Alert Policy: More Refined Notification Target Configuration¶
Optimizing Alert Rule Configuration¶
To handle complex and ever-changing monitoring environments and alert on abnormal events more flexibly, Alert Policy adds a "Filter" feature. When configuring alert rules, the Filter feature allows you to add more granular filtering conditions on top of the original levels. Only events that match both the level and the filter conditions are sent to the corresponding notification targets.
Alert Rule Configuration¶
Filter¶
Click the "+" icon to the right of a notification target to open the filter condition input box.
Filter rules:
-
After clicking Filter, the fields of the current workspace are automatically listed.
key:valuematching supports equals, not equals, wildcard, and negated wildcard. -
Only one group of filter conditions can be added under each alert rule. A group can contain one or more filter rules, and the filter rules are combined to filter conditions.
Filter rules filter by key:value value matching. Multiple filter conditions with the same key field are combined with OR, while filter conditions with different key fields are combined with AND.
Configure Alert Rules¶
The Filter feature takes effect in notification configuration and can be applied to custom notification time configuration and standard configuration.
Standard Notification Configuration¶
Scenario: Use this when a unified notification rule applies to all events. You can configure rules directly in Notification Configuration.
-
After selecting an event level, click the "+" icon to the right of the notification target and enter the filter condition in the pop-up filter condition box.
-
Only events that meet both the level and the filter conditions are sent to the corresponding notification target.
Custom Notification Time¶
Scenario: Use this when events triggered during a specific time period need to alert specific members. Click Custom Notification Time to configure.
-
In Custom Notification Configuration, configure necessary settings such as recurrence and time, select the event level, click the "+" icon to the right of the notification target, and configure the filter condition in the pop-up filter condition input box.
-
In the Other Times configuration area, select the level, click the "+" icon to the right of the notification target, and configure the filter condition in the pop-up filter condition input box.
Effect:
For an alert policy with a custom notification time configured, when a monitor triggers an event, the trigger time is evaluated first. Depending on whether the event trigger time falls within the recurrence and time of the custom notification configuration, the rules of Custom Notification Configuration or Other Times are evaluated. The event is then checked against the level and filter condition rules. Only events that meet both the configured level and filter conditions are sent to the corresponding notification targets.
Other Application Scenarios¶
Filter conditions and levels work together as detection rule items to evaluate events and match notification targets.
Select All Levels¶
Scenario: If a monitor triggers an event, regardless of its level, you want to alert specific people as long as the event's key:value values match.
Operation: Select "All" for the level, click the "+" icon, and fill in the rules in the filter condition area. After configuration, abnormal events are checked only against the filter conditions.
Multiple Notification Rule Groups for the Same Level¶
The restriction on the number of times an event level can be selected is removed. The same level can be selected and configured in multiple notification rule groups.
Scenario: If a monitor triggers multiple events at the same level, events with different attributes need to alert different targets.
Operation: Configure multiple notification rules, select the same level for these rules, and configure different filter conditions for each. After selecting notification targets, alerts can be sent to the corresponding people based on attribute values.
Notification Targets Support Custom External Email Addresses¶
To make it easier to handle issues, the system supports sending anomaly alerts to external members. You can click the notification target input field and enter a custom external email address directly.
Scope of application:
- When creating an alert policy, manually enter the notification target.
- When creating a monitor, add via the @ mention in event details.
Note
This feature is only available in the SaaS Commercial Plan and Deployment Plan.





