# Different alarm settings for different web\_log conf

**URL:** <https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174>\
**Category:** Help\
**Tags:** agent, agent-health\
**Created:** [April 13, 2021, 11:07am UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174 "2021-04-13T11:07:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DeWaRs1206](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/dewars1206/32/697_2.png) [@DeWaRs1206](https://community.netdata.cloud/u/DeWaRs1206)\
**Post date:** [April 13, 2021, 11:07am UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/1 "2021-04-13T11:07:29Z")

</div>

## Environment

Ubuntu 18.04 / Apache server

## Problem/Question

Hello,  
I have the following problematic I’m trying to solve with Netdata.  
I have a load balancer performing health check every 30 sec to my server.  
I have isolated this data using the following web\_log configuration.

```auto
apache_log2:
  name: full_log
  path: "/var/log/apache2/access.log"

apache_log_lb:
  name: Log_lb
  path: "/var/log/apache2/access.log"
  filter:
    include: 10.[108|109|110|111].[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3} #Regex to match my LB IPs

```

The problem is that the alarm for web\_log needs at least 120 requests in the last minute, which is not the case for the Log\_lb.  
Is there a way to modify this value (120/min) for a specific web\_log config? Or maybe another way to monitor such connection ?

Thanks for your help on this 🙂

---

<div class="post-metadata">

**Author:** ![OdysLam](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/odyslam/32/98_2.png) [@OdysLam](https://community.netdata.cloud/u/OdysLam)\
**Post date:** [April 19, 2021, 2:52pm UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/2 "2021-04-19T14:52:04Z")

</div>

Hey @DeWaRs1206,

There are a couple of things to unpack here. Let me try to help you out, but before we delve into this, I just wanted to welcome you to our community 🙂

For starters, even though you are monitoring your apache server, we are not actually using the [apache collector](https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/apache), but the [web\_log collector.](https://learn.netdata.cloud/docs/agent/collectors/go.d.plugin/modules/weblog) They are 2 different collectors who can monitor apache in a different manner, the first by reading stats from apache directly, while the web\_log by reading the logs produced by apache.

> If you want to learn more about collectors, take a look at our FAQ about it: [What are collectors and how do they work?](https://community.netdata.cloud/t/what-are-collectors-and-how-do-they-work/1189)

Now, what we need is to edit the default alarms for the `web_log` collector and modify it to our liking.

To modify the health file, you will need to run `sudo ./edit-config health.d/web_log.conf`. The script is smart enough to see that you haven’t yet edited that health file, thus it will show you the default one and then it will save any changes you make.

> **[Alerts and notifications | Learn Netdata](https://learn.netdata.cloud/docs/alerting)**
>
> The Netdata Agent is a health watchdog for the health and performance of your systems, services, and applications. We've

Now, it’s time to dive into the syntax for alarms in Netdata. Although it may seem daunting at first, it is really simple and really powerful.

> **[Configure alerts | Learn Netdata](https://learn.netdata.cloud/docs/alerting/health-configuration-reference)**
>
> Netdata's health watchdog is highly configurable, with support for dynamic thresholds, hysteresis, alert templates, and

I am not sure what you want to modify exactly, so I can’t help you any further. If you tell me which alarm you want to modify exactly and how, we can work on the syntax together here 🙂

---

<div class="post-metadata">

**Author:** ![ilyam8](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/ilyam8/32/134_2.png) [@ilyam8](https://community.netdata.cloud/u/ilyam8)\
**Post date:** [April 19, 2021, 4:44pm UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/3 "2021-04-19T16:44:51Z")

</div>

Hi @DeWaRs1206

> web\_log needs at least 120 requests in the last minute, which is not the case for the Log\_lb  
> Is there a way to modify this value (120/min) for a specific web\_log config?

I understand what you mean. Unfortunately, it is not possible to achieve it currently.

There is the list of alarms filters:

- [os](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-os)
- [hosts](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-hosts)
- [plugin](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-plugin)
- [module](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-module)
- [families](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-families)
- [host labels](https://learn.netdata.cloud/docs/agent/health/reference#alarm-line-host-labels)

None of them allow you to filter on job name (`full_log`, `Log_lb`). The job name is part of the job charts ids (e.g: `web_log_full_log.CHART_NAME`). But still there is nothing that allows to filter using charts ids when using templates.

---

<div class="post-metadata">

**Author:** ![ilyam8](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/ilyam8/32/134_2.png) [@ilyam8](https://community.netdata.cloud/u/ilyam8)\
**Post date:** [April 29, 2021, 8:05am UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/4 "2021-04-29T08:05:29Z")

</div>

We added the `charts` option [[PR](https://github.com/netdata/netdata/pull/11054)] to the health templates.

> Restrict an alarm or template to only certain charts.

It allows having different alarms for different jobs.

The algorithm is:

- write an alarm (template) for the specific job
- using `charts` filter in this alarm: include only this job and exclude everything else
- using `charts` filter in the default alarm: exclude only this job and include everything else

For instance:

```YAML
# exclude 'apache_log_lb', include eveyrthing else
template: web_log_requests
      on: web_log.request_processing_time
  charts: !*apache_log_lb* *

---

# include 'apache_log_lb', exclude eveyrthing else
template: web_log_requests_apache_log_lb
      on: web_log.request_processing_time
  charts: *apache_log_lb* !*

```

---

<div class="post-metadata">

**Author:** ![DeWaRs1206](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/dewars1206/32/697_2.png) [@DeWaRs1206](https://community.netdata.cloud/u/DeWaRs1206)\
**Post date:** [April 29, 2021, 1:44pm UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/5 "2021-04-29T13:44:45Z")

</div>

Hello @ilyam8

Thanks a lot for the details, I will have a look asap.

---

<div class="post-metadata">

**Author:** ![ilyam8](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/ilyam8/32/134_2.png) [@ilyam8](https://community.netdata.cloud/u/ilyam8)\
**Post date:** [April 29, 2021, 1:55pm UTC](https://community.netdata.cloud/t/different-alarm-settings-for-different-web-log-conf/1174/6 "2021-04-29T13:55:50Z")

</div>

Keep in mind that the feature in the master branch, if you are using stable releases you need to wait for v1.31.0.
