Skip to main content
An alert rule reads as one sentence: aggregation of measure, over spans matching the filters, in the last window, compared to a threshold. This page lists what each part accepts.

Measures

Alerts measure spans. Each measure has a unit, and the threshold you enter is in that unit.
Latency is in milliseconds and cost is in US dollars. “p95 latency over 2 seconds” is a threshold of 2000, and “more than five cents” is 0.05.

Aggregations

There are 11 aggregations: sum, avg, count, max, min, p50, p75, p90, p95, p99 and uniq. Which ones a measure accepts depends on its type: The form only offers valid pairs. The API rejects an invalid pair. uniq counts distinct values, so its result is a count rather than a value in the measure’s unit.

Trigger

The aggregated value is compared to the threshold with one of six operators: >, >=, <, <=, =, !=. A rule has a single threshold. For two levels, such as a warning and a critical level, create two alerts.

Window

The window is how far back each evaluation looks: 1m, 5m, 10m, 30m, 1h or 2h. The default is 10m. The window is a lookback, not a notification rate. Rules with a window of 5 minutes or less are measured at the pace of their window, and wider windows are measured every 5 minutes.

Filters

Filters limit which spans are measured. A span must match every filter on the rule. Unique user ids and Unique session ids cannot be combined with filters.

When a window has no data

A window with no matching spans produces no value. The no-data mode decides what that means: Under NOTIFY, a single empty window does not notify. The message is sent once the gap has lasted the shorter of the rule’s window or 10 minutes.

Renotify

Renotify controls whether a rule that stays in breach repeats its message.
  • Off (default): the rule notifies only when it enters Alert and when it recovers.
  • Re-alert at a regular interval: the breach message repeats every N minutes while the rule stays in Alert. The interval can be from 1 minute to 7 days (10,080 minutes) and defaults to 60 minutes.

Severities

The severity is the result of the latest evaluation. A rule whose last run failed shows Failing in the list, with the error, and retries on the next minute.

Statuses

The status says whether the rule is being evaluated at all. You can set only ACTIVE and PAUSED. PARKED is set by the evaluator, and the rule’s badge states the reason. To start a parked rule again, edit and save it, or resume it. A parked rule cannot be paused.

Limits

  • 100 alerts per project. Paused and parked alerts count toward the limit.
  • Names can be up to 200 characters and do not have to be unique.

Next steps

Get Started

Create a rule and check it against the live preview.

Slack Delivery

What each message contains and how to fix a failed delivery.