Enable or disable anomaly alert settings

How to enable or disable anomaly alerts

Understanding alerts

In Site24x7, there are two different types of alerts in anomaly detection:
  1. Status change alert: Triggered when there is a change in the monitor status, such as Trouble, Critical, or Down.
  2. Anomaly alert: Triggered when irregular patterns are detected by our machine learning (ML) models in monitored data. 
Note
An anomaly alert is sent only when there is a Confirmed anomaly.
In Threshold Configurations, if you have configured your Threshold Type as Zia-based Threshold, Zia will change the status of a monitor based on the severity of the anomaly. 
For example, for the above configurations in a server monitor where the CPU utilization is typically around 35%, a sudden spike to 90% prompts Zia to evaluate the severity of the anomaly. 
  1. If the anomaly is classified as Info, then there is no status change. 
  2. If the anomaly is classified as Likely, then the status is changed to Trouble.
  3. If the anomaly is classified as Confirmed, then the status is changed to Critical.

Disabling anomaly alerts will stop the alert mails for anomaly detection. 

How to enable or disable anomaly alerts 

Enable or disable anomaly alerts to suit your monitoring needs by toggling Yes or No in the following path:‌  
Admin > Configuration Profile > Anomaly Settings > Yes/No.
Note
  1. Anomaly alert settings are enabled by default.
  1. When anomaly alerts are disabled, the users will no longer receive an anomaly alert. However, if there is a status change triggered by the anomaly alert, then they will continue to receive the alert notifications.

Tips to handle status change alerts

You can configure the Notification Profile settings to reduce alert noise and focus only on the most relevant alerts.
  1. Set specific alert statuses: Instead of triggering alerts for all anomalies, configure the When the status is field to Trouble or Critical. This helps you focus on significant issues and avoid minor fluctuations.
  2. Limit alerting to working hours: In the Alerting Period, click Add Business Hours to configure business hours and avoid alerts during off-hours unless necessary. This ensures alerts are sent only when your team is available to respond.
  3. Choose appropriate notification channels: Select targeted channels like Email or Mobile Push instead of SMS under the Notification Medium field for lower-priority alerts to reduce interruption.

    • Related Articles

    • Troubleshooting steps for No anomaly triggered

      Why are anomaly alerts not triggered? If you are not receiving anomaly alerts, it means that the model was not able to recognize a behavior as an anomaly. Site24x7's AI-powered Zia framework is the underlying mechanism of anomaly detection. The ML ...
    • What are the various transactional mails sent by Site24x7?

      Site24x7 sends transactional mails to convey important updates about the monitors you've added, including alerts, reports, and more. These emails help you track processes, receive real-time notifications related to the monitors, and stay updated from ...
    • Troubleshooting false positive alerts in monitoring

      Problem False positive alerts are being generated. Possible cause The monitoring system is down in some locations. The Website monitor might be configured for one location, such as Seattle, but may appear down when accessed from another location, ...
    • Steps taken by Site24x7 to prevent false alerts

      Site24x7 is committed to zero false alerts and we have numerous measures in place to make sure downtime alerts from Site24x7 are genuine. Site24x7 eliminates false alarms by applying the "False Alarm Protector". Threshold and Availability Profiles ...
    • Alert Suppression – achieve better false alerts protection through dependency configuration in monitor groups

      To help limit the number of alerts sent when critical devices fail, Site24x7 allows you to create dependency relationships between the critical device monitors and the monitors for resources that lay beyond these devices. A network outage usually ...