  No, the wrench for screws&quot;&lt;br /&gt;
&quot;Oh I thought the piers were the end bits of the bridge.  No wonder it fell down&quot;&lt;/p&gt;
&lt;p&gt;That is supposed to be the function of ITIL, to define the generally accepted terminology and practices.&lt;br /&gt;
It&#039;s fine if you then diverge from that reference framework, but you can document the fact so as to alert consultants, contractors, auditors and new staff.&lt;/p&gt;
&lt;p&gt;ITIL should be clear on these things.  In this case it is not too bad if people actually read the book properly and study it closely and spend the time with book experts to tease out the correct interpretation, but lots of folk don&#039;t have time for that.&lt;br /&gt;
Let&#039;s get the message agreed, clear, consistent and out there.&lt;/p&gt;
</description>
 <pubDate>Mon, 03 Oct 2011 20:01:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8605 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Holy matter</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8603</link>
 <description>&lt;p&gt;When you&#039;re looking for divine ITIL enlightenment in this matter, make sure you dont skip the sections on &#039;Complex Monitor Control Loops&#039; and &#039;ITSM Monitor Control Loops&#039;. Both with the double feedback loop! Or even the matrix &quot;Reactive&amp;lt;&amp;gt;Proactive&quot; vs &quot;Active&amp;lt;&amp;gt;Passive&quot; Monitoring.&lt;/p&gt;
&lt;p&gt;This is one of the best sections of ITIL, as it includes a phrase that got my attention when I first stumbled upon it:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&quot;All of this is interesting theory, but does not explain how the monitor control loop concept can be used to operate IT services.&quot; (ITIL(c) 2011, SO 5.1.2.1)&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Unfortunately, they scope it to monitoring control loops, and not the rest of ITIL :)&lt;/p&gt;
</description>
 <pubDate>Mon, 03 Oct 2011 15:57:34 +0000</pubDate>
 <dc:creator>Niels</dc:creator>
 <guid isPermaLink="false">comment 8603 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Monitoring vs Events</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8602</link>
 <description>&lt;p&gt;Agree... I&#039;d say you can call the Data Collection &quot;Monitoring Data&quot;.&lt;/p&gt;
&lt;p&gt;Regarding,  &#039;All Alerts should create Incidents and/or Problems&#039;:  You could argue they can create a Service Request (or Standard Change): e.g. no harm done (yet) to any service/user and it&#039;s not likely to happen soon, but we would like someone to take a look at it some day soon.&lt;/p&gt;
&lt;p&gt;Especially in this area, the adagium comes into play : &quot;it depends on your situation&quot;&lt;/p&gt;
</description>
 <pubDate>Mon, 03 Oct 2011 15:45:04 +0000</pubDate>
 <dc:creator>Niels</dc:creator>
 <guid isPermaLink="false">comment 8602 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Events and Alerts</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8595</link>
 <description>&lt;p&gt;I&#039;ve had this discussion with my customers for years and years. &lt;/p&gt;
&lt;p&gt;I&#039;ve been setting up &#039;monitoring and alerting&#039; systems for the past 10 years. I haven&#039;t read the SO book, so beyond this thread I don&#039;t know how ITIL is describing them. &lt;/p&gt;
&lt;p&gt;I&#039;ve used the following in my discussions with my customers, or people on my team, so we are all on the same page.&lt;/p&gt;
&lt;p&gt;Data Collection =  anything we&#039;ve (either the customer, or us based on our &#039;expertise&#039;) determined important enough to capture and record. The primary source for reporting. &lt;/p&gt;
&lt;p&gt;Examples:&lt;/p&gt;
&lt;p&gt;Disk space utilization every 5 minutes (we don&#039;t care what it is, only that we capture/record it)&lt;br /&gt;
CPU, Security Log entries, End user emulation transaction times&lt;/p&gt;
&lt;p&gt;Events = Any data collected that either has value for immediate action (either automated or manual) or contains information of a &#039;proactive&#039; nature. Provides additional insight into Incident/Problem Management. Can be used by Problem to trend &quot;events&quot; over time. &lt;/p&gt;
&lt;p&gt;Examples:&lt;/p&gt;
&lt;p&gt;Disk space has exceeded a certain threshold (over a period of time (my preference), or occurred once) - Perhaps 50%, or 65%, or 95%&lt;br /&gt;
A security log entry of a particular type&lt;br /&gt;
End user emulation transactions have failed - from one location or maybe all locations (over a period of time (my preference), or occurred once)&lt;/p&gt;
&lt;p&gt;Alerts = Any event that meets or exceeds defined thresholds that require immediate attention/action by &#039;service providers&#039; (sys admins, DBAs, network engineers, product managers, service managers, service desk). Indicators of Incidents and/or Problems. &lt;/p&gt;
&lt;p&gt;Disk space has exceeded a certain threshold - usually something high like 95% and most always over a period of time (to avoid the &quot;false positive&quot;)&lt;br /&gt;
A security log entry of a particular type&lt;br /&gt;
End user emulation transactions have failed - usually from more than 1 location and for a period of time.&lt;/p&gt;
&lt;p&gt;Data collection &amp;gt; Events &amp;gt; Alerts&lt;br /&gt;
Lots of things &amp;gt; Some things &amp;gt; Few things&lt;/p&gt;
&lt;p&gt;Alert must first be an Event which must first be Data that is collected. &lt;/p&gt;
&lt;p&gt;Not all Data collected is worthy to be an Event - I just want to log CPU over time so I can graph it later&lt;br /&gt;
Not all events are worthy to be an Alert  - CPU spiked once on one web server (although if it happens every day, perhaps Prob Mgmt using reports on Events can see this an investigate)&lt;br /&gt;
All Alerts should create Incidents and/or Problem tickets. Something is really messed up (or is soon to be) requiring immediate (or near immediate) action/work.&lt;/p&gt;
</description>
 <pubDate>Fri, 30 Sep 2011 14:43:54 +0000</pubDate>
 <dc:creator>itsm_stephen</dc:creator>
 <guid isPermaLink="false">comment 8595 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Notification vs Alert</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8587</link>
 <description>&lt;p&gt;I think there is a bit of confusion among readers of ITIL between and &quot;Event Notification&quot; and &quot;Alert&quot; as ITIL treats them. Many thinks (as I used to misinterpret initially too) that Event Notification = Alert.&lt;/p&gt;
&lt;p&gt;It is clear from the diagarm 4.1 in ITIL v3 (4.2 in ITIL 2011) and associate description that ITIL treats them differently.&lt;/p&gt;
&lt;p&gt;Event - any change of state that is occuring on the system&lt;/p&gt;
&lt;p&gt;Event Notification - the notification generated by the CI/system or a monitoring tool that indicates that an event has occured on the CI/Service/System.&lt;/p&gt;
&lt;p&gt;Then, after filtering and understanding of the significance, the appropriate response to that particular event is to be decided by event management.&lt;/p&gt;
&lt;p&gt;The response could be:&lt;br /&gt;
- Trigger an auto-response to that event - running some scripts,reboots etc where the event is well understood (Modelled?)&lt;br /&gt;
AND/OR&lt;br /&gt;
- Trigger an appropriate process - Logging an incident ticket to trigger Incident mgmt  for example&lt;br /&gt;
AND/OR&lt;br /&gt;
- Alert an appropriate person/specialist who can do the suitable human intervention for that event - email/phone call, SMS etc...&lt;/p&gt;
&lt;p&gt;So, in this context, ALERT is just one of the possible response for a particular event. It may be applicable in some cases, while may not be applicable in some...&lt;/p&gt;
&lt;p&gt;Hope this helps in the discussion...&lt;/p&gt;
&lt;p&gt;Vinod Agrasala&lt;br /&gt;
www.itserviceview.com&lt;br /&gt;
www.wings2i.com&lt;/p&gt;
</description>
 <pubDate>Wed, 28 Sep 2011 05:24:20 +0000</pubDate>
 <dc:creator>vinodka</dc:creator>
 <guid isPermaLink="false">comment 8587 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>I try not to over-think some</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8586</link>
 <description>&lt;p&gt;I try not to over-think some of the ITIL stuff, it will make the head hurt :-) Looking at what we should be achieving through the service design and transition phases, this preliminary filtering should have taken place - whether it be defining thresholds and important states to monitor, setting up alerts for (and automagic response) for fault conditions that cannot/won&#039;t be fixed, or building instrumentation into the application or service. Microsoft calls it &quot;Designing for Operations&quot; - google is your friend. &lt;/p&gt;
&lt;p&gt;Today the capability of management packs has improved to include some of these important events and correlations. In practice though, often this monitoring tuning is forgotten post-transition when in reality it needs constant feeding and watering just like a garden.&lt;/p&gt;
</description>
 <pubDate>Wed, 28 Sep 2011 02:08:10 +0000</pubDate>
 <dc:creator>garyroos</dc:creator>
 <guid isPermaLink="false">comment 8586 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>the ITIL definition</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8585</link>
 <description>&lt;p&gt;You raise an important point: ITIL&#039;s categorization of Events (Information, Warning, Exception) suggests to those of us who have worked with messaging consoles in the past that an event is any detected system change of state, and an alert is a filtered message requiring human attention or human or system action.  Bit then why does it say &quot;of significance&quot; unless there was already some filtering went in to create the event?  If I spent enough time studying the holy books or withdrawing on a Practitioner retreat I would no doubt reach enlightenment eventually.&lt;/p&gt;
&lt;p&gt;Maybe we should start numbering every sentence: &quot;when David 5:13.7 says &#039;take not thy neighbour&#039;s incident ticket&#039; clearly it is a metaphor and not meant to be interpreted literally.  What I think it refers to is...&quot;&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 17:54:00 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8585 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>filtering </title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8584</link>
 <description>&lt;p&gt;It was popular then and it still is.  Filtering is one area where I believe SOME automation is useful - to improve the signal to noise ratio.&lt;/p&gt;
&lt;p&gt;But is it filtering the alerts from the message stream or the events from the alert stream or the alerts from the event stream or... tomayto tomahto&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 17:35:35 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8584 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>I&#039;m just listing ITIL concepts</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8583</link>
 <description>&lt;p&gt;Ian,&lt;br /&gt;
My list just contained the related ITIL concepts I have found.&lt;/p&gt;
&lt;p&gt;Aale&lt;/p&gt;
&lt;p&gt;PS&lt;br /&gt;
I do remember being involved in an operation automation project where the goal was to automatically filter the real alerts from the event stream. This happened in late 1980&#039;s. Suppose it was popular then.&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 09:03:17 +0000</pubDate>
 <dc:creator>aroos</dc:creator>
 <guid isPermaLink="false">comment 8583 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Event is the relevant occurence, Alert is a notification</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8582</link>
 <description>&lt;p&gt;A good answer to your question requires a bit of  &#039;why do you need it&#039;  - is it for creating a Event Mgt &#039;tool&#039;, or to explain to those people who are sent to an ITIL Foundations by their manager.&lt;br /&gt;
Taking the latter for now - my interpretation of ambiguous ITIL is as follows:&lt;/p&gt;
&lt;p&gt;Any detectable occurrence that is relevant for IT is an Event. If you think it is relevant to record that user X logs on, it&#039;s an event. If it&#039;s relevant when the temperature outside reaches 40 C, it&#039;s an event.&lt;/p&gt;
&lt;p&gt;If there&#039;s any  Event,  a series of Events, or a set of correlated Events that require special attention - you need to draw attention to it.&lt;br /&gt;
A notification to draw attention to one or more Events, is what I call an Alert.&lt;br /&gt;
Could be a pop-up for an admin, a work-order in a tool, an email to the sys-admin, an internal service request - whatever is appropriate.&lt;/p&gt;
&lt;p&gt;In the ITIL (example) categorization of Events (Information, Warning, Exception) - you could say Warnings are typically related to these Alerts, but not always.&lt;/p&gt;
&lt;p&gt;On a side note:&lt;br /&gt;
Determining which Events you want to record, or even, which Events you want new services to spawn is an interesting, not clearly identified, task/process/procedure. ITIL says &#039;making sense&#039; of Events is part of Event Management - and &quot;Service Design&quot; should pay attention to  &#039;Metrics&#039; and &#039;Service Mgt Systems and Tools&#039; - so they deal with it too.&lt;br /&gt;
I call that the &#039;tactical&#039; part of Event Mgt.&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 08:52:35 +0000</pubDate>
 <dc:creator>Niels</dc:creator>
 <guid isPermaLink="false">comment 8582 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Yet again we find ourselves intepreting the great oracle ITIL</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8580</link>
 <description>&lt;p&gt;WTF?&lt;/p&gt;
&lt;p&gt;This is why you can&#039;t and should not run around a customer site shouting ITIL - it contains sharp objects!  &lt;/p&gt;
&lt;p&gt;I&#039;m calling on my black project automated operations previous life here of 20 years ago - so treat me gently...&lt;/p&gt;
&lt;p&gt;I think earlier responders are close here - an event is anything that we can or wish to record about what is happening.  It has no implied level of importance.  An alert is an event that is of special note because someone or something has indicated an interest in that event.  Yes, one or more events can result in an alert, there should be a connection so whomever responds to the alert (notification) can access the event history and detailed records.&lt;/p&gt;
&lt;p&gt;Events are moderated (cleaned up), correlated (related), and counted amongst other actions.  So I see alerts as more of the notification aspect of an event.  &quot;You told me to tell you if this happened - it has!&quot;.  It can be threshold driven but need not be - contrary to ITIL&#039;s definition.  &lt;/p&gt;
&lt;p&gt;Lets keep incident and the rest out of this for the moment until there is some better appreciation of events and alerts... because although Aale&#039;s list is interesting it is missing &#039;events&#039; that happened prior to the event - for example - &#039;control barrier failure&#039; - and assumed the event is related to a failure - please note - a valid event could be just information or newsworthy - &quot;Its 5pm Friday and time to start overnight batch&quot;, or &quot;two floorpads have gone off in the bank after hours, more than ten feet apart, and we don&#039;t know why&quot; (hhmm thats more like two events and an alert!)&lt;/p&gt;
&lt;p&gt;So stop trying to &#039;fix ITIL&#039; just take note its at best a starter pack for those who have not lived event or alert mgt systems, and it will require someone with experience to child proof the room...&lt;/p&gt;
&lt;p&gt;Oh a tip - since storage is so much cheaper today than in my youth - you might consider recording and archiving all those events originally deemed just noise and of no interest, just in case problem management wants to have a poke around at a later date....&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 07:16:17 +0000</pubDate>
 <dc:creator>ianclayton</dc:creator>
 <guid isPermaLink="false">comment 8580 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>all just ITIL</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8578</link>
 <description>&lt;p&gt;For the benefit of readers, Gary is referring to  Figure 4.1 in the &lt;i&gt;Service Operation&lt;/i&gt; book from the ITIL-previously-known-as-V3, which is of course now Figure 4.2 in the ITIL-previously-known-as-3.1-but-now-known-as-ITIL-2011.  But hey, as TSO and &lt;a href=&quot;http://www.itskeptic.org/citizens-unite-assert-your-right-call-latest-versi&quot;&gt;a third of my readers&lt;/a&gt; insist, it is all just ITIL right?&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 03:55:12 +0000</pubDate>
 <dc:creator>skeptic</dc:creator>
 <guid isPermaLink="false">comment 8578 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>I think diagram 4.1 in the</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8575</link>
 <description>&lt;p&gt;I think diagram 4.1 in the SO book does a good job of describing the relationships between events, alerts, incidents. Not sure how it relates to the written definitions though. I like that they have drawn a distinction of actions between the warning and exception - not all filtered events should be incidents and certainly taking preventative action (via the warning) is a much more economical option. As for Informational, this needs a bit more pragmatism to it to avoid monitoring overload - we only want to record stuff which is useful - example - do I need to track a login activity for every user - no, but I want to track a login to certain systems for purposes of audit. Agreed that this is a tough concept to get across to students in a short space of time.&lt;/p&gt;
</description>
 <pubDate>Tue, 27 Sep 2011 01:39:51 +0000</pubDate>
 <dc:creator>Gary Roos</dc:creator>
 <guid isPermaLink="false">comment 8575 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Yes, I know</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8571</link>
 <description>&lt;p&gt;That was not really my question. I meant how exception differs from other ITIL terms.&lt;/p&gt;
&lt;p&gt;If a mirrored disk fails it is all of these:&lt;br /&gt;
- event&lt;br /&gt;
- alert&lt;br /&gt;
- exception&lt;br /&gt;
- failure&lt;br /&gt;
- incident&lt;br /&gt;
- problem&lt;br /&gt;
- error&lt;/p&gt;
&lt;p&gt;I think that the minimum requirement for a framework is that it contains a structured set of terms. Now ITIL has made such a mess of terms like incident and problem that they are worthless. I have written a short column on the subject here: &lt;a href=&quot;http://www.itsmportal.com/columns/word-incident-does-not-mean-anything&quot; title=&quot;http://www.itsmportal.com/columns/word-incident-does-not-mean-anything&quot; rel=&quot;nofollow&quot;&gt;http://www.itsmportal.com/columns/word-incident-does-not-mean-anything&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I teach my customers that customers have problems which IT solves. Solving a customer problem has three stages 1) restore the service 2) fix the broken component, if necessary 3) try to prevent similar customer problems in the future. &lt;/p&gt;
&lt;p&gt;These stages need three practices and one is actually kind of missing from ITIL 2011. &lt;/p&gt;
&lt;p&gt;Aale&lt;/p&gt;
&lt;p&gt; PS While exception is not in the glossary, excitement factor is.&lt;/p&gt;
</description>
 <pubDate>Mon, 26 Sep 2011 11:53:00 +0000</pubDate>
 <dc:creator>aroos</dc:creator>
 <guid isPermaLink="false">comment 8571 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>Given that ITIL is all about</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8570</link>
 <description>&lt;p&gt;Given that ITIL is all about &quot;adopt and adapt&quot; or to put it another way &quot;keep it vague and avoid the blame&quot; I think you can pretty much use most of the terms in what ever way works for you. &lt;/p&gt;
&lt;p&gt;In the absence of something definitive I like Peters take on it above and was about to submit something similar along the lines of &quot;an alert is the notification created when an event occurs which exceeds a predefined threshold&quot;&lt;/p&gt;
&lt;p&gt;Yes..that&#039;s vague enough....perfect :)&lt;/p&gt;
</description>
 <pubDate>Sat, 24 Sep 2011 23:03:38 +0000</pubDate>
 <dc:creator>Chris Evans</dc:creator>
 <guid isPermaLink="false">comment 8570 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>This IS confusing</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8567</link>
 <description>&lt;p&gt;Try to explain this to people in an ITIL Foundation class, where you have limited time and limited text... (sigh)&lt;/p&gt;
&lt;p&gt;I have interpreted in the following way:&lt;/p&gt;
&lt;p&gt;Anything that has a significance for the the management of the infrastructure is an event. Which means from &#039;someone logged in&#039; to &#039;system failed&#039;. Events can be classified as: informational, warning, exceptional. &lt;/p&gt;
&lt;p&gt;We have one set of events that we set thresholds for. We call these alerts. So alerts are a subset of events. Because we reach a threshold we have to take special action. This is where it becomes interesting: Are these the ones we would open incidents for ????&lt;/p&gt;
&lt;p&gt;This is my interpretation... not saying this is correct, but people seem to accept this... the question of course rises is this THE best practice.&lt;/p&gt;
&lt;p&gt;Regards&lt;br /&gt;
Peter Lijnse&lt;/p&gt;
</description>
 <pubDate>Sat, 24 Sep 2011 13:07:13 +0000</pubDate>
 <dc:creator>PELIJN</dc:creator>
 <guid isPermaLink="false">comment 8567 at http://www.itskeptic.org</guid>
</item>
<item>
 <title>It seems to be clear that</title>
 <link>http://www.itskeptic.org/does-itil-explain-difference-between-alert-and-eve#comment-8566</link>
 <description>&lt;p&gt;It seems to be clear that ITIL isn&#039;t clear about these terms, and there isn&#039;t much value trying to make sense out of it based on ITIL. So you have to depend on yourself.&lt;/p&gt;
&lt;p&gt;Here what MOF thinks about Event/Alert,&lt;/p&gt;
&lt;p&gt;Event: An occurrence within the IT environment detected by a monitoring tool.&lt;br /&gt;
Alert: A notification that an event requiring attention has occurred. &lt;/p&gt;
&lt;p&gt;I disagree with the Event definition. Based on my understanding of the english language I would prefer to change the definition of Event as stated below. I realize it&#039;s very broad but maybe that&#039;s just what it is.&lt;/p&gt;
&lt;p&gt;Event: A noteworthy occurrence within the IT environment.&lt;br /&gt;
Alert: A notification that an event requiring attention has occurred. &lt;/p&gt;
&lt;p&gt;I recall my first ITIL slides trying to sell it to management, which included some words like common terminology, standard taxonomy etc..... little did I know then. (still don&#039;t know much about ITIL, but learning a lot about ITSM every day).&lt;/p&gt;
&lt;p&gt;regards&lt;br /&gt;
Osama S.&lt;/p&gt;
</description>
 <pubDate>Sat, 24 Sep 2011 13:04:37 +0000</pubDate>
 <dc:creator>Osama Salah</dc:creator>
 <guid isPermaLink="false">comment 8566 at http://www.itskeptic.org</guid>
</item>
</channel>
</rss>
