In DX NetOps Spectrum, when using the VMware vCenter integration (Virtual Host Manager), child alarms (such as VM Contact Lost) that are suppressed under a parent alarm (such as ESX Host Down) may clear automatically when the parent alarm is resolved. This occurs even if the underlying child device is still unreachable.
Foe example, during a parent outage (e.g., ESX host down), child VMs generate "Contact Lost" alarms. Spectrum's correlation engine hides these under the parent probable cause (e.g., `0x56e000c`). When the ESX host recovers, the hidden child alarms (probable cause `0x10009`) clear automatically, changing the VM condition to "Normal," even if the VM agent has not recovered.
This is the default design of Spectrum's Root Cause Analysis (RCA). When a parent alarm is cleared, Spectrum clears all associated "impact" or "suppressed" child alarms to prevent stale alerts.
To ensure child alarms only clear after independent confirmation of reachability:
0x10009).0x1000a) rather than the parent's recovery.For detailed steps on custom correlations, see the [Condition Correlation Documentation](https://techdocs.broadcom.com/us/en/ca-enterprise-software/it-operations-management/spectrum/24-3/managing-network/condition-correlation.html).
If further assistance is needed, see [Contact Support](https://support.broadcom.com/web/ecx/contact-support). Scroll to the bottom of the page and click on your respective region to speak with a customer representative or a Support Engineer.