You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Prometheus告警:首次5分钟触发后4小时再触发同一规则

Prometheus告警规则配置修改建议

核心需求实现方案

要实现相同appname+operation组合的告警首次延迟5分钟触发,后续每4小时才重复触发,同时解决确认后不重复触发的问题,需结合Prometheus记录规则、告警表达式逻辑和抑制规则来完成。

具体配置修改步骤

1. 新增记录告警触发时间的规则

先添加一条记录规则,跟踪每个(appname, operation)组合的最近一次告警触发时间:

groups:
- name: alert_recording_rules
  rules:
  - record: dummy_alert:last_triggered_timestamp
    expr: |
      time() unless on(appname, operation) dummy_alert:last_triggered_timestamp
    labels:
      alertname: DummyAlert

这条规则会在告警触发时自动更新对应组合的时间戳,用于后续判断是否满足4小时间隔要求。

2. 修改原告警规则的表达式

更新expr字段,加入4小时间隔判断逻辑,确保仅首次触发(无历史记录)或距离上次触发超过4小时才会触发告警:

- alert: DummyAlert
  expr: |
    sum by (appname, operation)(increase(mycounter{appname="abc", operation="xyz"} [5m])) > 0
    and
    (
      absent(dummy_alert:last_triggered_timestamp{alertname="DummyAlert"})
      or
      time() - dummy_alert:last_triggered_timestamp{alertname="DummyAlert"} > 14400  # 4小时=14400秒
    )
  for: 5m  # 保留首次触发的5分钟条件验证
  labels:
    severity: critical
    maintainedby: test
    teamname: test
  annotations:
    summary: test alert
    description: 'test alert'

3. 添加告警抑制规则(解决确认后重复触发问题)

假设告警被确认后会添加自定义标签(比如acknowledged="true"),配置抑制规则确保已确认的同组合告警在4小时内不会重复触发:

inhibit_rules:
- source_match:
    alertname: DummyAlert
    acknowledged: "true"
  target_match:
    alertname: DummyAlert
  equal: ['appname', 'operation']
  # 仅当目标告警距离上次触发未超过4小时才抑制
  target_match_expr: 'time() - dummy_alert:last_triggered_timestamp < 14400'

如果你的告警系统无确认标签,可通过跟踪告警的resolved状态调整逻辑,确保确认后的告警不会立即重复触发。

关键说明

  • dummy_alert:last_triggered_timestamp指标持续跟踪每个组合的最近触发时间,保证间隔判断精准。
  • for: 5m保留首次触发的5分钟延迟,避免瞬时波动误触发告警。
  • 抑制规则确保已确认的告警在4小时周期内不会重复触发,同时不影响周期后的正常告警。

内容的提问来源于stack exchange,提问作者DeadPool

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 02:58:16