Alerting

SRE Burn rate based alerts

quahfamili
Path Finder

Hi all,

I m exploring to increase the efficiency of my systems' alerts. Was reading up on the Google SRE implementation of burn rate based alert. It is supposed to reduce the overall downtime by not scheduling (if by time-based, it will increase the error budget due to the wait time before alerts are fired) alert based on time but with a predetermined rate.

I must declare that after reading the pages a few times, I still cannot grasp the idea of the burn rate. Maybe someone here can enlighten me.

I m interested to see how this burn rate based alert can be implemented in splunk to increase the detection time.

Thanks in advance.

Regards,
Alan

0 Karma

woodcock
Esteemed Legend

How can we possibly help if you don't even post the links to the SRE material?

0 Karma

quahfamili
Path Finder
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...