Pick an SLO and how fast you're burning error budget. See how long the budget lasts, which standard multi-window burn-rate alerts would fire and when, and get Prometheus alert rules to match.
Burn rate × allowed error rate = actual error rate. At 99.9%, the allowed error rate is 0.1%, so a 14.4× burn means 1.44% of requests failing.
Multi-window, multi-burn-rate alerts, the pattern from Google's SRE Workbook. Each alert needs both a long window (so it's sure) and a short window (so it clears quickly once you've fixed things) above its threshold.
| Alert | Threshold | Windows | At this burn | Budget used when it fires |
|---|
Assumes an http_requests_total counter with a code label. Swap in your own SLI.