In logging 5.7 and later versions, users can configure the LokiStack deployment to produce customized alerts and recorded metrics. If you want to use customized alerting and recording rules, you must enable the LokiStack ruler component.
LokiStack log-based alerts and recorded metrics are triggered by providing LogQL expressions to the ruler component. The Loki Operator manages a ruler that is optimized for the selected LokiStack size, which can be
To provide these expressions, you must create an
AlertingRule custom resource (CR) containing Prometheus-compatible alerting rules, or a
RecordingRule CR containing Prometheus-compatible recording rules.
Administrators can configure log-based alerts or recorded metrics for
infrastructure tenants. Users without administrator permissions can configure log-based alerts or recorded metrics for
application tenants of the applications that they have access to.
Application, audit, and infrastructure alerts are sent by default to the OKD monitoring stack Alertmanager in the
openshift-monitoring namespace, unless you have disabled the local Alertmanager instance. If the Alertmanager that is used to monitor user-defined projects in the
openshift-user-workload-monitoring namespace is enabled, application alerts are sent to the Alertmanager in this namespace by default.