APM metric condition and NRQL condition notification duplication in New Relic alert policies
0 reputation · 20 Jan 2020, 22:24 UTC
0 reputation · 20 Jan 2020, 22:24 UTC
Goal: Configure a New Relic alert policy that includes both an APM metric condition and an NRQL condition so that a single underlying issue generates one actionable notification instead of multiple noisy alerts. The policy can attach notification channels at the condition level or share a common set at the policy level, and New Relic offers violation closure, minimum duration, and aggregation settings to suppress transient spikes. However, it is unclear whether the platform treats a violation that satisfies both conditions as separate events that each trigger their own notification, or whether it aggregates them into a single notification when the channels are shared. This ambiguity affects teams trying to balance signal fidelity with noise reduction when using mixed condition types.
27025 reputation · 21 Jan 2020, 05:19 UTC
New Relic evaluates each alert condition independently. If both an APM metric condition and an NRQL condition breach their thresholds during the same evaluation window, the alert engine creates two separate violation events. Notification channels are attached to the policy (or optionally to individual conditions), and each violation event causes a notification to be sent to every attached channel. The “violation timeout” and “open violation” settings suppress repeat notifications **per condition**, not across conditions.
When both conditions fire for the same underlying issue, you receive two notifications because the platform treats them as distinct rules, even if they share the same notification channel. Enabling “Notify on policy” or configuring a shared aggregation window does not change this behavior; those options only affect where the channel is attached or how violations are aggregated within a single condition.
Are notification channels currently attached directly to the APM metric condition, the NRQL condition, or both? Knowing this determines whether removing per‑condition channel attachments will resolve the duplication.
Use comments to ask for clarification. Post a solution as an answer.
2,390 reputation · 21 Jan 2020, 03:06 UTC
A critical distinction to consider here is the Incident Preference setting within the alert policy. New Relic treats each condition as an independent evaluator; if an APM metric condition and an NRQL condition both cross their respective thresholds, the platform generates two distinct violations.
To verify this in your environment, check the Incident ID in the New Relic UI during a failure state. If you see two different IDs for the same event, the policy is operating on a "Per Condition" basis. Transitioning to "Per Time Window" is generally the most reliable way to consolidate these notifications without removing the granular telemetry provided by having both condition types.