Interval Detection¶
About This Document
This document is the second step in the detection rule configuration process. After completing the configuration, return to the main document to continue with the third step: Event Notification.
Within the selected time range, the system performs anomaly detection on metric data. If the proportion of sudden-change anomalies among the detected data points exceeds the preset threshold percentage, an interval anomaly event is triggered.
Suitable for monitoring data/metrics with stable trends. For example, an anomaly event is generated when the proportion of data points with sudden-change anomalies in host CPU usage exceeds 10% in the last 1 day.
Detection Configuration¶
Detection Frequency¶
Set the time period for executing detection; it automatically matches the selected detection interval.
| Detection Interval (Dropdown Options) | Detection Frequency |
|---|---|
| 15m | 5m |
| 30m | 5m |
| 1h | 15m |
| 4h | 30m |
| 12h | 1h |
| 1d | 1h |
Detection Interval¶
Set the data time range for each detection query (❗️The detection interval must be greater than or equal to the detection frequency, and must match the actual data reporting period to avoid missed detections or false positives).
-
Preset options: Last 15 minutes, Last 30 minutes, Last 1 hour, Last 4 hours, Last 12 hours, Last 1 day
-
Custom format: Customize the detection interval, e.g., 20m (last 20 minutes), 2h (last 2 hours), 1d (last 1 day).
Detection Metrics¶
Define the detection data source and aggregation method based on DQL (❗️Avoid selecting high-cardinality fields as detection dimensions. Improper configuration with overly loose trigger conditions may lead to frequent alerts. The current query returns a maximum of 100,000 records).
Configuration Options¶
| Configuration Item | Description |
|---|---|
| Workspace | Defaults to the current workspace. You can switch to other authorized workspaces. After authorization, you can use the detection metrics of other workspaces under the current account to create monitors. Once the rule is created, cross-workspace alert configuration is enabled. Note that when you select another workspace, the detection metric dropdown only displays the data types that the current workspace is authorized to use. |
| Data Source Type | Metrics, Logs, Infrastructure, Resource Catalog, Events, Application Performance Monitoring (APM), Real User Monitoring (RUM), Network, Profiling, etc. |
| Query Method | Simple Query, Expression Query |
| Detection Dimensions | Any string type (keyword) field in the configured data can be selected as a detection dimension. Up to three fields are currently supported. A specific detection object can be determined by combining multiple detection dimension fields. The system determines whether the statistical metric corresponding to a detection object meets the trigger condition threshold; if so, an event is generated.For example, if host and host_ip are selected as detection dimensions, the detection object can be {host: host1, host_ip: 127.0.0.1}. |
| Filter Conditions | Filter the detection metric data based on metric tags to limit the detection data range. Supports adding one or more tag filters, and supports fuzzy match and fuzzy not-match filter conditions. |
| Aggregation Algorithm | Avg by (average), Min by (minimum), Max by (maximum), Sum by (sum), Last (last value), First by (first value), Count by (number of data points), Count_distinct by (number of distinct data points), p50 (median), p75 (value at the 75th percentile), p90 (value at the 90th percentile), p99 (value at the 99th percentile), etc. |
| Alias | Customize the name of the detection metric. |
Click to view Query Method Details.
Trigger Conditions¶
Configure trigger conditions and severity. When the query result contains multiple values, an event is generated if any value meets the trigger condition.
Supports configuring four severity thresholds—Fatal, Critical, Important, Warning—as well as the Normal recovery condition.
| Severity | Configuration | Description |
|---|---|---|
| Fatal | When the change direction is Up or Down/Up/Down, Result >= [value] % |
Compares the proportion of sudden-change anomaly data points. An event is triggered when the result is not within the configured range. |
| Critical | When the change direction is Up or Down/Up/Down, Result >= [value] % |
Compares the proportion of sudden-change anomaly data points. An event is triggered when the result is not within the configured range. |
| Important | When the change direction is Up or Down/Up/Down, Result >= [value] % |
Compares the proportion of sudden-change anomaly data points. An event is triggered when the result is not within the configured range. |
| Warning | When the change direction is Up or Down/Up/Down, Result >= [value] % |
Compares the proportion of sudden-change anomaly data points. An event is triggered when the result is not within the configured range. |
| Normal | [N] detection runs with no events generated |
After the detection rule takes effect, if the data detection result returns to normal from abnormal (Fatal, Critical, Important, Warning) within the configured number of custom detections, a recovery alert event is triggered. ❗️Recovery alert events are not subject to alert muting. If the recovery alert event detection count is not set, the alert event will not recover and will remain in the Events > Unrecovered Events list. |
For more details, refer to Event Level Description.
Bulk Alert Protection¶
Enabled by default.
When the number of alerts generated by a single detection exceeds the preset threshold, the system automatically switches to a status-based aggregation strategy: instead of processing alert objects one by one, it generates and pushes a small number of summary alerts based on event status.
This ensures timely notifications while significantly reducing alert noise, avoiding the risk of timeouts caused by processing too many alerts.
When this toggle is enabled, the Event Details of such events generated after the monitor detects anomalies will not display historical records or related events.
Data Gap¶
Handling strategy when the detection metric returns empty query results within the detection interval:
| Option | Description |
|---|---|
| Do Not Trigger Events (Default) | Works in conjunction with the detection interval's time range to determine whether to generate events based on the query results of the detection metric in the most recent few minutes. Suitable for scenarios where missing data is acceptable. |
| Treat Query Results as 0 | Works in conjunction with the detection interval's time range, treats the query results of the detection metric in the most recent few minutes as 0, and re-compares them with the thresholds configured in Trigger Conditions above to determine whether to trigger an anomaly event. |
| Custom Fill and Trigger Events | Supports custom filling of detection interval values and triggers the following event types respectively: Data Gap Event, Emergency Event, Important Event, Warning Event, and Recovery Event. ❗️When selecting this strategy, it is recommended to configure the custom data gap time ≥ the detection interval duration; if the configured time is ≤ the detection interval duration, a data gap and an anomaly may be detected simultaneously, in which case the data gap handling result takes priority. |
When Trigger Conditions, Data Gap, and Info Event Generation are configured simultaneously, the trigger is judged according to the following priority: Data Gap > Trigger Conditions > Info Event Generation.
That is, first determine whether there is a data gap, then whether a threshold is triggered, and finally whether an info event is generated.
Info Event Generation¶
When this option is enabled, Info Event Generation Conditions must be configured. Only when the detection result does not trigger any of the "Fatal", "Critical", "Important", or "Warning" thresholds and the info event generation conditions are met will the system write an "Info" event.
Suitable for scenarios where normal state changes or low-priority information needs to be recorded.
Next Steps¶
After completing the above detection configuration, continue with the following:
-
Event Notification: Define the event title, content, notified members, data gap handling, and incident association;
-
Alert Configuration: Select an alert policy, and set notification targets and the mute period;
-
Link: Associate a dashboard for quick navigation to view data;
-
Permissions: Set operation permissions to control who can edit or delete this monitor.