비정적 임계값 모니터링하기
비정적 임계값 모니터링하기 (How to monitor non-static thresholds)
전형적인 메트릭 모니터는 단일 메트릭이 특정 임계값 숫자보다 높아지면 경보를 트리거해요. 예를 들어 디스크 사용량이 80%를 넘으면 경보가 트리거되도록 설정할 수 있어요. 이 접근 방식은 많은 사용 사례에 효율적이지만, 임계값이 절대 숫자가 아니라 변수라면 어떻게 될까요?
Watchdog 기반 모니터(즉 이상(anomaly) 및 아웃라이어(outlier))는 메트릭이 정상 궤도를 벗어났다는 명시적 정의가 없을 때 특히 유용해요. 하지만 가능하다면 특정 사용 사례에 맞춘 알림 조건을 가진 일반 모니터를 사용해 정밀도를 극대화하고 경보 발생까지의 시간을 최소화해야 해요.
이 가이드는 비정적(non-static) 임계값에 대한 경보의 일반적인 사용 사례를 다뤄요:
- 계절적 변동(seasonal variations) 밖으로 벗어나는 메트릭에 대해 경보
- 다른 참조(reference) 메트릭의 값을 기반으로 경보
출처: 문서
본문
계절적 임계값 (Seasonal threshold)
컨텍스트 (Context)
이커머스 웹사이트를 담당하는 팀 리드라고 가정해볼게요. 다음을 원해요:
- 홈페이지의 예상치 못하게 낮은 트래픽에 대해 경보 받기
- 공용 인터넷 제공업체에 영향을 주는 것 같은 더 지역화된 인시던트 포착하기
- 알 수 없는 실패 시나리오 대비하기
웹사이트 트래픽은 밤과 낮, 평일과 주말에 따라 달라져요. "예상치 못하게 낮다"를 정량화할 절대 숫자는 없어요. 하지만 트래픽은 예측 가능한 패턴을 따르므로, 10% 차이를 공용 인터넷 제공업체에 영향을 주는 지역화된 인시던트 같은 문제의 신뢰할 수 있는 지표로 간주할 수 있어요.
{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_line_graph.eebfa1f0a92715a4cb5590cd2052bb54.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_line_graph.eebfa1f0a92715a4cb5590cd2052bb54.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Line graph of a periodic or seasonal metric" /%}
모니터 (Monitor)
팀은 nginx.requests.total_count 메트릭으로 NGINX 웹 서버의 연결 수를 측정해요.
요청(request) 은 3부분으로 구성돼요:
- 현재 요청 수를 가져오는 쿼리.
- 일주일 전 같은 시각의 요청 수를 가져오는 쿼리.
- 처음 두 쿼리 사이의 비율을 계산하는 "Formula" 쿼리.
그다음 시간 집계를 결정해요:
- 시간 프레임을 선택해요. 시간 프레임이 클수록 이상을 감지하기 위해 평가하는 데이터가 많아져요. 시간 프레임이 크면 모니터 경보도 더 많아질 수 있으므로, 1시간으로 시작해 필요에 맞게 조정해요.
- 집계를 선택해요. 비율을 수행하는 count 메트릭이므로
average(또는sum)가 자연스러운 선택이에요.
아래 스크린샷에 표시된 임계값은 첫 번째 쿼리(현재)와 두 번째 쿼리(일주일 전) 값 사이의 10% 차이를 허용하도록 0.9로 구성되어 있어요.
{% tab title="UI Configuration" %}
{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_threshold_config.c0957bc274c84f82e2241f73c508f666.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_threshold_config.c0957bc274c84f82e2241f73c508f666.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Configuration to add week_before timeshift to metric query and set formula a/b" /%}
{% /tab %}
{% tab title="JSON Example" %}
{
"name": "[Seasonal threshold] Amount of connection",
"type": "query alert",
"query": "sum(last_10m):sum:nginx.requests.total_count{env:prod} by {datacenter} / week_before(sum:nginx.requests.total_count{env:prod} by {datacenter}) <= 0.9",
"message": "The amount of connection is lower than yesterday by {{value}} !",
"tags": [],
"options": {
"thresholds": {
"critical": 0.9
},
"notify_audit": false,
"require_full_window": false,
"notify_no_data": false,
"renotify_interval": 0,
"include_tags": true,
"new_group_delay": 60,
"silenced": {}
},
"priority": null,
"restricted_roles": null
}
{% /tab %}
참조 임계값 (Reference threshold)
컨텍스트 (Context)
QA 팀 리드로서 이커머스 웹사이트의 체크아웃 프로세스를 담당하고 있다고 해볼게요. 고객이 좋은 경험을 하고 문제 없이 제품을 구매할 수 있도록 보장하고 싶어요. 이를 나타내는 지표 중 하나가 오류율이에요.
트래픽은 하루 종일 동일하지 않아서, 금요일 저녁의 분당 50개 오류는 일요일 아침의 분당 50개 오류보다 덜 우려돼요. 오류 자체가 아니라 오류율을 모니터링하면 건강한 메트릭과 건강하지 않은 메트릭이 어떤 모습인지 신뢰할 수 있게 볼 수 있어요.
오류율이 높을 때뿐 아니라 힛(hit)의 양이 충분히 클 때도 경보를 받아요.
모니터 (Monitor)
총 3개의 모니터를 만들어요:
- 총 힛 수에 대해 경보하는 메트릭 모니터.
- 오류율을 계산하는 메트릭 모니터.
- 처음 두 모니터가 ALERT 상태면 경보를 트리거하는 복합(composite) 모니터.
총 힛 수에 대해 경보하는 메트릭 모니터 (Metric monitor to alert on the total number of hits)
첫 번째 모니터는 성공과 실패를 모두 포함한 총 힛 수를 추적해요. 이 모니터는 오류율이 경보를 트리거해야 하는지 결정해요.
{% tab title="UI Configuration" %}
{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_total_hits.55947f19b807662039b288eb84aee014.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_total_hits.55947f19b807662039b288eb84aee014.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Metric monitor configuration with formula to calculate total hits" /%}
{% /tab %}
{% tab title="JSON Example" %}
{
"name": "Number of hits",
"type": "query alert",
"query": "sum(last_5m):sum:shopist.checkouts.failed{env:prod} by {region}.as_count() + sum:shopist.checkouts.success{env:prod} by {region}.as_count() > 4000",
"message": "There has been more than 4000 hits for this region !",
"tags": [],
"options": {
"thresholds": {
"critical": 1000
},
"notify_audit": false,
"require_full_window": false,
"notify_no_data": false,
"renotify_interval": 0,
"include_tags": true,
"new_group_delay": 60
}
}
{% /tab %}
오류율을 계산하는 메트릭 모니터 (Metric monitor to calculate the error rate)
두 번째 모니터는 오류율을 계산해요. 오류율 a / a+b를 얻기 위해 오류 수를 총 힛 수로 나눈 쿼리를 만들어요:
{% tab title="UI Configuration" %}
{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_error_rate.5c0f5ca88cbc364b6446841751c99a58.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_error_rate.5c0f5ca88cbc364b6446841751c99a58.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Metric monitor configuration with formula to calculate error rate" /%}
{% /tab %}
{% tab title="JSON Example" %}
{
"name": "Error Rate",
"type": "query alert",
"query": "sum(last_5m):sum:shopist.checkouts.failed{env:prod} by {region}.as_count() / (sum:shopist.checkouts.failed{env:prod} by {region}.as_count() + sum:shopist.checkouts.success{env:prod} by {region}.as_count()) > 0.5",
"message": "The error rate is currently {{value}} ! Be careful !",
"tags": [],
"options": {
"thresholds": {
"critical": 0.5
},
"notify_audit": false,
"require_full_window": false,
"notify_no_data": false,
"renotify_interval": 0,
"include_tags": true,
"new_group_delay": 60
}
}
{% /tab %}
복합 모니터 (Composite monitor)
마지막 모니터는 복합(Composite) 모니터로, 앞의 두 모니터가 모두 ALERT 상태일 때만 경보를 보내요.
{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_composite_monitor_config.26c19e3eac1ab52b2ecde72403599a6a.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_composite_monitor_config.26c19e3eac1ab52b2ecde72403599a6a.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Example composite monitor configuration showing boolean logic to alert if both monitors are in ALERT state" /%}