본문 바로가기
WIKI 기술 지식 베이스

비정적 임계값 모니터링하기

원문 보기 위키 갱신

비정적 임계값 모니터링하기 (How to monitor non-static thresholds)

전형적인 메트릭 모니터는 단일 메트릭이 특정 임계값 숫자보다 높아지면 경보를 트리거해요. 예를 들어 디스크 사용량이 80%를 넘으면 경보가 트리거되도록 설정할 수 있어요. 이 접근 방식은 많은 사용 사례에 효율적이지만, 임계값이 절대 숫자가 아니라 변수라면 어떻게 될까요?

Watchdog 기반 모니터(즉 이상(anomaly) 및 아웃라이어(outlier))는 메트릭이 정상 궤도를 벗어났다는 명시적 정의가 없을 때 특히 유용해요. 하지만 가능하다면 특정 사용 사례에 맞춘 알림 조건을 가진 일반 모니터를 사용해 정밀도를 극대화하고 경보 발생까지의 시간을 최소화해야 해요.

이 가이드는 비정적(non-static) 임계값에 대한 경보의 일반적인 사용 사례를 다뤄요:

  • 계절적 변동(seasonal variations) 밖으로 벗어나는 메트릭에 대해 경보
  • 다른 참조(reference) 메트릭의 값을 기반으로 경보

출처: 문서

본문

계절적 임계값 (Seasonal threshold)

컨텍스트 (Context)

이커머스 웹사이트를 담당하는 팀 리드라고 가정해볼게요. 다음을 원해요:

  • 홈페이지의 예상치 못하게 낮은 트래픽에 대해 경보 받기
  • 공용 인터넷 제공업체에 영향을 주는 것 같은 더 지역화된 인시던트 포착하기
  • 알 수 없는 실패 시나리오 대비하기

웹사이트 트래픽은 밤과 낮, 평일과 주말에 따라 달라져요. "예상치 못하게 낮다"를 정량화할 절대 숫자는 없어요. 하지만 트래픽은 예측 가능한 패턴을 따르므로, 10% 차이를 공용 인터넷 제공업체에 영향을 주는 지역화된 인시던트 같은 문제의 신뢰할 수 있는 지표로 간주할 수 있어요.

{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_line_graph.eebfa1f0a92715a4cb5590cd2052bb54.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_line_graph.eebfa1f0a92715a4cb5590cd2052bb54.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Line graph of a periodic or seasonal metric" /%}

모니터 (Monitor)

팀은 nginx.requests.total_count 메트릭으로 NGINX 웹 서버의 연결 수를 측정해요.

요청(request) 은 3부분으로 구성돼요:

  1. 현재 요청 수를 가져오는 쿼리.
  2. 일주일 전 같은 시각의 요청 수를 가져오는 쿼리.
  3. 처음 두 쿼리 사이의 비율을 계산하는 "Formula" 쿼리.

그다음 시간 집계를 결정해요:

  • 시간 프레임을 선택해요. 시간 프레임이 클수록 이상을 감지하기 위해 평가하는 데이터가 많아져요. 시간 프레임이 크면 모니터 경보도 더 많아질 수 있으므로, 1시간으로 시작해 필요에 맞게 조정해요.
  • 집계를 선택해요. 비율을 수행하는 count 메트릭이므로 average(또는 sum)가 자연스러운 선택이에요.

아래 스크린샷에 표시된 임계값은 첫 번째 쿼리(현재)와 두 번째 쿼리(일주일 전) 값 사이의 10% 차이를 허용하도록 0.9로 구성되어 있어요.

{% tab title="UI Configuration" %}

{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_threshold_config.c0957bc274c84f82e2241f73c508f666.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/seasonal_threshold_config.c0957bc274c84f82e2241f73c508f666.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Configuration to add week_before timeshift to metric query and set formula a/b" /%}

{% /tab %}

{% tab title="JSON Example" %}

{
	"name": "[Seasonal threshold] Amount of connection",
	"type": "query alert",
	"query": "sum(last_10m):sum:nginx.requests.total_count{env:prod} by {datacenter} / week_before(sum:nginx.requests.total_count{env:prod} by {datacenter}) <= 0.9",
	"message": "The amount of connection is lower than yesterday by {{value}} !",
	"tags": [],
	"options": {
		"thresholds": {
			"critical": 0.9
		},
		"notify_audit": false,
		"require_full_window": false,
		"notify_no_data": false,
		"renotify_interval": 0,
		"include_tags": true,
		"new_group_delay": 60,
		"silenced": {}
	},
	"priority": null,
	"restricted_roles": null
}

{% /tab %}

참조 임계값 (Reference threshold)

컨텍스트 (Context)

QA 팀 리드로서 이커머스 웹사이트의 체크아웃 프로세스를 담당하고 있다고 해볼게요. 고객이 좋은 경험을 하고 문제 없이 제품을 구매할 수 있도록 보장하고 싶어요. 이를 나타내는 지표 중 하나가 오류율이에요.

트래픽은 하루 종일 동일하지 않아서, 금요일 저녁의 분당 50개 오류는 일요일 아침의 분당 50개 오류보다 덜 우려돼요. 오류 자체가 아니라 오류율을 모니터링하면 건강한 메트릭과 건강하지 않은 메트릭이 어떤 모습인지 신뢰할 수 있게 볼 수 있어요.

오류율이 높을 때뿐 아니라 힛(hit)의 양이 충분히 클 때도 경보를 받아요.

모니터 (Monitor)

총 3개의 모니터를 만들어요:

  1. 총 힛 수에 대해 경보하는 메트릭 모니터.
  2. 오류율을 계산하는 메트릭 모니터.
  3. 처음 두 모니터가 ALERT 상태면 경보를 트리거하는 복합(composite) 모니터.
총 힛 수에 대해 경보하는 메트릭 모니터 (Metric monitor to alert on the total number of hits)

첫 번째 모니터는 성공과 실패를 모두 포함한 총 힛 수를 추적해요. 이 모니터는 오류율이 경보를 트리거해야 하는지 결정해요.

{% tab title="UI Configuration" %}

{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_total_hits.55947f19b807662039b288eb84aee014.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_total_hits.55947f19b807662039b288eb84aee014.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Metric monitor configuration with formula to calculate total hits" /%}

{% /tab %}

{% tab title="JSON Example" %}

{
	"name": "Number of hits",
	"type": "query alert",
	"query": "sum(last_5m):sum:shopist.checkouts.failed{env:prod} by {region}.as_count() + sum:shopist.checkouts.success{env:prod} by {region}.as_count() > 4000",
	"message": "There has been more than 4000 hits for this region !",
	"tags": [],
	"options": {
		"thresholds": {
			"critical": 1000
		},
		"notify_audit": false,
		"require_full_window": false,
		"notify_no_data": false,
		"renotify_interval": 0,
		"include_tags": true,
		"new_group_delay": 60
	}
}

{% /tab %}

오류율을 계산하는 메트릭 모니터 (Metric monitor to calculate the error rate)

두 번째 모니터는 오류율을 계산해요. 오류율 a / a+b를 얻기 위해 오류 수를 총 힛 수로 나눈 쿼리를 만들어요:

{% tab title="UI Configuration" %}

{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_error_rate.5c0f5ca88cbc364b6446841751c99a58.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_error_rate.5c0f5ca88cbc364b6446841751c99a58.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Metric monitor configuration with formula to calculate error rate" /%}

{% /tab %}

{% tab title="JSON Example" %}

{
	"name": "Error Rate",
	"type": "query alert",
	"query": "sum(last_5m):sum:shopist.checkouts.failed{env:prod} by {region}.as_count() / (sum:shopist.checkouts.failed{env:prod} by {region}.as_count() + sum:shopist.checkouts.success{env:prod} by {region}.as_count()) > 0.5",
	"message": "The error rate is currently {{value}} ! Be careful !",
	"tags": [],
	"options": {
		"thresholds": {
			"critical": 0.5
		},
		"notify_audit": false,
		"require_full_window": false,
		"notify_no_data": false,
		"renotify_interval": 0,
		"include_tags": true,
		"new_group_delay": 60
	}
}

{% /tab %}

복합 모니터 (Composite monitor)

마지막 모니터는 복합(Composite) 모니터로, 앞의 두 모니터가 모두 ALERT 상태일 때만 경보를 보내요.

{% image source="https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_composite_monitor_config.26c19e3eac1ab52b2ecde72403599a6a.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/guide/non_static_thresholds/reference_composite_monitor_config.26c19e3eac1ab52b2ecde72403599a6a.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Example composite monitor configuration showing boolean logic to alert if both monitors are in ALERT state" /%}

더 알아보기 (Learn more)