GCP Cloud Monitoring日志周同比摄入告警未触发问题排查
需求说明
- 配置日志量告警规则:当服务生成的日志量显著高于上周同期水平时,推送告警通知
- 日志生成速率存在日内正弦波动规律,数值全天随时间周期性起伏,单纯使用固定阈值检测的灵敏度过低,若存在更优的实现方案可替换现有逻辑
现有实现问题
当前基于GCP的Monitoring Query Language(MQL)编写的告警策略,配置完成后始终未触发任何告警事件,使用的MQL查询语句如下:
fetch global::logging.googleapis.com/billing/bytes_ingested | align delta_gauge(1m) | { t_0: ident ; t_1: time_shift 1w } | join | value [t_0_value_bytes_ingested_mean_sub: sub(t_0.value.bytes_ingested, t_1.value.bytes_ingested)] | condition ge(t_0_value_bytes_ingested_mean_sub, 10'MiBy’)
该查询返回的指标输出示意图:
完整告警配置
通过GCP监控REST接口拉取到的完整AlertPolicy配置如下:
{ "name": "projects/[PROJECT_ID_OR_NUMBER]/alertPolicies/[ALERT_POLICY_ID]", "displayName": "日志量告警:较上周同期增量超10MiB/分钟", "combiner": "OR", "creationRecord": { "mutateTime": "2022-06-16T14:15:51.572165064Z", "mutatedBy": "[已脱敏]" }, "mutationRecord": { "mutateTime": "2022-06-24T10:14:45.366847354Z", "mutatedBy": "[已脱敏]" }, "conditions": [ { "displayName": "日志量告警:较上周同期增量超10MiB/分钟", "name": "projects/[PROJECT_ID_OR_NUMBER]/alertPolicies/[ALERT_POLICY_ID]/conditions/6368804464715103184", "conditionMonitoringQueryLanguage": { "query": "fetch global::logging.googleapis.com/billing/bytes_ingested\n| align delta_gauge(1m)\n| { t_0: ident\n ; t_1: time_shift 1w }\n| join\n| value\n [t_0_value_bytes_ingested_mean_sub:\n sub(t_0.value.bytes_ingested, t_1.value.bytes_ingested)]\n| condition ge(t_0_value_bytes_ingested_mean_sub, 10'MiBy')", "duration": "0s", "trigger": { "count": 1 } } } ], "documentation": { "content": "执行对应处置操作", "mimeType": "text/markdown" }, "notificationChannels": [ "projects/[PROJECT_ID_OR_NUMBER]/notificationChannels/[已脱敏]" ], "enabled": true, "alertStrategy": { "autoClose": "604800s" } }
内容的提问来源于stack exchange,提问作者Dominik
相关产品推荐
相关产品推荐

