[Watcher] Conditional Criteria and Actions Through a Watcher UI #18463
Labels
Feature:Watcher
release_note:enhancement
Team:Kibana Management
Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more
Original comment by @alexfrancoeur:
After speaking to a number of users at Elastic{ON} I noticed that there was a common request to create more conditional alerts. The features I list below are common across products like APM. I imagine our APM team will eventually need a UI to create and edit such watches.
Users would like to define a single watch through a UI that allow for conditional criteria and multiple actions like this:
If
[field1]
isgreater than
thresholdX
and[field2]
isless than
thresholdY
over the last15 minutes
mark aswarning
and `send email to EMAIL REDACTEDIf
[field]
isgreater than
thresholdY
and[field2]
isless than
thresholdY
over the last60 minutes
mark assevere
andsend slack to #opschannel
Ideally, this would not be limited to thresholds but also the ability to conditionally check if a value is in (or not in) a specific document. IE, if
X
number of documents contain404
as a response code, send warning alert.cc: @skearns64 @makwarth
The text was updated successfully, but these errors were encountered: