CertSafari
    Databricks Certified Data Analyst Associate· Lessons

    Domain 6 · Lesson 29/39

    Databricks SQL Alerts: Thresholds and Notification Destinations

    Configure an alert with a desired threshold and destination.

    16 min read
    2.56% of exam
    6 sources
    Published 3 Oct 2026
    Docs as of 30 Sep 2026

    What you will be able to do

    • Describe what each part of the Databricks SQL alert editor does and what the OK, TRIGGERED and ERROR statuses mean
    • Set an alert condition: the value to check (first value or an aggregation), the operator, and a static or column threshold
    • Explain how an aggregation rewrites the alert query, and how to alert on a condition that spans several columns
    • Send notifications to users or to admin-configured destinations (Email, Slack, Webhook, Microsoft Teams, PagerDuty) and control how often they repeat
    • Schedule an alert, test it, and read its evaluation history

    Key concept

    Databricks SQL alert — An alert has its own query, which runs on a schedule. Each run, the alert compares a value from the result against a threshold you set. When the condition is met, the alert's status becomes TRIGGERED and the chosen users or destinations get a notification.

    1.What an alert is made of

    An alert answers one question on a timer: is a number from this query outside the range I expect? To create one, click Alerts in the sidebar, then Create Alert. The editor has a fixed set of parts, and each one handles a separate job:

    - Query editor: where you write and test the SQL the alert checks. - Compute: the SQL warehouse that runs the alert query. - Schedule: how often the alert runs. - Share: permissions for other people in the workspace. - Condition: the threshold that triggers a notification. - Notifications: which users or notification destinations hear about it, and optionally how often to repeat. - Advanced: special cases such as empty results and custom message templates.

    This lesson focuses on Condition (the threshold) and Notifications (the destination), because that is what the objective asks for. The other parts set the context they run in.

    The alert query also has a limit: alerts do not support queries with parameters. If you are used to parameterized dashboard queries, hard-code the values into the alert's SQL.

    Each evaluation ends in one of three statuses: OK, TRIGGERED or ERROR. The UNKNOWN status from legacy alerts no longer exists. TRIGGERED means that on the most recent run, the value met the condition and threshold you set. OK means the most recent run did *not* meet it. The docs' example is an alert that checks whether "cats" is above 1500. It stays TRIGGERED as long as cats is above 1500 and shows OK once cats drops to 1470. OK describes the latest run only. It does not mean the alert never fired. ERROR means something went wrong while the alert was being evaluated.

    Checkpoint 1 of 9· Check yourself

    An alert checks whether a value is above 1500. Yesterday it was TRIGGERED. Today the value is 1470 and the listing page shows OK. What does OK tell you?

    Sources123

    2.Setting the threshold: value, operator, comparison

    The Condition section is where you define what "out of range" means. It has three settings:

    1. The value to check. This is either the *first value* of a column in the query result, or an *aggregation across all rows* of one column, such as SUM or AVERAGE. You also choose which column. 2. The logical operator, for example > (greater than). 3. The threshold. Static value is the default, and you type a number into the value field. The threshold can also be another column instead of a literal.

    In the docs' tutorial, the query returns one row per day of NYC taxi fares with a column amount. The condition is set to Sum of amount > static value 4000. Then you click Test condition to see whether the alert would trigger on the current data. You can change the threshold and test again before saving.

    Threshold options as shown in the alert's declarative (bundle) definition
    KeyMeaning
    double_valueNumeric literal threshold, e.g. 1.25
    string_valueString literal threshold, e.g. test
    bool_valueBoolean literal threshold, e.g. true
    columnUse a column reference as the threshold instead of a literal
    aggregationAggregation applied to the source column: SUM, COUNT, COUNT_DISTINCT, AVG, MEDIAN, MIN, MAX, STDDEV
    The same pieces as configuration: a comparison operator, a source column, a literal threshold, the query, a schedule and a warehouseyaml
          evaluation:
            comparison_operator: EQUAL
            source:
              name: '1'
            threshold:
              value:
                double_value: 2
          query_text: select 2
          schedule:
            quartz_cron_schedule: '44 19 */1 * * ?'
            timezone_id: Europe/Amsterdam
          warehouse_id: 799f096837fzzzz4

    Here is why. An aggregation on an alert doesn't summarize the rows after the fact. The alert rewrites the SQL: it wraps your original query text in a common table expression (CTE) and runs an aggregation query over it. So the result the alert evaluates, and passes to templates, is a single aggregated value. The pre-aggregation rows are gone.

    Checkpoint 2 of 9· Fill the gap

    The alert's column is column_name and its aggregation is set to Sum, on a query with text SELECT 1 AS column_name. Complete the SQL the alert actually runs.

    WITH q AS (SELECT 1 AS column_name) SELECT  ? (column_name) FROM q

    A condition checks one column. When the real rule depends on several columns, for example *drafts above 10,000 and archived above 5,000*, put that logic in the query and return a flag. Then set the alert to trigger when the value is 1.

    Multi-column logic folded into a single 1/0 value for the alert to checksql
    SELECT CASE WHEN drafts_count > 10000 AND archived_count > 5000 THEN 1 ELSE 0 END
    FROM (
    SELECT sum(CASE WHEN is_archived THEN 1 ELSE 0 END) AS archived_count,
    sum(CASE WHEN is_draft THEN 1 ELSE 0 END) AS drafts_count
    FROM queries) data

    Checkpoint 3 of 9· Exam question

    A BI team wants a Databricks SQL alert to fire whenever the total daily revenue reported by a query drops below $50,000, and the underlying query returns one row per store with a `revenue` column across many stores. Which condition configuration correctly triggers the alert based on the overall daily total rather than any single store's value?

    Sources245

    3.Choosing where the notification goes

    The threshold decides *when* an alert fires. The Notifications section decides *who hears about it*. There you search for and add either users or notification destinations. In the tutorial, you search for your own username, and the notification arrives by email.

    Email to users is the default. To send anywhere else, an admin has to configure a notification destination first. Only a workspace admin can manage destinations, and once one is configured, every user can select it. The admin path is: username in the top bar → Settings → under *Workspace admin*, the Notifications tab → Manage → +Add destination. Then choose a type, configure it and click Create.

    Supported destination types and what each one stores
    Destination typeWhat the admin provides
    EmailEmail addresses
    Slack (webhook)The URL to which the notification is sent
    Microsoft Teams (webhook)The URL to which the notification is sent
    PagerDutyIntegration key that routes notifications to a PagerDuty service
    WebhookUsername and password for HTTP Basic authentication, or client ID and secret for OAuth (Beta)

    Databricks stores destination configurations encrypted. It recommends separate credentials for each destination, so you can revoke one without affecting the others. Webhook-based endpoints must use HTTPS with SSL certificates signed by a trusted certificate authority. They must also allowlist the workspace's control plane and data plane outbound IP addresses. Slack and Microsoft Teams can also be reached through the Databricks Genie app, which supports SQL alerts on both platforms. That option is in Beta and an admin has to turn it on.

    Checkpoint 4 of 9· Match them up

    Match each destination type to the secret its configuration stores

    Tap a term, then the definition that fits it.

    How often notifications go out. You can optionally set a notification frequency in the Notifications section, so notifications repeat until the alert returns to OK. The bundle definition shows what this means: retrigger_seconds is how long the alert waits after triggering before it may notify again. If it is 0 or omitted, there is only one notification after the first trigger. A value of 1 notifies on every evaluation where the condition holds. A separate flag, notify_on_ok, sends a message when the alert returns to normal.

    Checkpoint 5 of 9· Check yourself

    An alert is defined with no retrigger_seconds value, and the condition stays met for six consecutive runs. How many notifications go out?

    Checkpoint 6 of 9· Exam question

    An analyst is setting up a Databricks SQL alert and wants failures to post directly into a team's Slack channel, but no Slack destination currently appears in the alert's Destination drop-down menu for the workspace. What must happen before the analyst can select a Slack option for this alert?

    Sources26

    4.Advanced settings: OK messages, empty results, templates

    Advanced settings controls what the notification says and handles edge cases:

    - Notify on OK: also notify when the alert goes back to OK, so recipients learn the problem has cleared. - Empty result state: the status to report when the query returns no rows. - Template: the default message, or a customized subject and body.

    With Customize template you get two editors. The standard editor uses {{VARIABLE_NAME}} placeholders and accepts a limited set of HTML tags. The Markdown editor uses @VARIABLE_NAME, and typing @ opens a variable picker.

    Checkpoint 7 of 9· Check yourself

    You turn on Notify on OK for an alert. When does it send an extra notification?

    Template variables available in custom alert notifications
    VariableContains
    ALERT_STATUSThe evaluated alert status
    ALERT_CONDITIONThe condition operator
    ALERT_THRESHOLDThe threshold
    ALERT_COLUMNThe column name
    ALERT_NAME / ALERT_URLAlert name and alert page URL
    QUERY_RESULT_VALUEThe query result value
    QUERY_RESULT_TABLEHTML table of results, first 100 rows; renders only on email
    QUERY_RESULT_ROWS / QUERY_RESULT_COLSResult rows and column names (standard editor only)

    Sources2

    5.Scheduling, testing and checking the alert

    The threshold and the destination only matter if the alert runs. Use Compute to choose the SQL warehouse that runs the alert query. Then click the calendar icon to open Edit schedule. In the tutorial the alert runs every 5 minutes, starting at 0 minutes past the hour. You can also tick Show cron syntax to write the schedule in Quartz cron syntax. Click View alert to save it.

    Once saved, the alert runs on its schedule. If the condition is met, recipients are notified. If the evaluation is OK, no notification goes out. The alert's page shows a history of evaluation details, and Run now runs the query immediately.

    Checkpoint 8 of 9· Put it in order

    Put the tutorial's alert-creation steps in order

    1. 1.Choose a warehouse in the compute selector
    2. 2.Set the schedule, save, and click View alert
    3. 3.Click Alerts in the sidebar and click Create Alert
    4. 4.Set the condition (Sum of amount > static value 4000) and click Test condition
    5. 5.Add a user in the Notifications section
    6. 6.Paste the query into the query editor and run it

    One operational limit can stop an alert from firing even when everything is set up correctly. Each workspace allows 250 simultaneous active alert runs by default. If all slots are busy when a scheduled alert is due, that run is skipped and the alert does not evaluate. The usual sign is a gap in the evaluation history at the scheduled time, while a manual Run now works. The fix is to stagger schedules, for example 01:30, 01:32, 01:34, instead of running everything at 01:30.

    Checkpoint 9 of 9· Exam question

    An alert's underlying query returns a result set sorted so that the most recent hourly `error_count` value appears in the first row, followed by older hourly values in subsequent rows. The analyst wants the alert to evaluate only that most recent hour's count, ignoring the rest of the rows. Which condition setting achieves this?

    Sources2

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.An alert query can use parameters, and the alert evaluates them with their default values.Why is that wrong?

      In the current alert editor, the query cannot have parameters. Hard-code the values in the alert's own SQL.

      Covered in What an alert is made of

    2. 2.With a SUM aggregation on the alert, QUERY_RESULT_ROWS in the email still lists the original rows.Why is that wrong?

      The alert wraps your query in a CTE and aggregates it, so the template variables only hold the post-aggregation result.

      Covered in Setting the threshold: value, operator, comparison

    3. 3.Any alert author can add a new Slack webhook or PagerDuty destination from inside the alert editor.Why is that wrong?

      Only a workspace admin can create notification destinations. Once created, they are available to all users, who pick them in the Notifications section.

      Covered in Choosing where the notification goes

    4. 4.An HTML-formatted template with QUERY_RESULT_TABLE renders the same way in Slack, Teams and email.Why is that wrong?

      Only email destinations can render HTML. Other destinations display the notification in their own way.

      Covered in Advanced settings: OK messages, empty results, templates

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Evaluations resolve to OK, TRIGGERED, or ERROR.”
      ↩︎ What an alert is made of
      “Databricks SQL alerts run queries on a schedule and notify you when a condition that you define is met against the query result.”
      ↩︎ Key concept
      “An existing saved SQL query cannot be reused when creating an alert.”
      ↩︎ Prediction
    2. 2.
      “Choose the SQL warehouse that runs the alert query.”
      ↩︎ What an alert is made of
      “you can select to set an aggregation across all rows of a single column, such as SUM or AVERAGE.”
      ↩︎ Setting the threshold: value, operator, comparison
      “Static value is selected by default.”
      ↩︎ Setting the threshold: value, operator, comparison
      “Click Test condition to preview the alert and test whether the alert would trigger with the current data.”
      ↩︎ Setting the threshold: value, operator, comparison
      “Indicate which users or notification destinations should be alerted when the threshold value falls outside of the expected range.”
      ↩︎ Choosing where the notification goes
      “Optionally, set a notification frequency to repeat notifications until the alert returns to OK.”
      ↩︎ Choosing where the notification goes
      “Notify on OK: Send a notification when the alert returns as OK.”
      ↩︎ Advanced settings: OK messages, empty results, templates
      “Empty result state: Set a special status to return when the query returns no results.”
      ↩︎ Advanced settings: OK messages, empty results, templates
      “In the Markdown editor, reference variables with @VARIABLE_NAME.”
      ↩︎ Advanced settings: OK messages, empty results, templates
      “If the Test condition returned OK, no notification is sent.”
      ↩︎ Scheduling, testing and checking the alert
      “Each workspace has a default limit of 250 simultaneous active alert runs.”
      ↩︎ Scheduling, testing and checking the alert
      “stagger alert schedules so they do not all fire at the same time.”
      ↩︎ Scheduling, testing and checking the alert
      “Alerts do not support queries with parameters.”
      ↩︎ Exam trap 1
      “Only email notification destinations can render HTML.”
      ↩︎ Exam trap 4
      “Click Alerts in the sidebar and click Create Alert.”
      ↩︎ Checkpoint
    3. 3.
      “ERROR indicates that an error occurred during alert evaluation.”
      ↩︎ What an alert is made of
      “This doesn't mean that the Alert was not previously triggered.”
      ↩︎ Checkpoint
    4. 4.
      “Threshold to use for alert evaluation, can be a column or a value.”
      ↩︎ Setting the threshold: value, operator, comparison
      “If set to 0 or omitted, the alert will not send any further notifications after the first trigger.”
      ↩︎ Checkpoint
    5. 5.
      “your query can implement the alert logic and return a Boolean value for the alert to trigger on.”
      ↩︎ Setting the threshold: value, operator, comparison
      “The alert wraps the original query text in a common table expression (CTE) and performs a wrapping aggregation query on it”
      ↩︎ Exam trap 2
      “those variables will only display the final, post-aggregation query result.”
      ↩︎ Prediction
    6. 6.
      “By default, notifications are sent to user email addresses”
      ↩︎ Choosing where the notification goes
      “After a destination is configured, it is available to all users.”
      ↩︎ Choosing where the notification goes
      “The following destinations are currently supported: Email Slack Webhook, with optional OAuth authentication (Beta) Microsoft Teams PagerDuty”
      ↩︎ Choosing where the notification goes
      “Databricks enforces the use of HTTPS for security.”
      ↩︎ Choosing where the notification goes
      “SQL alerts: Slack and Microsoft Teams.”
      ↩︎ Choosing where the notification goes
      “You must be a Databricks workspace admin to manage notification destinations.”
      ↩︎ Exam trap 3
      “PagerDuty: integration key used to uniquely route notifications to a PagerDuty service.”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 10 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.