practice

Multi-Window Multi-Burn-Rate Alerting

Alerting on how fast an error budget is being consumed, over two time windows simultaneously, to get both fast detection and few false alarms.

sloalertingreliability

A static error rate threshold forces an unpleasant choice. Set it sensitively and it fires on brief harmless blips. Set it conservatively and a sustained partial failure runs for hours before crossing it.

Burn rate reframes the question as: at the current error rate, how quickly is the month's budget being consumed? A burn rate of 1 exhausts the budget exactly at the period's end. A burn rate of 14.4 exhausts it in about two days, which is worth waking someone for.

The multi-window part is what removes the false alarms. Each alert requires the burn rate to be high over both a long window, which establishes that the problem is sustained, and a short window, which confirms it is still happening — so an alert does not fire on a two-minute spike, and it stops firing promptly once the problem is resolved rather than staying latched for an hour.

A typical configuration uses a fast-burn alert that pages — high burn rate over one hour and five minutes — and a slow-burn alert that raises a ticket for a low-grade problem eroding the budget over days without ever looking dramatic.

The prerequisite is an SLO that reflects something users care about. Burn-rate alerting on a badly chosen indicator produces very precise alerts about the wrong thing, which is worse than a threshold because it carries more authority.