Documentation · Monitoring

Alerts and event rules

Turn Warden's local system observations into durable, explainable firing and resolved events.

Rules

Administrators can create enabled rules for CPU percentage, memory percentage, disk percentage and one-minute load. Each rule defines an above/below operator, threshold, required breach duration and info, warning or critical severity.

Evaluation lifecycle

The server evaluates enabled rules in the background. A breach must remain true for the configured duration before an alert fires. Warden records the triggering value and time, keeps the current instance updated, and creates a resolved event when the metric returns to normal.

Acknowledgement

Users allowed to read monitoring data can acknowledge an active incident for their own account. Acknowledgement and resolution are separate: acknowledgement records that a person has seen the problem, while resolution is driven by the observed condition.

Scope

Local operational alerts.

Warden watches the machine it operates. It is not intended to become a fleet-scale time-series monitoring system; distributed monitoring can integrate with Warden later for host-level investigation and remediation.