Change Alert 모니터
Change Alert 모니터 (Change Alert Monitor)
메트릭 모니터는 가장 흔하게 사용되는 모니터 유형 중 하나예요. 이 가이드는 change alert 탐지 방식의 동작과 추가 옵션을 명확히 설명해요. change alert 모니터가 어떻게 동작하는지, 그리고 change alert 평가를 어떻게 문제 해결하는지 배워 보세요.
출처: 문서
본문
change alert 모니터란? (What are change alert monitors?)
change(변화) 탐지 방식을 사용하는 모니터가 동작하는 방식을 정리하면 다음과 같아요:
- 모니터가 현재 시점의 데이터 포인트 쿼리를 가져와요.
- N분, N시간, 또는 N일 전의 데이터 포인트 쿼리를 가져와요.
- 그런 다음 (1)과 (2) 사이 값의 차이에 대한 쿼리를 가져와요.
- (3)의 쿼리에 집계(aggregation)를 적용해 단일 값을 반환해요.
- Set alert conditions에서 정의한 임계값을 (4)에서 반환된 단일 값과 비교해요.
모니터 생성 (Monitor creation)
Datadog에서 Change Alert 모니터를 만들려면 기본 내비게이션 Monitors > New Monitor > Change를 사용해요.
평가 조건 (Evaluation conditions)
change alert 모니터에서 구성해야 하는 다양한 옵션은 다음과 같아요.
{% image source="https://docs.dd-static.net/images/monitors/monitor_types/change-alert/configure_define_the_metrics.fbfea4a43d7bca9b43b065710bc7e656.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/monitor_types/change-alert/configure_define_the_metrics.fbfea4a43d7bca9b43b065710bc7e656.png?auto=format&fit=max&w=850&dpr=2 2x" alt="Configuration options for change alert detection method" /%}
예시는 다음 경보 조건을 보여줘요: 1시간에 걸친 변화의 평균을 5분과 비교
| 선택된 옵션 (Options selected) | 설명 (Description) | 옵션 (Options) |
|---|---|---|
| average | 쿼리에 사용되는 집계. | Average, Maximum, Minimum, Sum |
| change | 값의 절대 변화 또는 백분율 변화 중에서 선택. | change 또는 % change |
| 1 hour | 평가 창. 자세한 내용은 모니터 구성 (Monitor Configuration) 문서를 참고하세요. | N분, N시간, N일, N주, 또는 최대 1개월일 수 있어요. |
| 5 minutes | 쿼리를 이동(shift)하려는 시간대. | N분, N시간, N일, N주, 또는 최대 1개월 전일 수 있어요. |
Change와 Change % (Change and change %)
change alert 탐지를 구성할 때 두 가지 옵션(Change와 % Change)이 있어요.
이 옵션은 다음 테이블의 formula 섹션에 표현된 것처럼 모니터가 평가하는 방식을 결정해요:
| 옵션 (Option) | 설명 (Description) | 공식 (Formula) |
|---|---|---|
| Change | 값의 절대 변화. | a - b |
| % Change | 이전 값과 비교한 값의 백분율 변화. | ((a - b) / b) * 100 |
두 경우 모두 Change와 % Change는 양수 또는 음수가 될 수 있어요.
알림 (Notifications)
Configure notifications and automations 섹션에 대한 지침은 알림 (Notifications) 및 모니터 구성 (Monitor configuration) 페이지를 참고하세요.
change alert 평가 문제 해결 (Troubleshooting a change alert evaluation)
change alert 평가의 결과를 확인하려면 Notebook으로 메트릭 쿼리를 재구성해요. 다음 설정의 이 change alert 모니터를 살펴보세요.
{% image source="https://docs.dd-static.net/images/monitors/monitor_types/change-alert/example_monitor_config.6fecec3093eb98edadb8a5d18dab81d4.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/monitor_types/change-alert/example_monitor_config.6fecec3093eb98edadb8a5d18dab81d4.png?auto=format&fit=max&w=850&dpr=2 2x" alt="The create monitor page with a change alert selected, evaluating the percent change of the average of the metric system.load.1 over the last 5 minutes compared to the last 30 minutes" /%}
모니터 쿼리: pct_change(avg(last_5m),last_30m):<METRIC> > -50
이는 다음 조건과 함께 쿼리를 나눈 것이에요:
- avg 집계.
- % change 사용.
- 5분 평가 창.
- 30분 또는 1800초의 타임시프트(timeshift).
- > -50 임계값.
쿼리 재구성 (Reconstructing the query)
- notebook과 타임시프트 함수 (timeshift function)를 사용해 특정 평가에서 모니터가 사용하는 데이터를 재구성해요.
- 현재 시점의 데이터 포인트 쿼리(이것이 일반 쿼리예요).
- N분 전의 데이터 포인트 쿼리(이것은 일반 쿼리 + timeshift(-1800)예요).
- 타임시프트 함수는 데이터를 뒤로 이동시키기 때문에 음수 기간을 사용해요. 이 쿼리들을 테이블의 % change 공식과 함께 결합해요.
- 참고: 이 예시는 메트릭이 하나뿐이므로 단일 쿼리(a)를 사용하고 공식
((a - timeshift(a, -1800)) / timeshift(a, -1800)) * 100을 추가하는 것도 가능해요 {% image source="https://docs.dd-static.net/images/monitors/monitor_types/change-alert/notebook_query_reconstruct_timeshift.566e1cab2c9866e494cf016b826150a7.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/monitors/monitor_types/change-alert/notebook_query_reconstruct_timeshift.566e1cab2c9866e494cf016b826150a7.png?auto=format&fit=max&w=850&dpr=2 2x" alt="The edit screen of a cell in a notebook, titled Reconstruct Change Alert query, configured as a timeseries using the average of the metric system.load.1, from everywhere, with the formula ((a - timeshift(a, -1800)) / timeshift(a, -1800)) * 100 being applied" /%}
- 모니터의 히스토리 그래프를 notebook 그래프와 비교해요. 값들이 비교 가능한가요?
- 집계를 적용해요.
- notebook 그래프를 change alert 모니터 평가와 비교하려면 시간대를 change alert과 일치하도록 범위를 지정해요.
- 예를 들어 1:30에 지난 5분 동안의 모니터 평가 값을 확인하려면 notebook을 1:25 - 1:30으로 범위를 지정해요.
참고: 메트릭이 gauge이고 pct_change()가 비정상적으로 큰 음수 값을 생성한다면 쿼리에 as_count()를 추가해요. 자세한 내용은 모니터 평가에서의 as_count() (as_count() in Monitor Evaluations)을 참고하세요.