# LogsAlert

> Resource LogsAlert in pulumi-posthog.

<!-- Generated from the pulumi-posthog SDK. -->

Resource LogsAlert in pulumi-posthog.

Pulumi type: `posthog:index/logsAlert:LogsAlert`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as posthog from "pulumi-posthog"

const resource = new posthog.LogsAlert("logsAlert", {})
```

## Arguments

| Property            | Type                               | Required | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------- | ---------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `blockedWindows`    | `LogsAlertBlockedWindow (input)[]` | no       | Quiet hours: time windows during which the alert is not evaluated. Times use the project timezone. Windows must not overlap or touch each other. A window may cross midnight (for example `22:00` to `06:00`), but only as the sole window, because PostHog stores a crossing window as two windows when anything else is configured. PostHog enforces its own limits on window length and count, and reports them on apply. Omit the attribute, or set it to an empty list, to disable quiet hours.                                                                                                                                                                                                                                                   |
| `cooldownMinutes`   | `number`                           | no       | Minimum minutes between repeated notifications after the alert fires. Defaults to 0, meaning no cooldown.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `datapointsToAlarm` | `number`                           | no       | How many of the `evaluationPeriods` most recent check periods must breach the threshold before the alert fires. Must be between 1 and 10 and must not exceed `evaluationPeriods`. Defaults to 1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `enabled`           | `boolean`                          | no       | Whether the alert is actively evaluated. Defaults to true. Disabling resets the alert state to `notFiring`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `evaluationPeriods` | `number`                           | no       | How many of the most recent check periods to consider. PostHog checks a log alert every 5 minutes, so 3 periods covers the last 15 minutes. Must be between 1 and 10. Defaults to 1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `filterGroupJson`   | `string`                           | no       | Attribute-level filters as JSON, matching the `filters.filterGroup` object of the [logs alerts API](https://posthog.com/docs/api/logs). Use this for anything beyond severity and service, such as filtering on a log attribute. Must be a non-empty JSON object. Only the fields you declare are tracked: PostHog annotates saved filters with defaults (such as `label`) that would otherwise surface as permanent drift. The flip side is that a field you omit is not tracked either. If someone edits it in the PostHog UI Terraform will not detect the drift, so declare every field you care about. An imported alert adopts PostHog's stored filter group verbatim, so the first plan after an import may show one diff that clears on apply. |
| `name`              | `string`                           | no       | Human-readable name for the alert. PostHog defaults this to `Untitled alert` when omitted, so this attribute is computed: leaving it out adopts the server's default rather than producing a diff.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `projectId`         | `string`                           | no       | Project ID (environment) for this resource. Overrides the provider-level project_id.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `serviceNames`      | `string[]`                         | no       | Service names to scope the alert to.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `severityLevels`    | `string[]`                         | no       | Log severity levels to count: `trace`, `debug`, `info`, `warn`, `error`, or `fatal`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `snoozeUntil`       | `string`                           | no       | RFC 3339 timestamp until which the alert is silenced, for example `2026-01-31T09:00:00Z`. Useful for planned work when you want a window of silence in version control rather than in someone's memory. Managed only when you set it. Leave it out and Terraform never sends it, so a snooze an operator sets in the PostHog UI is left alone rather than being reverted on the next apply.                                                                                                                                                                                                                                                                                                                                                            |
| `thresholdCount`    | `number`                           | no       | Log entry count to compare against. The alert fires when the number of matching entries in the window is `above` (or `below`) this value. Defaults to 100. Use `0` with `above` to fire on any matching log.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `thresholdOperator` | `string`                           | no       | Whether the alert fires when the count is `above` or `below` the threshold. Defaults to `above`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `windowMinutes`     | `number`                           | no       | Time window in minutes over which log entries are counted: `5`, `10`, `15`, `30`, or `60`. Defaults to 5.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property            | Type                                | Computed | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------- | ----------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `blockedWindows`    | `LogsAlertBlockedWindow (output)[]` | no       | Quiet hours: time windows during which the alert is not evaluated. Times use the project timezone. Windows must not overlap or touch each other. A window may cross midnight (for example `22:00` to `06:00`), but only as the sole window, because PostHog stores a crossing window as two windows when anything else is configured. PostHog enforces its own limits on window length and count, and reports them on apply. Omit the attribute, or set it to an empty list, to disable quiet hours.                                                                                                                                                                                                                                                   |
| `cooldownMinutes`   | `number`                            | no       | Minimum minutes between repeated notifications after the alert fires. Defaults to 0, meaning no cooldown.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `datapointsToAlarm` | `number`                            | no       | How many of the `evaluationPeriods` most recent check periods must breach the threshold before the alert fires. Must be between 1 and 10 and must not exceed `evaluationPeriods`. Defaults to 1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `enabled`           | `boolean`                           | no       | Whether the alert is actively evaluated. Defaults to true. Disabling resets the alert state to `notFiring`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `evaluationPeriods` | `number`                            | no       | How many of the most recent check periods to consider. PostHog checks a log alert every 5 minutes, so 3 periods covers the last 15 minutes. Must be between 1 and 10. Defaults to 1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `filterGroupJson`   | `string`                            | no       | Attribute-level filters as JSON, matching the `filters.filterGroup` object of the [logs alerts API](https://posthog.com/docs/api/logs). Use this for anything beyond severity and service, such as filtering on a log attribute. Must be a non-empty JSON object. Only the fields you declare are tracked: PostHog annotates saved filters with defaults (such as `label`) that would otherwise surface as permanent drift. The flip side is that a field you omit is not tracked either. If someone edits it in the PostHog UI Terraform will not detect the drift, so declare every field you care about. An imported alert adopts PostHog's stored filter group verbatim, so the first plan after an import may show one diff that clears on apply. |
| `name`              | `string`                            | no       | Human-readable name for the alert. PostHog defaults this to `Untitled alert` when omitted, so this attribute is computed: leaving it out adopts the server's default rather than producing a diff.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `projectId`         | `string`                            | no       | Project ID (environment) for this resource. Overrides the provider-level project_id.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `serviceNames`      | `string[]`                          | no       | Service names to scope the alert to.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `severityLevels`    | `string[]`                          | no       | Log severity levels to count: `trace`, `debug`, `info`, `warn`, `error`, or `fatal`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `snoozeUntil`       | `string`                            | no       | RFC 3339 timestamp until which the alert is silenced, for example `2026-01-31T09:00:00Z`. Useful for planned work when you want a window of silence in version control rather than in someone's memory. Managed only when you set it. Leave it out and Terraform never sends it, so a snooze an operator sets in the PostHog UI is left alone rather than being reverted on the next apply.                                                                                                                                                                                                                                                                                                                                                            |
| `state`             | `string`                            | yes      | Current evaluation state of the alert, as PostHog reports it: `notFiring`, `firing`, `pendingResolve`, `errored`, `snoozed` or `broken`. A `broken` alert has stopped evaluating after repeated failed checks and notifies nobody; clearing that is a PostHog UI action, so the provider warns about it on refresh rather than managing it.                                                                                                                                                                                                                                                                                                                                                                                                            |
| `thresholdCount`    | `number`                            | no       | Log entry count to compare against. The alert fires when the number of matching entries in the window is `above` (or `below`) this value. Defaults to 100. Use `0` with `above` to fire on any matching log.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `thresholdOperator` | `string`                            | no       | Whether the alert fires when the count is `above` or `below` the threshold. Defaults to `above`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| `windowMinutes`     | `number`                            | no       | Time window in minutes over which log entries are counted: `5`, `10`, `15`, `30`, or `60`. Defaults to 5.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

## `LogsAlertBlockedWindow (input)`

Input object `LogsAlertBlockedWindow`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description                                                   |
| -------- | -------- | -------- | ------------------------------------------------------------- |
| `end`    | `string` | yes      | End time as `HH:MM` (24-hour, project timezone). Exclusive.   |
| `start`  | `string` | yes      | Start time as `HH:MM` (24-hour, project timezone). Inclusive. |

## `LogsAlertBlockedWindow (output)`

Output object `LogsAlertBlockedWindow`. Fields below belong to this object.

| Property | Type     | Always present | Description                                                   |
| -------- | -------- | -------------- | ------------------------------------------------------------- |
| `end`    | `string` | yes            | End time as `HH:MM` (24-hour, project timezone). Exclusive.   |
| `start`  | `string` | yes            | Start time as `HH:MM` (24-hour, project timezone). Inclusive. |
