Skip to main content

ExplorationAlert

Resource ExplorationAlert in pulumi-logtail.
10 min read

Resource ExplorationAlert in pulumi-logtail.

Pulumi type: logtail:index/explorationAlert:ExplorationAlert.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
additionalConditionsExplorationAlertAdditionalCondition (input)[]noAdditional conditions that must all be met together with the main alert condition for the alert to fire (logical AND, evaluated per series on the same time bucket). Up to 4 additional conditions; 'threshold' and 'relative' types only.
aggregationIntervalnumbernoThe data aggregation interval in seconds.
alertTypestringyesThe type of alert: 'threshold', 'relative', or 'anomaly_rrcf'.
anomalySensitivitynumbernoAnomaly detection sensitivity 0-100 (only for 'anomaly_rrcf' type, lower = more sensitive).
anomalyTrainingRangeDaysnumbernoHow many days of history to train the anomaly detection on, 1-30 (only for 'anomaly_rrcf' type).
anomalyTriggerstringnoAnomaly trigger mode: 'any', 'higher', or 'lower' (only for 'anomaly_rrcf' type).
callbooleannoEnable phone call notifications.
checkPeriodnumbernoHow often to check the alert condition in seconds. Required for threshold and relative alerts; ignored for anomaly alerts, which derive their cadence from query_period.
confirmationPeriodnumbernoThe confirmation delay in seconds before triggering.
criticalAlertbooleannoMark as critical alert (bypasses quiet hours).
emailbooleannoEnable email notifications.
escalationTargetExplorationAlertEscalationTarget (input)noThe escalation target for this alert. Specify either team_id/team_name OR policy_id/policy_name.
explorationIdstringyesThe ID of the exploration this alert belongs to.
incidentCausestringnoIncident description template (supports {{variable}} interpolation).
incidentPerSeriesbooleannoCreate separate incidents per series.
metadata{ [key: string]: string }noCustom metadata key-value pairs included in incident notifications. Use a plain string for a single value; for multiple values use jsonencode([...]).
namestringnoThe name of this alert.
onMissingDatastringnoWhat to do when the monitored query returns no data: 'treat_as_zero', 'dont_fire', 'treat_as_previous', or 'start_incident'. Only for threshold and relative alerts.
operatorstringnoThe comparison operator. Required for threshold and relative alerts; not used for anomaly alerts. For threshold: 'equal', 'not_equal', 'higher_than', 'higher_than_or_equal', 'lower_than', 'lower_than_or_equal'. For relative: 'increases_by', 'decreases_by', 'changes_by'.
pausedbooleannoWhether the alert is paused.
pushbooleannoEnable push notifications.
queryPeriodnumbernoThe query evaluation window in seconds.
recoveryPeriodnumbernoThe duration in seconds that a condition must be resolved before an incident is recovered. A value of 0 recovers the alert immediately, a value of -1 means never automatically recover an incident.
seriesNamesstring[]noSpecific series to monitor. Conflicts with series_names_except; set to an empty list to alert on any series.
seriesNamesExceptsstring[]noMonitor all series except these. Conflicts with series_names; set to an empty list to alert on any series.
smsbooleannoEnable SMS notifications.
sourceModestringnoSource selection mode: 'source_variable', 'platforms_single_source', or 'platforms_all_sources'.
sourcePlatformsstring[]noPlatform filters (used when sourceMode is 'platforms_*').
sourceVariablestringnoSource reference (format: 'source:table_name'). If omitted, derived from the parent resource's source variable.
stringValuestringnoThe string threshold value (only for threshold alerts with 'equal' or 'not_equal' operators).
valuenumbernoThe numeric threshold value. Required for threshold and relative alerts.
variableValuesExplorationAlertVariableValue (input)[]noValues pinned for a dashboard or exploration variable when evaluating this alert.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
additionalConditionsExplorationAlertAdditionalCondition (output)[]noAdditional conditions that must all be met together with the main alert condition for the alert to fire (logical AND, evaluated per series on the same time bucket). Up to 4 additional conditions; 'threshold' and 'relative' types only.
aggregationIntervalnumbernoThe data aggregation interval in seconds.
alertTypestringnoThe type of alert: 'threshold', 'relative', or 'anomaly_rrcf'.
anomalySensitivitynumbernoAnomaly detection sensitivity 0-100 (only for 'anomaly_rrcf' type, lower = more sensitive).
anomalyTrainingRangeDaysnumbernoHow many days of history to train the anomaly detection on, 1-30 (only for 'anomaly_rrcf' type).
anomalyTriggerstringnoAnomaly trigger mode: 'any', 'higher', or 'lower' (only for 'anomaly_rrcf' type).
callbooleannoEnable phone call notifications.
checkPeriodnumbernoHow often to check the alert condition in seconds. Required for threshold and relative alerts; ignored for anomaly alerts, which derive their cadence from query_period.
confirmationPeriodnumbernoThe confirmation delay in seconds before triggering.
createdAtstringyesThe time when this alert was created.
criticalAlertbooleannoMark as critical alert (bypasses quiet hours).
emailbooleannoEnable email notifications.
escalationTargetExplorationAlertEscalationTarget (output)noThe escalation target for this alert. Specify either team_id/team_name OR policy_id/policy_name.
explorationIdstringnoThe ID of the exploration this alert belongs to.
incidentCausestringnoIncident description template (supports {{variable}} interpolation).
incidentPerSeriesbooleannoCreate separate incidents per series.
metadata{ [key: string]: string }noCustom metadata key-value pairs included in incident notifications. Use a plain string for a single value; for multiple values use jsonencode([...]).
namestringnoThe name of this alert.
onMissingDatastringnoWhat to do when the monitored query returns no data: 'treat_as_zero', 'dont_fire', 'treat_as_previous', or 'start_incident'. Only for threshold and relative alerts.
operatorstringnoThe comparison operator. Required for threshold and relative alerts; not used for anomaly alerts. For threshold: 'equal', 'not_equal', 'higher_than', 'higher_than_or_equal', 'lower_than', 'lower_than_or_equal'. For relative: 'increases_by', 'decreases_by', 'changes_by'.
pausedbooleannoWhether the alert is paused.
pausedReasonstringyesRead-only field explaining why the alert is paused (e.g., 'Manually paused', complexity issues, too many failures).
pushbooleannoEnable push notifications.
queryPeriodnumbernoThe query evaluation window in seconds.
recoveryPeriodnumbernoThe duration in seconds that a condition must be resolved before an incident is recovered. A value of 0 recovers the alert immediately, a value of -1 means never automatically recover an incident.
seriesNamesstring[]noSpecific series to monitor. Conflicts with series_names_except; set to an empty list to alert on any series.
seriesNamesExceptsstring[]noMonitor all series except these. Conflicts with series_names; set to an empty list to alert on any series.
smsbooleannoEnable SMS notifications.
sourceModestringnoSource selection mode: 'source_variable', 'platforms_single_source', or 'platforms_all_sources'.
sourcePlatformsstring[]noPlatform filters (used when sourceMode is 'platforms_*').
sourceVariablestringnoSource reference (format: 'source:table_name'). If omitted, derived from the parent resource's source variable.
stringValuestringnoThe string threshold value (only for threshold alerts with 'equal' or 'not_equal' operators).
updatedAtstringyesThe time when this alert was updated.
valuenumbernoThe numeric threshold value. Required for threshold and relative alerts.
variableValuesExplorationAlertVariableValue (output)[]noValues pinned for a dashboard or exploration variable when evaluating this alert.

ExplorationAlertAdditionalCondition (input)#

Input object ExplorationAlertAdditionalCondition. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
alertTypestringyesThe type of this condition: 'threshold' or 'relative'. Anomaly detection is only available as the main alert condition.
operatorstringyesThe comparison operator. For threshold: 'equal', 'not_equal', 'higher_than', 'higher_than_or_equal', 'lower_than', 'lower_than_or_equal'. For relative: 'increases_by', 'decreases_by', 'changes_by'.
seriesNamesstring[]noSpecific series this condition applies to. Conflicts with series_names_except; omit to apply to any series.
seriesNamesExceptsstring[]noApply this condition to all series except these. Conflicts with series_names; omit to apply to any series.
stringValuestringnoThe string threshold value of this condition (only with 'equal' or 'not_equal' operators). Set exactly one of value and string_value.
valuenumbernoThe numeric threshold value of this condition.

ExplorationAlertEscalationTarget (input)#

Input object ExplorationAlertEscalationTarget. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
policyIdnumbernoThe Better Stack escalation policy ID.
policyNamestringnoThe Better Stack escalation policy name.
teamIdnumbernoThe Better Stack team ID to escalate to.
teamNamestringnoThe Better Stack team name to escalate to.

ExplorationAlertVariableValue (input)#

Input object ExplorationAlertVariableValue. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
namestringyesThe name of an existing non-source dashboard or exploration variable.
selectedLabelstringnoThe selected label for a predefined SQL variable.
valuesstring[]noThe values to use when evaluating this alert.

ExplorationAlertAdditionalCondition (output)#

Output object ExplorationAlertAdditionalCondition. Fields below belong to this object.

PropertyTypeAlways presentDescription
alertTypestringyesThe type of this condition: 'threshold' or 'relative'. Anomaly detection is only available as the main alert condition.
operatorstringyesThe comparison operator. For threshold: 'equal', 'not_equal', 'higher_than', 'higher_than_or_equal', 'lower_than', 'lower_than_or_equal'. For relative: 'increases_by', 'decreases_by', 'changes_by'.
seriesNamesstring[]noSpecific series this condition applies to. Conflicts with series_names_except; omit to apply to any series.
seriesNamesExceptsstring[]noApply this condition to all series except these. Conflicts with series_names; omit to apply to any series.
stringValuestringnoThe string threshold value of this condition (only with 'equal' or 'not_equal' operators). Set exactly one of value and string_value.
valuenumbernoThe numeric threshold value of this condition.

ExplorationAlertEscalationTarget (output)#

Output object ExplorationAlertEscalationTarget. Fields below belong to this object.

PropertyTypeAlways presentDescription
policyIdnumbernoThe Better Stack escalation policy ID.
policyNamestringnoThe Better Stack escalation policy name.
teamIdnumbernoThe Better Stack team ID to escalate to.
teamNamestringnoThe Better Stack team name to escalate to.

ExplorationAlertVariableValue (output)#

Output object ExplorationAlertVariableValue. Fields below belong to this object.

PropertyTypeAlways presentDescription
namestringyesThe name of an existing non-source dashboard or exploration variable.
selectedLabelstringnoThe selected label for a predefined SQL variable.
valuesstring[]noThe values to use when evaluating this alert.