Skip to content

rules_ignored conflates paused rules with broken ones, so it cannot be alerted on #13

Description

@PRIYAM232

Summary

rules_ignored counts deliberately paused rules and silently broken rules in the same number, so it cannot be used as an alert signal for "something is not being enforced".

Evidence

Observed in one session on the sandbox:

Action ruleset updated line
8 rules, one bad regex + one SAMPLE-on-LOGS rules_total: 8 … rules_ignored: 2
Paused throttle-noisy-tenants rules_total: 8 … rules_enforced_logs: 2, rules_ignored: 3
Resumed it back to rules_ignored: 2

A pause is intentional; a rule the collector could not compile is a defect. Both move the same counter, and neither the counter nor otelcol_pulse_filter_rules (which counts all rules, enforced or not) says which rules are affected.

Impact

An operator cannot write the alert they actually want: "a rule exists that is not being enforced."

Suggested fix

  • Separate the concepts: paused rules are not "ignored". Either exclude them from the count or report them separately (rules_paused).
  • Expose enforceability per rule rather than only as a fleet-wide count — e.g. a gauge labelled by rule name/id, so a dashboard can list dead rules.

Found during a real-developer UX test of deploy/sandbox on main (cc07d09), 2026-09-17: every rule created through the dashboard UI with the load generator running.

🤖 Filed with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions