repeated alerts

%3CLINGO-SUB%20id%3D%22lingo-sub-633017%22%20slang%3D%22en-US%22%3Erepeated%20alerts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-633017%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Guys%2C%20Using%20below%20query%20I%20have%20enabled%20the%20alert%20for%20Processor%20Utilization%20with%20threshold%20of%2080%25%20targeting%20multiple%20windows%20servers%20on%20my%20workspace%20in%20Azure%20monitoring%20log%20space%20analytics.%20Perf%20%7C%20where%20ObjectName%20%3D%3D%20%22Processor%22%20and%20CounterName%20%3D%3D%20%22%25%20Processor%20Time%22%20%7C%20summarize%20AggregatedValue%20%3D%20avg(CounterValue)%20by%20bin(TimeGenerated%2C%205m)%2C%20Computer%20%7C%20where%20AggregatedValue%20%26gt%3B%2080%20Now%20the%20problem%20is%20I%20am%20getting%20multiple%20repeated%20alerts%20for%20the%20same%20severs%20for%20every%205%20minutes%20as%20the%20query%20frequency%20is%20set%20for%205%20minutes.%20Can%20Some%20one%20please%20guide%20me%20to%20stop%20this%20behavior%20so%20that%20it%20should%20trigger%20new%20alerts%20only%20when%20the%20new%20server%20breaches%20the%20threshold%20of%2080%25.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-633017%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Log%20Analytics%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-662793%22%20slang%3D%22en-US%22%3ERe%3A%20repeated%20alerts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-662793%22%20slang%3D%22en-US%22%3E%3CP%3EI%20would%20suggest%20using%20dynamic%20alerts%20to%20help%20cut%20down%20on%20the%20noise.%20It%20may%20take%20a%20few%20alerts%20to%20tune%20it%20to%20exactly%20what%20you%20want%20but%20worth%20the%20effort.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Falerts-dynamic-thresholds%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fazure-monitor%2Fplatform%2Falerts-dynamic-thresholds%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F338025%22%20target%3D%22_blank%22%3E%40roopesh_shetty%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi Guys, Using below query I have enabled the alert for Processor Utilization with threshold of 80% targeting multiple windows servers on my workspace in Azure monitoring log space analytics. Perf | where ObjectName == "Processor" and CounterName == "% Processor Time" | summarize AggregatedValue = avg(CounterValue) by bin(TimeGenerated, 5m), Computer | where AggregatedValue > 80 Now the problem is I am getting multiple repeated alerts for the same severs for every 5 minutes as the query frequency is set for 5 minutes. Can Some one please guide me to stop this behavior so that it should trigger new alerts only when the new server breaches the threshold of 80%.

1 Reply

I would suggest using dynamic alerts to help cut down on the noise. It may take a few alerts to tune it to exactly what you want but worth the effort.

 

https://docs.microsoft.com/en-us/azure/azure-monitor/platform/alerts-dynamic-thresholds

 

@roopesh_shetty