Skip to content

Alert Policy


When a Monitor detects an anomaly, it automatically creates an anomaly event record. By associating monitors with alert policies, you can ensure that relevant alert notifications are sent to designated targets in a timely manner.

Alert policies support configuration of basic information such as name, description, and timezone, and provide flexible alert rule settings:

  • Define notification methods based on two dimensions: alert level and notification target

  • Support alert escalation rules to meet urgent scenario requirements

  • Allow custom notification sending times to suit different business scenarios

  • Support repeated alert rules to flexibly control notification frequency

  • Support aggregating notification content to deliver alert information more efficiently

Concepts

Term
Description
Notification timezone Defines the timezone in which alert notifications are sent. By default, the current Workspace timezone is displayed here. If the owner or administrator has not configured it, UTC+8 is used by default
Event level Indicates the urgency of anomaly events. Available levels include Critical, Severe, Important, Warning, Data Gap, Info, All
Alert Escalation Sometimes simple notification configuration based on levels or members cannot meet business requirements. If a monitor detects anomalies of the same level multiple times within a short period, it may indicate a persistent issue. To avoid repeated notifications, you can set rules to automatically escalate persistent anomalies into urgent notifications and send them to designated recipients, ensuring that issues receive timely attention and resolution
Custom notification time Set the specific moments for sending notifications based on two dimensions: period and time
Repeated alerts You can specify a time interval within which alert notifications for the same event are suppressed. Even if event data continues to be generated, the system only records the events without sending repeated alerts. The event records can be viewed in the Event Explorer. For example, if an event in your workspace is not very urgent but generates alert notifications at a high frequency, you can reduce the alert notification frequency by setting a time interval for repeated alert notifications
Alert Aggregation Defines the four modes for sending notifications: no aggregation, rule-based aggregation, smart aggregation, and AI aggregation. In the latter two modes, events are merged according to the corresponding aggregation rules before being sent
Aggregation Cycle In rule-based aggregation and smart aggregation modes, new events occurring within a certain number of minutes are merged into one alert notification. Once the aggregation cycle is exceeded, newly occurring events are grouped into the next alert notification

Getting Started

Feedback

Is this page helpful?