Goal: to group log messages (and monitoring alerts, like SNMP traps next) into groups so you can work out:
a) CRIT What do I really have to worry about - immediate action - like a full COS root filesystem, or something that how high impact/urgency
b) WARN What messages do I need to be aware of, like a path failure or disk capacity warnings, something with medium impact/urgency
c) WATCH What messages should I track for trending - like %RDY time for a guest?
d) IGNORE What messages don't I care about?
Is there a standard already for the colour scheme for these kind of message groups? I've chosen what makes sense to me... does anyone else have input for this grouping?