Skip to content

[AO] Use a same format for threshold and value in APM Latency alert document #156255

Description

@maryam-saeidi

📝 Summary

RFC Document

Currently, for the APM Latency threshold rule, the information for evaluation threshold and value are in 2 different formats. In this ticket, we need to see if there is a way to improve this situation and remove the extra code related to handling this case.

Here is an example of saved data in the alert document:

image

Challenge

  • If we change this value in the alert document, then some documents have the new format and others the old one, which makes the data that we show in UI not consistent. We need to check if there is a way to use a consistent format for both fields safely.

Ideas

  • Adding kibana.alert.evaluation.threshold.us field and maybe deprecating kibana.alert.evaluation.threshold
  • Add a new revision
  • Introduce the unit within the field in an object format
  • Change the field value to microsecond and accept the fact that this value will not be correct for the previously recovered alerts

✅ Acceptance Criteria

  • Threshold and value in the alert document should have the same unit for the APM Latency threshold

Activity

  1. elasticmachine commented on May 1, 2023

    @elasticmachine
    Contributor

    Pinging @elastic/actionable-observability (Team: Actionable Observability)

  2. CoenWarmer commented on May 3, 2023

    @CoenWarmer
    Contributor

    Will be discussed in the next Team Time (May 8th), and there we will come to a decision.

  3. added 4 commits that reference this issue on Jun 1, 2023
    d13f884
    57eb2e1
    7bbc871
    cd27f98
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions