Large-scale observability deployments typically present a difficult choice: monitor comprehensively and face exponential costs, or restrict monitoring scope and accept coverage gaps. This hands-on session targets SREs and platform engineers wrestling with runaway alert rules, alert fatigue from false positives, and fragmented notification systems. The focus centers on two OpenSearch capabilities—PPL (Piped Processing Language) and the Unified Alert Manager—designed to resolve these operational challenges. All functionality operates under Apache 2.0 licensing with no tiered features, no licensing discussions required, and no cost thresholds that make alerting uneconomical.

Charles Humble, host at The New Stack, and Joshua Bright, an OpenSearch project maintainer at Amazon, will guide participants through both technical architecture and real-world operational procedures. The session includes live demonstrations and an open question-and-answer period for attendees to address their specific alerting concerns.

Key Topics Covered

  • Constructing multi-step alert conditions using PPL's pipeline approach—and identifying when cross-signal analysis detects failure patterns that simple threshold-based rules cannot
  • Setting up the Unified Alert Manager for consolidated rule administration, alert distribution, and alert suppression—and evaluating how this operational shift affects on-call team responsibilities
  • Creating alert conditions that correlate logs, metrics, and traces within a single query, eliminating the need to integrate multiple separate platforms
  • Lowering false positive rates while preserving signal quality—using proven techniques to identify where suppression strategies deliver the most impact
  • Running OpenSearch alerting without cost constraints: understanding how the absence of feature restrictions applies to data ingestion volume and alert rule scaling

Source: The New Stack