All Products
Search
Document Center

OpenSearch:Alert rule groups

Last Updated:Feb 27, 2024

You can configure alert rules, alert metrics , and threshold values for Retrieval Engine Edition instances in an easy and quick manner. The system can send alert notifications by phone calls or text messages.

Default alert rules provided by Retrieval Engine Edition

Retrieval Engine Edition provides default alert rules, including multiple common alert rules. This way, you can create alert rules in an easy and quick manner.

The alert rules are created for all clusters. The alert rules include the general query duration in Havenask, the memory usage of QRS workers, the CPU utilization of QRS workers, the memory usage of Searcher workers, the CPU utilization of Searcher workers, and the disk usage of Searcher workers. You only need to add alert contacts and alert notification methods and enable the default alert rules.

Alert rules

Item

Alert metric

Alert threshold

Notification interval

CPU utilization of Searcher workers

opensearch.ha3suez.searcher.proc_cpu

WARNING:>60

CRITICAL:>80

5 minutes

General query duration in Havenask

opensearch.ha3suez.qrs.basic.qrssessionlatencynormal

WARNING:>400

CRITICAL:>800

5 minutes

Disk usage of Searcher workers

opensearch.ha3suez.searcher.disk_use_ratio

WARNING:>80

CRITICAL:>90

5 minutes

CPU utilization of QRS workers

opensearch.ha3suez.qrs.proc_cpu

WARNING:>60

CRITICAL:>80

5 minutes

Memory usage of Searcher workers

opensearch.ha3suez.searcher.proc_mem_used_ratio

WARNING:>80

CRITICAL:>90

5 minutes

Memory usage of QRS workers

opensearch.ha3suez.qrs.proc_mem_used_ratio

WARNING:>80

CRITICAL:>90

5 minutes

Note

For more information about metrics, see Metrics.

Procedure

1. On the Alert Rule Groups page, click Create Default Alert Rules. In the message that appears, click OK.

image

2. Find the created default alert rule and click Alert Rules in the Actions column.

image

3. On the Alert Rules page, click Modify Alert Rule.

image

4. On the Modify Alert Rule page, you can modify Clusters (instance IDs), Metrics, Alert Threshold, Notification Interval, and Alert Contacts. If no contact is available, you must create a contact first, and select a Notification Method (Text Message or Phone). Then, click Modify.

image

5. After you modify the alert rule, click Enable and then click OK.

image

Customize an alert rule group

Create an alert rule group

1. Log on to the OpenSearch Retrieval Engine Edition console and choose Alert Management > Alert Rule Groups in the left-side navigation pane. On the page that appears, click Create Alert Rule Group.

image

2. In the Create Alert Rule Group dialog box, specify the Alert Rule Group Name parameter and fill in the Description field. Click Complete. You can also click Create Alert Rule. For more information about subsequent steps, see Create an alert rule.

image

Create an alert rule

1. On the Alert Rule Groups page, click Create Alert Rule.

image

2. On the Create Alert Rule dialog box, you can specify the Alert Rule Name parameter, modify Clusters (instance IDs), Metrics, Alert Threshold, Notification Interval, and Alert Contacts. If no contact is available, you must create a contact first, and select a Notification Method (Text Message or Phone). Then, click Create.

image

View alert rules

1. On the Alert Rule Groups page, find the alert group that you want to manage and click Alert Rules in the Actions column. On the page that appears, you can view the alert rules of the alert group. You can create, modify, copy, delete, and disable alert rules. You can also specify a scheduled point in time to disable an alert rule. After you configure the required parameters for the operation that you want to perform, click OK.

image

Delete an alert rule group

1. On the Alert Rule Groups page, find the group that you want to delete and click Delete. In the message that prompts you to confirm the delete operation, click OK. (Note: When you delete an alert rule group, all alert rules in the alert rule group are also deleted. Exercise caution when you perform this operation.)

image