Naming anomaly signals so humans can act
An alert named stream_anomaly_47 teaches no one. During Anomaly Signal Tuning Sessions we spend surprising amounts of time on names, because names decide whether a person opens the right runbook at 2 a.m.
Put the event type first
Lead with the business object: order_confirm_lag_high, inventory_delta_drop_suspected. People search for the noun they already use in Slack. Cryptic metric IDs belong in the details, not the title.
Say what failed, not how clever the detector is
“Z-score excursion on topic X” may be accurate and still useless. Prefer “Consumer applied count fell more than 15% versus producer count for 10 minutes.” The second version tells the responder where to look.
Attach one owner group
If two teams share an alert, it becomes nobody’s problem. Name the owning rotation in the signal description. Streaming application analytics only helps when a human accepts the page.
Good names will not fix a broken path, but they shorten the minutes between detection and the first useful action — which is often the entire point of anomaly work.