Skip to main content

Metrics

Home > Select Project > Alert icon Alert > Event Configuration > Metrics tab

You can view the complete list of all metrics-based events configured for the project. You can review, edit, or delete existing metrics events, or add new events as needed.

Default Options

  • Event Level: Indicates the severity of an event and is classified into three levels: Normal (Info), Warning (Warning), and Critical (Critical).

  • Duplicate Agent Alert Suppression: If two or more agents with the same name run simultaneously, events are not triggered for the selected duration (30 seconds, 1 minute, 3 minutes, 5 minutes, 10 minutes).

  • Search: Search events by event name.

  • JSON Download/Upload: Edit event rules directly in the JSON editor, or download them as a file, modify them, and upload them again.

  • + Add Event: Add a new metrics event.

  • Resize Columns: Adjust column widths by dragging column borders.

Table | Metrics Event List Structure
ItemDescription
No.Event sequence number
Toggle off iconEvent activation status
– Enabled: An event is triggered when conditions are met
– Disabled: The event does not run and conditions are not evaluated
Edit iconEdit or delete event settings
Event NameUser-defined event name
– Up to 255 characters
RuleEvent trigger conditions
TargetMonitoring targets to which the event applies
Trigger CountThe time window and number of occurrences required to trigger an event
– An event is triggered when conditions are met the configured number of times within the selected duration
PauseTemporarily suppresses the same event after an alert is triggered
– Available durations: Disabled, 5 min, 10 min, 15 min, 20 min, 30 min, 1 hr, 2 hrs, 3 hrs, 6 hrs, 12 hrs, 1 day
– If recovery notifications are enabled, alerts are not triggered for the selected duration after a RECOVERED notification is sent
Recovery NotificationWhether to receive a RECOVERED (normal) notification when Critical or Warning events are resolved
– Enabled: Sends a RECOVERED notification when the status changes from in progress to normal and allows viewing active and resolved states in event history
– Disabled: Triggers a one-time event each time the threshold is exceeded
Event RecipientsUsers or groups that receive notifications for the event (recipient tags)

Event Configuration

Metrics events allow you to define events based on conditions that occur in monitored targets and configure notifications so you can respond efficiently.

Add Event

To add a metrics event, go to Event Configuration > Metrics tab, then click the [ + Add Event ] button in the upper-right corner.

How to Add a Metrics Event
Step 1. Select Template: Choose the basic structure of the event.
Step 2. Define Event Conditions: Configure the conditions that determine when the event is triggered.
Step 3. Select Event Target: Select the monitoring targets where the event applies.
Step 4. Basic Information and Notification Settings: Configure the event name, message, and recipients.

Select Template

  1. Depending on how you want to configure the event, select one of the three templates on the left side of the screen.

    • Create New: Freely configure categories and metrics from scratch. This option is suitable for advanced users who need complex conditions or fine-grained monitoring rules.

    • Quick Setup: Provides predefined categories, metrics, and default thresholds. You can apply it quickly by adjusting only the threshold values, which makes it suitable for beginners.

    • Advanced Setup: Add conditions or freely modify settings based on predefined categories and metrics.

Note

Metrics events support multiple configuration approaches. The available templates may vary depending on the monitoring platform.

Define Event Conditions

In the Define Event Conditions step, configure the metrics that determine when the event is triggered, along with the trigger count, pause settings, recovery notifications, and event active time.

Metric Settings
  1. Enter a category in the search field, or select a category (metric) from the category list.
    You must select a category to proceed with metric configuration.

    • The category list shows the category name, data collection interval, and key. It displays metrics data collected in the project within the last 3 hours.
  2. If the metric you need is not listed, select Direct Input and enter the category manually.

    Note

    If you are not sure about categories or metrics, use the Metrics Finder.

    When configuring metrics for the first time, the Metrics Finder helps you locate metrics more quickly.

    • Search for a metric in the Metrics Finder to view related categories and detailed information.

    • Click the [ Select ] button for a metric in the search results to automatically apply the selected value to the event configuration screen.

  3. Select the event level (Critical, Warning, Info). You can configure multiple levels for a single metric.

    Note

    Event Level Behavior

    Even when multiple conditions are satisfied, only the highest-priority level (CriticalWarningInfo) triggers an event. For details, see the Level Action Guide.

    • Event levels are classified as Critical (Critical), Warning (Warning), and Info (Info).

    • It is recommended to configure multiple levels for the same metric with stepwise thresholds.

  4. Enter the field, operator, and value for the selected event level.

    a. Click + Add to add more conditions.

    • &&: An event is triggered only when all conditions are satisfied simultaneously
    • ||: An event is triggered when at least one condition is satisfied

    b. Click to remove the condition.

    Note

    For condition syntax and supported operators, refer to the Condition Settings Guide.

Trigger Count

Configure how many times a condition must be met before an event is triggered. This is useful for detecting persistent issues only.

  1. Select the trigger frequency.

    • Consecutive: An event is triggered when the condition occurs consecutively for the configured number of times.

    • Recent: An event is triggered when the condition occurs the configured number of times within the selected time window.

      • Available durations: 5 seconds, 10 seconds, 15 seconds, 30 seconds, 1 minute, 2 minutes, 3 minutes, 4 minutes, 5 minutes, 10 minutes, 30 minutes, 1 hour
  2. Enter the trigger count.

    • The Interval value corresponds to the data collection interval of the selected category. (Interval: 10s)
Pause

To prevent excessive event generation, select a pause duration for event execution. After an event occurs, the same event will not be triggered again during the configured time period.

  • Available durations: Disabled, 5 minutes, 10 minutes, 15 minutes, 20 minutes, 30 minutes, 1 hour, 2 hours, 3 hours, 6 hours, 12 hours, 1 day
Note

When recovery notifications are enabled

Even if the same event condition is met again, no notification is sent until the configured time has passed since the RECOVERED notification was received.

Resolved Notification

When the resolved notification feature is enabled, you can track state changes after an event occurs (in progress → resolved). The event is shown as an ongoing event in the Event History menu.

  • Resolved notifications apply only to Critical and Warning levels. Info-level events always operate as one-time events.

  • When a Critical or Warning event is resolved, a notification with the RECOVERED (normal) state is sent.

  • Click the toggle button to enable or disable this feature.

    • Toggle on icon Enabled: Events operate based on state. They enter an in-progress state when the threshold is exceeded and transition to a resolved state when the value recovers below the threshold.

    • Toggle off icon Disabled: A one-time event is generated each time the threshold is exceeded.

Event Operation Time

Configure tags so that events operate only during specific time periods (such as business hours, non-business hours, or maintenance windows). If no tag is configured, events operate continuously for 24 hours while enabled.

  1. Click + Add.

  2. In Event Operation Time, click + Create New Tag.

  3. In Create Event Operation Time Tag, select the tag name, days, time, and color, then click the [ Apply ] button.

  4. You can view created tags in the tag list, and apply them by selecting the checkbox.

  5. To modify or delete a tag, click the Edit icon icon and update or delete it in Edit Event Operation Time Tag.

Caution

When a tag is deleted, it is removed from all users to whom it was applied. However, tags that are currently in use by event rules cannot be deleted.

Simulation

The simulation feature lets you pretest configured event conditions using historical data. If the expected number of events is too high or too low, you can adjust the conditions to find optimal threshold values.

  • Rule Validation: Verify how newly created event rules would behave when applied to historical data.
  • Threshold Tuning: Adjust thresholds to an appropriate level when events occur too frequently or not at all.

Start Simulation

  1. After completing event condition settings, click the [ Simulation ] button.
  2. Review the expected number of events and the visualized results.

Understanding Simulation Results

  1. Time-Series Data

    A graph displays metric changes over time along with threshold lines for each level, allowing you to intuitively identify when events are triggered.

  2. Event Counts by Level

    The number of events for the Critical, Warning, and Info levels is shown on the right side of the screen. This helps you understand overall event distribution and frequency.

  3. Target-Level Details

    Hover over a specific point on the chart to see the exact metric value and monitoring target at that moment. When multiple targets exist, they are distinguished by color. If patterns differ by target, you can use filtering to analyze them individually.

  4. Peak Interval Identification

    Identify periods where metrics spike sharply to understand when issues occur most frequently or to recognize recurring patterns.

Tip

Simulation Tips

  • Simulate Different Time Ranges

    Run simulations for weekdays vs. weekends and peak vs. off-peak hours to set optimal thresholds for each time period.

  • Include Actual Incident Periods

    Include past outage periods in simulations to verify whether current rules accurately detect real incidents.

  • Add Target Filtering

    When many targets are monitored, simulation results can become complex. Use filters to focus on specific targets for clearer insights.

  • Adjust Thresholds Gradually

    Instead of making large changes at once, adjust thresholds incrementally, such as in 10 percent steps, to find optimal values.

Select Event Target

If no event target is specified, events are triggered for all targets in the project, which can result in excessive events. It is therefore recommended to clearly define the targets to which the event applies.

Note

If you change the event targets, the number of events may change. Click the Simulation button and run it again to check the updated expected event count.

Target Selection

You can specify the targets to which the event applies using either Select Input or Direct Input.

  1. Select or enter a tag, operator, and value.
    a. If it is difficult to find a tag, you can search for it using the Metrics Finder.

  2. Click + Add to add event targets using conditions (&&, ||).

Basic Information and Notification Settings

Configure the event name, message, and recipients. Because this information is displayed as is in event history and actual notification messages, it should be clear and easy to identify.

Event Activation

Configure whether the event is triggered when the defined conditions are met.

  • Toggle on icon Enabled: The event is triggered when the configured conditions are satisfied.

  • Toggle off icon Disabled: Conditions are not evaluated.

Event Name

Enter the event name to be used as the event title. The configured event name is displayed in the Event List and Event History menus and can be used as a search keyword.

Message

Enter the event message. The message you enter is used in event history and notifications. Click the Time icon icon to view previously written message history. You can include variables in the message to insert actual values at the time the event occurs.

  • Variable Usage Rules

    • Variable format: ${metric_name}
    • Only metrics within the same category as the configured category can be used as variables.
    • You can combine multiple variables to create a more detailed message.
    • The list of available variables can be found in the Metrics Query menu.
  • Variable Usage Example

    Event ConfigurationWhen Event Occurs
    TitleDisk Usage IncreaseDisk Usage Increase
    MessageDisk = ${disk}%Disk = 89.9%
Event Recipients

Specify the members who will receive event notifications.

Notifications are sent to all targets (members and channels) in the project that have event reception enabled.

Edit/Delete Event

  1. Go to Alert Notifications > Event Settings and open the Metrics tab.

  2. In the event list, click the Edit icon icon for the event you want to edit or delete.

  3. In the Edit Event Rule window, update the options and click the [ Save ] button.

    a. To delete the selected event, click the [ Delete ] button in the upper-right corner of the Edit Event Rule window.

Event Sharing

You can save metric event settings as a JSON file to share configurations with other users or import settings created by others.

  • JSON file name: event-rules-YYYYMMDD.json

Export

  1. Click the [ JSON Export icon ] button at the top right of the screen.
  2. When the JSON editor opens, click the [ Export icon Export ] button.
    • If you use the export function after searching for events, only the searched list will be downloaded as a JSON file.
  3. After the JSON file is downloaded, share it with other users.

Import

  1. Click the [ Import icon ] button at the top right of the screen.
  2. Select the JSON file downloaded using the Export function.
  3. When the JSON editor opens, choose either [ Add to List ] or [ Overwrite ].
Caution

It is recommended to use this feature between projects of the same product type. You can import event settings from projects of different products, but they may not function correctly.

Edit in JSON Format

  1. Click the [ JSON Export icon ] button at the top right of the screen.

  2. When the editor opens, modify the content according to the JSON format.

  3. After completing the edits, click the [ Save ] button at the bottom of the screen.

Note

If the modified content does not conform to the JSON format, an error message will be displayed at the bottom of the screen and the content cannot be saved. The error message may vary depending on the type of formatting issue.

JSON error

JSON Data Structure
{
"version": 2,
"eventId": "zcef7s7f27rum1",
"enabled": true,
"stateful": false,
"title": "Active Transaction",
"message": "Active Transaction = ${active_tx_count}",
"category": "app_counter",
"alertLabel": [
"oid"
],
"repeatCount": 1,
"repeatDuration": 0,
"silent": 300000,
"receiver": [],
"timeTag": [],
"selectString": "",
"conditions": [
{
"level": 20,
"enabled": true,
"rule": "active_tx_count > 100"
}
],
"createTime": 1763632674345,
"lastModifiedTime": 1763632674347,
"lastModifiedUser": "support@whatap.io",
"basic": true,
"metaId": "java004",
"selectCondition": {
"oid": [
"-1010758404",
"-250906941"
]
}
}
Table | JSON Data Structure
JSON FieldTypeDescriptionNotes
versionIntegerVersion of the event ruleRestricted
eventIdStringUnique identifier of the event rule
enabledbooleanWhether the event is enabled
statefulbooleanWhether the event is state-based
titleStringEvent rule name defined by the user
messageStringEvent rule message defined by the user
categoryStringData category
alertLabelList<String>Default identifier (primary key) value assigned per category for event state managementRestricted
repeatCountIntegerNumber of repetitions
repeatDurationLongDuration for repetition
silentIntegerPause duration
receiverList<String>List of recipient tag keys
timeTagList<String>List of operation-time tag keys
selectStringStringTarget selection
conditionsList<Object>List of trigger conditions by level
ㄴ levelbyteLevel valueCritical: 30, Warning: 20, Info: 10
ㄴ enabledbooleanWhether the level is enabled
ㄴ ruleStringTrigger condition for the level
createTimeLongInitial creation time of the event rule
lastModifiedTimeLongLast modification time of the event rule
lastModifiedUserStringAccount that last modified the event rule
basicbooleanWhether the event was created using Quick SetupRestricted
metaIdStringUnique identifier of the Quick Setup templateRestricted: This value exists only for events created via Quick Setup (basic=true).
selectConditionObjectTarget selection value for Quick SetupThis value exists only for events created via Quick Setup (basic=true).
Caution

Fields marked as “Restricted” may affect event behavior, so it is recommended not to modify their values.


Appendix

Trigger Conditions and Target Selection Guide

Metric alert trigger conditions and event target selection use the same syntax. However, trigger conditions use the field key as the variable, while target selection uses the tag key as the variable.

Level Behavior Guide

Event levels are categorized into Critical, Warning, and Info.

  1. Priority-based Event Triggering

    When multiple level conditions are met at the same time, only the event with the highest priority is triggered.

    Example
    Configuration:
    - Warning: CPU > 70%
    - Critical: CPU > 90%

    Current state: CPU 95%
    → Result: Only the Critical event is triggered (Warning is suppressed)
  2. Level Escalation

    For events that maintain an in-progress state, when a higher-level condition is met while a lower-level event is already in progress, both levels enter the in-progress state.

    Example
    Configuration:
    - Warning: CPU > 70%
    - Critical: CPU > 90%

    Scenario:
    1) CPU 80% → Warning triggered (in progress)
    2) CPU 95% → Warning (in progress), Critical (in progress)
  3. Level De-escalation

    For events with an in-progress state, when the level transitions from a higher level to a lower level, the higher-level event is resolved while the lower-level event remains active.

    Example
    Configuration:
    - Warning: CPU > 70%
    - Critical: CPU > 90%

    Scenario:
    1) CPU 97% → Critical triggered
    2) CPU 85% → Critical resolved, Warning remains
    3) CPU 65% → Warning resolved
  4. Execution Flow

    - Warning: CPU > 70%
    - Critical: CPU > 90%

    Metric value: 60% → 75% → 92% → 85% → 60%
    State: Info Warning Critical Warning Info
    (triggered) (triggered) (maintained) (resolved)
    Warning
    (maintained)
Note

Events that have an in-progress state remain active as long as their conditions are met and continue until those conditions are cleared.

Condition Configuration Guide

Caution

If a metric name starts with a number or contains special characters, you must wrap it in the ${metric_name} format.

  • Brackets ( ), [ ]
  • Operators +, -, *, /, %
  • Delimiters :, @, #, ,, (space)
  • Other special characters !, ^, &, |, ~, ```, =

Examples using ${}:

${cpu(xos)} > 50
${mem[0]} >= 100
${cpu-usage} > 80
${namespace:cpu} > 70
${metric name} > 60
${4xx_error} > 10

Usable without ${}: Metric names that contain only alphabetic characters, underscores (_), or dots (.)

cpu > 80
cpu_usage > 50
CPUUtilization.Average > 0.8
  1. Comparison Operators

    Numeric Comparison
        Greater than:            cpu > 80
    Greater than or equal: cpu >= 80
    Less than: memory < 1000
    Less than or equal: memory <= 1000
    Equal to: status == 200
    Not equal to: error != 0
    String Comparison
        status == 'OK'
    region == "us-east-1"
  2. Arithmetic Operators

    • Basic arithmetic operations

      Addition:        cpu + 10 >= 90
      Subtraction: memory - 100 >= 500
      Multiplication: cpu * 2 >= 100
      Division: disk / 1024 >= 100
      Modulo: value % 10 == 0
    • Controlling precedence with parentheses

      (cpu + memory) * 2 >= 200
      (disk - used) / total >= 0.2
      ((cpu + memory) / 2) >= 50
    • Negative values

      cpu > -100
  3. Logical Operators

    • AND operator (&&)

      cpu > 80 && memory > 1000
      ${cpu(xos)} > 50 && ${mem(xos)} > 60
    • OR operator (||)

      cpu > 90 || memory > 90
      disk < 10 || network > 1000
    • Combined logical operations

      (cpu > 50 && memory > 50) || disk < 20
      cpu > 80 && (memory > 1000 || disk > 500)
  4. Pattern Matching Operators

    • LIKE operator

      oname like 'prod-*'
      url like '*error*'
      message like 'WARN%'
    • NOT LIKE operator

      oname not like 'test-*'
      url not like '*debug*'
  5. Built-in Functions

    • Null check functions

      isNull(value)             # Checks whether the value is null
      isNotNull(value) # Checks whether the value is not null
      nvl(value, 0) # Returns a default value if null
      isEmpty(str) # Checks whether the string is empty
      isNotEmpty(str) # Checks whether the string is not empty
    • Aggregate functions

      sum(cpu, memory, disk)              # Sum
      avg(cpu, memory) # Average
      max(cpu, memory, disk) # Maximum
      min(cpu, memory, disk) # Minimum
      count(value1, value2, value3) # Count
    • Math functions

      round(cpu, 2)             # Rounds to 2 decimal places
    • String functions

      length(str)                # String length
      startsWith(str, 'prefix') # Checks prefix
      endsWith(str, 'suffix') # Checks suffix
      indexOf(str, 'search') # String index
      substring(str, 0, 10) # Substring
      trim(str) # Trims whitespace
      replace(str, 'old', 'new') # String replacement
      hasStr(str, 'search') # Checks string containment
    • Conditional functions

      • if: A conditional function that returns the trueValue if the condition evaluates to true, or the falseValue if it evaluates to false
      Syntax
      if(condition, trueValue, falseValue)
      Example
      if(value >= 90, 'High', 'Medium') == 'High'
      • decode: Compares a value against conditions and returns the result of the matching condition, or a default value if no match is found
      Syntax
      decode(value, condition1, result1, condition2, result2, ..., conditionN, resultN, defaultValue)
      Example
      decode(value, 1, 'Low', 2, 'Medium', 3, 'High', 'Unknown') == 'Unknown'
      • in: Returns true if the value matches any of the specified candidates; otherwise returns false
      Syntax
      in(value, candidate1, candidate2, ..., candidateN)
      Example
      in(status, 200, 201, 204) == false
    Caution

    Writing Guidelines

    • Recommended

      • Use simple variable names without ${} (e.g. cpu, memory)
      • Always use ${} when special characters are included
      • Use parentheses to clearly separate complex expressions
      • Enter function names exactly as defined (case-sensitive)
    • Avoid

      • Incomplete expressions (e.g. cpu >, memory &&)
      • Mismatched parentheses (e.g. (cpu > 80 && cpu > 70))
      • Consecutive or invalid operators (e.g. cpu >> 80, cpu >< 80)