fix(alerts): explain raw-SQL sample counts and warn when they count rows - #1205
Conversation
A raw-SQL rule without a `samples` column counts every returned row as one sample, so a minimum sample count gates on buckets rather than events. The column was only mentioned in one MCP parameter description. - Document `value`, `group`, `samples` and the no-rows behavior in the alert SQL editor and on the MCP create/update parameters. - Warn in the editor and in create/update/get_alert_rule output when a raw-SQL rule sets a minimum above 1 without selecting `samples`. - Note in the warehouse catalog that service_overview_spans has no SpanKind.
Maple review🟢 Confidence 5/5 · safe to merge Adds documentation and an advisory warning for raw-SQL alert rules whose minimum sample count counts returned rows. Evaluation is untouched and the wiring type-checks; safe to merge.
Findings🔵 Note · F1 ·
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (10)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughRaw-query alert rules now produce configuration warnings when their minimum sample count exceeds one and their SQL does not select a ChangesRaw alert sample-count warnings
Warehouse span catalog note
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant create_alert_rule
participant ruleConfigWarnings
participant rawAlertSampleCountWarning
create_alert_rule->>ruleConfigWarnings: Check rule configuration
ruleConfigWarnings->>rawAlertSampleCountWarning: Check raw query SQL and minimum sample count
rawAlertSampleCountWarning-->>ruleConfigWarnings: Warning or null
ruleConfigWarnings-->>create_alert_rule: Configuration warnings
create_alert_rule-->>create_alert_rule: Include warnings in output and rendered notices
Suggested reviewers: Merge Risk: 🔵 Low · up to The advisory warning can be missed for nested queries or CTEs. Alert evaluation remains unchanged, so this is mergeable with awareness of the warning's limitation. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The changes are advisory: they do not alter alert evaluation, grant additional permissions, or change how rules are saved. The public output change is additive. Warning detection is heuristic, however, and should not be treated as confirmation that a query returns event counts. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Match only a column aliased exactly `samples` (bare, backticked or double quoted); the engine reads that key case-sensitively, so `Samples` or a column merely named t.samples no longer suppresses the warning. Correct the create_alert_rule defaults to what normalizeRule applies.
Maple review🟢 Confidence 5/5 · safe to merge Documents what
Fixed since the last review
What was checked
|
Stack 1/5. Customer feedback from an agent building alert rules: a raw-SQL rule's
minimum_sample_countcounts returned rows (one per bucket), not events.The engine already reads an optional
samplescolumn (each row counts as 1 without it), but only one MCP parameter description mentioned it.create_alert_rule/update_alert_ruleparameters documentvalue,group,samplesand what a query returning no rows means.rawAlertSampleCountWarning(domainraw-sql) flags a raw-SQL rule with a minimum above 1 and nosamplescolumn. It shows in the editor and as a notice on create/update/get_alert_rule output (warningson the create/update outputs).service_overview_spanshas noSpanKind(PR 5 replaces this).No behavior change to evaluation.
Test:
raw-sql.test.ts,alert-tools.test.ts.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
samplesvalue. In that case, each returned row counts as one sample; selecting asamplesvalue lets the query provide the sample count.