如何编写Prometheus Alertmanager支持多实例多挂载点的挂载状态告警规则
问题根因
你之前的写法失效是因为absent()函数的逻辑是仅当整个查询返回的结果集完全为空时才返回1,只要任意一个实例的任意一个匹配的挂载点存在,absent()就会返回空,不会触发告警,完全没法实现按每个实例、每个挂载点单独判断存在性的需求。
解决方案
我们可以用PromQL的unless运算符实现按标签组合的存在性判断:先构造所有需要监控的实例+挂载点预期组合的指标向量,再和实际上报的文件系统指标做匹配,只要某个预期组合没有实际上报的指标,就会保留下来触发告警。
通用实现规则
groups: - name: mountpoints rules: - alert: MountpointMissing expr: | # 构造所有预期的<instance, mountpoint>监控组合 # 单个组合写法:label_replace(label_replace(vector(1), "instance", "实例地址", "", ""), "mountpoint", "挂载点路径", "", "") label_replace(label_replace(vector(1), "instance", "my.machine.org:9100", "", ""), "mountpoint", "/ghome", "", "") or label_replace(label_replace(vector(1), "instance", "my.machine.org:9100", "", ""), "mountpoint", "/something", "", "") or label_replace(label_replace(vector(1), "instance", "my.machine.org:9100", "", ""), "mountpoint", "/other", "", "") or label_replace(label_replace(vector(1), "instance", "another.machine.org:9100", "", ""), "mountpoint", "/ghome", "", "") # 过滤掉实际存在的挂载点,剩余即为缺失的组合 unless on(instance, mountpoint) node_filesystem_avail_bytes for: 60s labels: severity: critical annotations: summary: "挂载点 {{ $labels.mountpoint }} 在实例 {{ $labels.instance }} 上缺失" description: "实例未上报对应挂载点的使用指标,确认挂载已丢失。\n标签信息:{{ $labels }}"
简化写法(所有实例需监控的挂载点完全一致时使用)
如果所有待监控实例都需要检查相同的一批挂载点,可以用更简洁的写法,直接修改正则即可批量新增实例或挂载点:
expr: | # 填写所有需要监控的实例地址,用|分隔 label_replace(vector(1), "instance", "my.machine.org:9100|another.machine.org:9100", "", "") + on() group_left(mountpoint) # 填写所有需要监控的挂载点路径,用|分隔 label_replace(vector(1), "mountpoint", "/ghome|/something|/other", "", "") unless on(instance, mountpoint) node_filesystem_avail_bytes
逻辑说明
unless on(instance, mountpoint)会按instance和mountpoint两个标签做匹配,只要实际上报的node_filesystem_avail_bytes中存在对应标签组合的记录,就会从左侧的预期组合列表中删除该条目,最终剩余的就是已经丢失的挂载点组合- 每个缺失的
实例+挂载点组合会单独生成告警,无需为每个组合单独编写告警规则,后续维护只需要更新左侧的预期组合列表即可
内容的提问来源于stack exchange,提问作者Völker Graf
相关产品推荐
相关产品推荐

