I have read through the EMS documentation, as well as the following KB articles, but I am still confused about EMS messages:
https://docs.netapp.com/us-en/ontap/error-messages/index.html
https://kb.netapp.com/onprem/ontap/OS/What_is_EMS_and_what_is_the_difference_between_the_messages_in_etc_messages_and_etc_log_ems_files
https://kb.netapp.com/mgmt/AIQUM/How_to_configure_and_receive_alerts_from_ONTAP_EMS_Event_Subscription_in_Active_IQ_Unified_Manager
From what I am understanding from this, if we forward our EMS alerts to AIQUM, it really does nothing unless we specifically subscribe to each message type to get the resulting alert from AIQUM. In OnTap 9.8, there are 7162 different EMS messages (according to the "event route show"). Even if I were to just subscribe to ERROR and above, that is still 3270 different messages that we would need to subscribe to individually. There does not appear to be a way to subscribe to all EMS messages ERROR and above in AIQUM: "Multiple events (regardless of delimiter) or 'wildcard' events (example: snapmirror.status*) cannot be used in the 'EMS event name' field or the subscription process will fail."
So, how do you make sure that you are getting important EMS events about your clusters? If we are not subscribed to all of these events, are we missing important alerts about our clusters?