Skip to content
fernet.consultores

Splunk Observability Cloud

SignalFlow & Detectors.

SignalFlow detectors that alert on what matters, with an owner, a procedure and configuration as code.

The problem we solve.

Detectors copied from a template alert too much or too late. When every alert arrives with no context and no owner, the team learns to ignore them.

What’s included.

  • Detector design per service and SLO
  • Custom SignalFlow programs
  • Static, sudden-change and historical conditions
  • Muting rules and notification routing
  • Detectors managed as code

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review what's monitored today, with which tools, which incidents went unnoticed and what it costs.

We design the collection layer with OpenTelemetry: agents, gateways, egress paths, common attributes and sampling.

We write the detectors in SignalFlow, define muting rules and notification routes and manage them as code.

We test each detector with historical data and simulated failures to tune sensitivity and noise.

We tune cardinality, sampling and detectors based on real usage to contain cost and noise.

Technical capabilities.

  • SignalFlow
  • Detectors and alert conditions
  • Muting rules
  • Notification integrations
  • Splunk Observability Cloud Terraform provider
  • Splunk Observability Cloud API

Use cases.

Noisy alerts

Reduce alerts without losing the important ones.

SLOs

Alert on error-budget consumption.

Governance

Review and deploy detectors like any other code.

Benefits for your organisation.

  • Fewer, more useful alerts
  • Alerts with an owner and a procedure
  • Reviewable, versioned detectors
  • Consistency across teams

Deliverables.

  • Configured detectors
  • Documented SignalFlow programs
  • Detectors-as-code repository
  • Alert catalogue

Frequently asked questions.

What is SignalFlow?

Splunk Observability Cloud's analytics language for processing metrics in real time; it's used in charts and detectors.

Can you manage detectors with Terraform?

Yes, with the Terraform provider, so they're reviewed and deployed as code.

How do you decide what deserves an alert?

If nobody has to act on receiving it, it shouldn't be an alert. We work through this service by service.

Shall we talk about SignalFlow & Detectors?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service