Manual Configuration of Alerts

To configure alerts manually, refer to the Grafana documentation for setting up alerts.

Use this checklist when creating the same alerts manually from the Grafana Web UI instead of provisioning the YAML file.

  • Create or select the SD-WAN folder and the SD-WAN evaluation group.

    Use a 1-minute evaluation interval unless the customer requires a different interval.

  • For each alert rule, select the Prometheus data source that receives Skyline SD-WAN metrics.

  • Paste the PromQL query from the alert package into query A.

    Keep Instant enabled for rules that evaluate the current state.

  • Add expression C as a Threshold expression that evaluates query A.

    Use the same threshold value from the YAML rule.

  • Add labels Importance and Severity with the values mentioned in the alert below.

    These labels are used by the dashboard alert counters and by notification routing.

  • Add the same summary, description, and runbook URL from the YAML.

  • Select an existing contact point or notification policy receiver.

  • Link the rule to the dashboard and panel only after the dashboards are imported in the target environment and the dashboard UID and panel ID are known.

Configuration in Grafana Web UI

  1. Open the Grafana Web UI.

  2. Navigate to Alerts > Alerts Rules.

  3. In the top right corner, click New alert rule.

  4. In Step 1, enter the alert name.

  5. Select your data source.

  6. Configure the alert query and expression.

  7. In Step 4, create a folder or assign the alert to an existing folder.

  8. In Step 5, either select an existing or create new evaluation Group which defines the sample rate for all your alerts in the group.

    Configure the applicable pending mode.

  9. Give the alert a summary and attach it to your dashboard widgets if needed.

Example Configuration Queries for Alerts

Query for alert - Security Gateway is "Down"

Query for alert - ISP "Down"

Query for alert - Link QOE is low

Query for alert - VPN tunnel is "Down" while ISP link is "UP"

Query for alert - All public ISPs exceeded thresholds of one steering object

Query for alert - All public ISPs exceeded thresholds for multiple steering objects

Query for alert - ISP exceeded threshold on one steering object

Query for alert - ISP exceeded thresholds for multiple steering objects

Query for alert - ISP state changes frequently

Query for alert - Overlay VPN tunnel is down (ISP down)

Query for alert - All Overlay VPN tunnels to a peer are down

Query for alert - Overlay VPN tunnel state changes frequently

Query for alert - High CPU utilization

Query for alert - High memory utilization

Query for alert - WAN link exceeded thresholds for more than 10% of time

Query for alert - WAN link was down for more than 10% of time

Query for alert - All overlay tunnels to multiple peers are down.

Query for alert - WAN link is frequently breaching and recovering from steering threshold