如何通过Terraform配置GCP基于日志错误触发的告警规则
你的实现思路是正确的,基于google_monitoring_alert_policy资源确实可以实现GCP指定日志触发告警的需求,你只需要修改以下几个配置项即可匹配需求:
- 修正
filter过滤规则
你当前填写的metric.type参数值错误,统计日志条目数需要使用logging.googleapis.com/log_entry_count这个指标。如果需要指定只统计error类型的日志,有两种常用配置方式:- 匹配日志级别为ERROR:在filter中添加
severity="ERROR"规则 - 匹配日志内容包含error关键字:如果你的日志是结构化JSON格式,可以添加
jsonPayload.message=~".*error.*"规则,非结构化日志可调整为textPayload=~".*error.*"
- 匹配日志级别为ERROR:在filter中添加
- 调整阈值配置
你当前的threshold_value设置为300,直接修改为100即可匹配「1小时内超过100条触发告警」的规则,原有的duration="1h"配置是正确的。
修正后的完整配置示例如下:
resource "google_monitoring_alert_policy" "too_many_errors_alerts" { display_name = "TERRAFORM -- Too many errors alerts" enabled = true combiner = "OR" conditions { display_name = "Too many errors alerts" condition_threshold { # 过滤规则示例:统计Cloud Run服务的ERROR级别日志条目数,可自行扩展匹配规则 filter = "metric.type=\"logging.googleapis.com/log_entry_count\" resource.type=\"cloud_run_revision\" severity=\"ERROR\"" duration = "1h" comparison = "COMPARISON_GT" threshold_value = 100 # 补充聚合规则,统计1小时窗口内的日志总条数 aggregations { alignment_period = "3600s" per_series_aligner = "ALIGN_SUM" cross_series_reducer = "REDUCE_SUM" } trigger { count = 1 } } } # 可选配置:关联告警通知渠道,需提前创建对应google_monitoring_notification_channel资源 # notification_channels = [google_monitoring_notification_channel.your_notification_channel.id] }
内容的提问来源于stack exchange,提问作者andolffer.joseph
相关产品推荐
相关产品推荐

