WSO2 API Cloud supports the following alert types.
Abnormal response time
|Reason for triggering||When there is a sudden increase in the response time of a specific API resource.|
|Indication||Slow WSO2 API Cloud runtime, or slow backend.|
|Description||This alert gets triggered when the response time of a particular API for which this alert type is configured is higher than the configured threshold value. These alerts can be an indication of a slow runtime or backend.|
Abnormal backend time
|Reason for triggering||If there is a sudden increase in the backend time corresponding to a particular API resource.|
|Description||This alert gets triggered when the backend time corresponding to a particular API for which this alert type is configured is higher than the configured threshold value. These alerts can be an indication of a slow backend.|
Abnormal request count
|Reason for triggering||If there is a sudden spike or a drop in the request count within a period of one minute by default for a particular API resource.|
|Indication||These alerts can be considered indications of high traffic, suspicious acts or the malfunction of client applications etc.|
|Description||This alert is triggered when there is a sudden spike in the request count within a period of one minute by default for a specified API of an application for which this alert type is configured. These alerts can be an indication of possible high traffic, suspicious activity etc.|
Abnormal resource access
|Reason for triggering||If there is a change in the resource access pattern of a user who uses a particular application.|
|Indication||These alerts can be considered as indications of suspicious activities done by one or more users in your application.|
A Markov Chain model is built for each application to learn its resource access pattern. For the purpose of learning the resource access patterns, no alerts are sent during the first 500 (default) requests. After learning the normal pattern of a specific application, WSO2 Analytics performs a real time check on a transition done by a specific user, and sends an alert if it is identified as an abnormal transition. For a transition to be considered valid, it has to occur within 60 minutes by default, and it should be by the same user.
The above diagram depicts an example where a Markov Chain model is created during the learning curve of the system. Two states are recorded against Application A and the arrows show the directions of the transitions. Each arrow carries a probability value that stands for the probability of a specific transition taking place. Assume that the following two consecutive events are received by the application from user email@example.com.
The above transition has happened from the
Unseen source IP access
|Reason for Triggering||If there is either a change in the request source IP for a specific API of an application, or if the request if from an IP used before 30 days (default).|
|Indication||These alerts can be considered as indications of suspicious activities carried out by a user over an API of an application.|
The first 500 requests are used only for learning purposes by default and therefore, no alerts are sent during that time. However, the learning would continue even after the first 500 requests. This means, even if you receive continuous requests from the newly detected
|Reason for Triggering|
This alert is triggered in the following scenarios.
|Indication||These alerts indicate that you need to subscribe to a higher tier.|
These alerts are triggered for the reasons specified in the tables below.
|Reason for Triggering|
The response time of an API is greater than the upper percentile value specified for the same (which is 95 by default). This should occur continuously for a specified number of times (5 times by default).
|Indication||The response time is too high.|
|Reason for Triggering||The request count of an API per minute is less than the lower percentile value specified for the same (which is 5 by default). This should occur 5 times (i.e. 5 minutes) continuously in order to trigger the error.|
|Indication||The request count per minute is normal, but the response count per minute is low.|
|Reason for Triggering||The response status code is greater than or equal to 500, but less than 600. This should occur continuously for a specified number of times ( 5 by default) in order to trigger an alert.|
|Indication||A server side error has occurred.|
For more information on how API status changes depending on health availability of APIs, see Viewing Availability of APIs.