I’ve been testing a conversion of legacy alerts to Unified Alerting, but I’m getting an error when trying to continue using a cloudwatch error. The error looks like this:
Failed to evaluate queries and expressions: failed to execute conditions: input data must be a wide series but got type not (input refid)
Looking up this error message lead me to this Github post, in which a dev said:
in your example, your first query is making use of the
stats
command (therefore returns numeric data) while the second (i’m assuming) is returning raw log entries, on which Grafana cannot do alerting.
In legacy alerts, I was able to create an alert on these raw cloudwatch log queries by simply counting the number of responses. Is something like this no longer possible under unified alerts?
My query looks like this:
fields @timestamp, @log, 1, msg, @message, error
| filter @message like 'example specific error here'
| sort @timestamp desc
| limit 200