Section 2 · Name and query

How an operator and a threshold define when an alert moves from normal toward firing.

Estimated time: 1 min

Alert condition

The alert condition defines when an alert moves toward firing. A threshold is the value the condition compares against.

The condition watches a value over time. If the value stays at or below the threshold, the alert stays normal. When it rises above the threshold and stays there through the pending period you configure later, the alert fires.

For this journey’s QuickPizza server-errors example, the value is how many new 5xx responses arrived in the last five minutes. Alert when that count is above 0 so any server errors in the window can trigger the rule. The alert condition has two parts:

  • Is above is the operator.
  • 0 is the threshold.
Line chart of QuickPizza 5xx responses over five-minute windows, near zero when healthy and spiking when errors appear, with a dashed threshold line at 0; the alert is normal at zero and moves toward firing while the value is above it

Important: verify after setting

Always click Preview alert rule condition to verify which instances would fire. If you change the operator from Is above to Is below, double-check that the threshold value still makes sense.