Comparison of observability alerting and O&M systems

Updated at:

The new alerting feature of Simple Log Service is an all-in-one platform for artificial intelligence for IT operations (AIOps). It combines alerting and monitoring, alert denoising, transaction management, and notification management in a single service. This topic compares the new alerting feature of Simple Log Service with common self-managed open source alerting systems.

Simple Log Service alerting

The new alerting feature of Simple Log Service is an AIOps service that monitors data of various types, such as logs and metrics, and receives alerts from third-party systems. In addition to alerting and monitoring, it provides alert denoising, transaction management, and notification management. It adds more than 40 feature scenarios and covers the alerting, monitoring, and O&M requirements of development, O&M, security, and operations teams. For more information, see What is Simple Log Service alerting?.

Architecture of the new alerting feature of Simple Log Service

The following figure shows the five main advantages of the new alerting feature of Simple Log Service.

Five main advantages of the new alerting feature of Simple Log Service

The following sections compare the new alerting feature of Simple Log Service with common self-managed open source alerting stacks. Each comparison uses the same categories: durability, cost, alerting and monitoring, alert management, and notification management. The Simple Log Service alerting column is identical in every comparison table, so you can read only the section for the stack that you are evaluating.

Comparison with ELK X-Pack alerting (Elasticsearch Watcher and Kibana 7.x+ Alert)

A self-managed ELK stack uses the open source combination of Elasticsearch, Logstash, and Kibana, which does not include an alerting feature. To configure alerting for a self-managed ELK stack, you must purchase the commercial X-Pack package. X-Pack provides two alerting features that are independent of each other and cannot interoperate: Elasticsearch Watcher and Kibana 7.x+ Alert.

CategoryItemSimple Log Service alertingELK X-Pack alerting
DurabilityAvailability of the alerting featureService availability of more than 99.9% and storage durability of more than 99.99999999%.The commercial edition is distributed. Data storage requires manual configuration.
CostFeesNo subscription fees. Fully managed. Monitoring and alert management are free of charge. Among notification channels, only text message and Voice Service notifications incur a small per-message fee.Subscription fees for the commercial edition, manual O&M costs, costs for self-purchased hardware, and third-party fees for text message and voice call notifications.
Alerting and monitoringScale of monitored logs and metricsPetabyte-scale.Terabyte-scale.
Alerting and monitoringQuery and analysis syntax for monitoringSupports SQL-92 syntax (including extensions), Prometheus Query Language (PromQL) syntax, and extended alerting syntax.
  • Elasticsearch Watcher: Supports ES DSL.

  • Kibana 7.x+ Alert: Supports limited filtering and aggregation operations.

Alerting and monitoringMachine learning capabilitiesSupports more than 10 AI algorithms, such as prediction, outlier detection, and root cause analysis.Supports X-Pack ML algorithms.
Alerting and monitoringData collaboration capabilitiesSupports collaborative monitoring across data stores, projects, regions, and accounts.Supports merged analysis of identically structured indexes within the same cluster.
Alerting and monitoringNo-data alertsSupported.Not supported.
Alerting and monitoringAlert recoverySupported.Not supported.
Alerting and monitoringTags and annotationsSupported.Kibana 7.x+ Alert supports custom tags.
Alerting and monitoringDynamic severitySupported.Not supported.
Alerting and monitoringEvaluation by groupSupported. You can customize the configuration.
  • Elasticsearch Watcher: Fixed, with no grouping.

  • Kibana 7.x+ Alert: Fixed, with automatic grouping.

Alerting and monitoringMonitoring-side control
  • Supports configuring a sustained threshold.

  • Supports pausing and automatically resuming monitoring based on time.

Elasticsearch Watcher supports pausing and resuming monitoring based on acknowledgments (ACKs).
Alert managementAlert denoising and transaction management
  • Supports alert deduplication, alert merging, suppression, and silence.

  • Supports transaction management and owner assignment.

Not supported.
Notification managementNotification capabilitiesSupports dynamic notification channel dispatch, alert escalation, recipient group management, notification channel calendar settings, on-call schedule settings, and notification channel quota control.Not supported.
Notification managementCommon channelsSupports notification channels such as text message, Voice Service, DingTalk, email, WebHook, and Alibaba Cloud Message Center. You can also integrate channels such as WeCom, Lark, and Slack through WebHook.

Supports notification channels such as email and WebHook. Does not support text message or voice call channels.

  • Watcher supports PagerDuty, JIRA, and Slack.

  • Kibana Alert supports IBM Resilient, MS Teams, and ServiceNow.

Comparison with Prometheus and Loki 2.0 alerting (including AlertManager)

A self-managed Prometheus and Loki system uses the open source combination of Prometheus, Loki, and AlertManager to build an alerting and monitoring system. Prometheus alerts on metrics, and Loki alerts on logs. Both send their alerts to AlertManager for centralized management.

CategoryItemSimple Log Service alertingPrometheus and Loki 2.0 alerting
DurabilityAvailability of the alerting featureService availability of more than 99.9% and storage durability of more than 99.99999999%.Some services are distributed, and others provide only single-node availability. Storage provides single-node availability.
CostFeesNo subscription fees. Fully managed. Monitoring and alert management are free of charge. Among notification channels, only text message and Voice Service notifications incur a small per-message fee.Manual O&M costs, costs for self-purchased hardware, and third-party fees for text message and voice call notifications.
Alerting and monitoringScale of monitored logs and metricsPetabyte-scale.
  • Logs: Hundreds of gigabytes.

  • Metrics: Terabyte-scale.

Alerting and monitoringQuery and analysis syntax for monitoringSupports SQL-92 syntax (including extensions), Prometheus Query Language (PromQL) syntax, and extended alerting syntax.
  • Logs: LogQL syntax.

  • Metrics: PromQL syntax.

Alerting and monitoringMachine learning capabilitiesSupports more than 10 AI algorithms, such as prediction, outlier detection, and root cause analysis.Not supported.
Alerting and monitoringData collaboration capabilitiesSupports collaborative monitoring across data stores, projects, regions, and accounts.Supports cross-metric PromQL joins within the same cluster.
Alerting and monitoringNo-data alertsSupported.Not supported.
Alerting and monitoringAlert recoverySupported.Supported.
Alerting and monitoringTags and annotationsSupported.Supported.
Alerting and monitoringDynamic severitySupported.Not supported.
Alerting and monitoringEvaluation by groupSupported. You can customize the configuration.Supports fixed grouping by label.
Alerting and monitoringMonitoring-side control
  • Supports configuring a sustained threshold.

  • Supports pausing and automatically resuming monitoring based on time.

Supports setting a sustained threshold. Does not support pausing or resuming monitoring.
Alert managementAlert denoising and transaction management
  • Supports alert deduplication, alert merging, suppression, and silence.

  • Supports transaction management and owner assignment.

Supports alert deduplication, alert merging, suppression, and silence. Does not support transaction management or owner management.
Notification managementNotification capabilitiesSupports dynamic notification channel dispatch, alert escalation, recipient group management, notification channel calendar settings, on-call schedule settings, and notification channel quota control.Only supports dynamic notification channel dispatch. Other capabilities are not supported.
Notification managementCommon channelsSupports notification channels such as text message, Voice Service, DingTalk, email, WebHook, and Alibaba Cloud Message Center. You can also integrate channels such as WeCom, Lark, and Slack through WebHook.Supports email, WeCom, WebHook (custom bodies not supported), PagerDuty, PushOver, Slack, OpsGenie, and VictorOps. Does not support text message or voice call channels. Third-party plug-ins can also add support for channels such as DingTalk, Lark, and Slack.

Comparison with InfluxDB 2.0 alerting (including Kapacitor)

A self-managed InfluxDB system uses the open source combination of InfluxDB OSS 2.0 and Kapacitor to build an alerting and monitoring system. If you require cluster deployment, you must also purchase the commercial InfluxDB Enterprise edition. This solution applies only to alerting and monitoring for metrics.

CategoryItemSimple Log Service alertingInfluxDB 2.0 alerting (including Kapacitor)
DurabilityAvailability of the alerting featureService availability of more than 99.9% and storage durability of more than 99.99999999%.The commercial edition is distributed and supports storage configuration. The open source edition runs on a single node.
CostFeesNo subscription fees. Fully managed. Monitoring and alert management are free of charge. Among notification channels, only text message and Voice Service notifications incur a small per-message fee.Subscription fees for the commercial edition, manual O&M costs, costs for self-purchased hardware, and third-party fees for text message and voice call notifications.
Alerting and monitoringScale of monitored logs and metricsPetabyte-scale.
  • Logs: Not supported.

  • Metrics: Terabyte-scale.

Alerting and monitoringQuery and analysis syntax for monitoringSupports SQL-92 syntax (including extensions), Prometheus Query Language (PromQL) syntax, and extended alerting syntax.Supports Flux syntax.
Alerting and monitoringMachine learning capabilitiesSupports more than 10 AI algorithms, such as prediction, outlier detection, and root cause analysis.Supports the Loud ML algorithm.
Alerting and monitoringData collaboration capabilitiesSupports collaborative monitoring across data stores, projects, regions, and accounts.Supports cross-bucket Flux joins within a single cluster.
Alerting and monitoringNo-data alertsSupported.Not supported.
Alerting and monitoringAlert recoverySupported.Not supported.
Alerting and monitoringTags and annotationsSupported.Supports simple tags.
Alerting and monitoringDynamic severitySupported.Supported.
Alerting and monitoringEvaluation by groupSupported. You can customize the configuration.Not supported.
Alerting and monitoringMonitoring-side control
  • Supports configuring a sustained threshold.

  • Supports pausing and automatically resuming monitoring based on time.

Not supported.
Alert managementAlert denoising and transaction management
  • Supports alert deduplication, alert merging, suppression, and silence.

  • Supports transaction management and owner assignment.

Only supports alert suppression. Other capabilities are not supported.
Notification managementNotification capabilitiesSupports dynamic notification channel dispatch, alert escalation, recipient group management, notification channel calendar settings, on-call schedule settings, and notification channel quota control.Only supports dynamic notification channel dispatch. Other capabilities are not supported.
Notification managementCommon channelsSupports notification channels such as text message, Voice Service, DingTalk, email, WebHook, and Alibaba Cloud Message Center. You can also integrate channels such as WeCom, Lark, and Slack through WebHook.Supports notification channels such as email, WebHook (flexible custom bodies not supported), exec, PagerDuty, PushOver, Slack, OpsGenie, VictorOps, and HipChat. Does not support text message or voice call channels.