You can apply actions to an alert to transition the alert through the alert lifecycle. The following table lists the actions that can be applied to an alert:
|A received alert needs to be acknowledged. After you acknowledge the alert, a comment is displayed as Acknowledged and includes the user name. From the Incident unique ID drop-down menu, click Acknowledge and a tick mark is displayed below the Incident ID.|
|A ticket can be created for the generated alert, assigning users and setting the priority. After an incident is created, the status of the alert changes to Ticketed and the incident ID is displayed in the Action/Status column.Note: While creating the incident manually from the alert, you can use canned response templates to auto populate description in the incident.See Create canned responses for more information on how to make a canned response default.|
|Map an alert to an existing ticket or update the ticket with the alert contents. This action is generally used to update the same ticket with related alerts.|
|Map an alert to an existing ticket without updating the ticket with the alert contents.|
|Suppress the current alert and all duplicate alerts. A new alert of the same type is displayed as a fresh alert and not as a duplicate alert. The status of the alert changes to Suppressed. The Snooze setting suppresses alerts for a specified time interval. If a repeated alert occurs when the alert is in snoozed state, the alerts repeat count increments and the snooze duration is reset based on the repeated alert attributes.|
Note that if the alert payload has a source time that is older than the suppression time, the First Response recommendation or suppression is not applied.
|Undo the |
|Undo a |
|Add process definitions to an alert and run. The option does not appear for Suppressed and Heal alerts.|
|Close an alert when an issue is solved and the alert is resolved. The alert state changes to OK.|
|Under the alert list, there is a new option called Heal. When the user selects the |
This option is applicable to heal the alert for critical and warning types of alerts even if they are in any action. We don't have the option to perform heal action on multiple alerts simultaneously, but can perform heal alert action only on one alert at a time.
For correlated alerts, an action can be performed on the entire inference, but not on a single, correlated alert.
Apply alert action
- Select a client from the All Clients list.
- Go to Alerts and select the alert ID you want.
- In the Action/Status column, click Select and select the action you want to apply.
The alert status transitions to the next state associated with the action. See Alert Lifecycle.
Snooze an alert
You can snooze an alert for a specified duration.
In the Suppress alert window, select Snooze alert for n minutes.
Enter the snooze duration you want:
In the Comments text box, enter a comment you want associated with the suppress action.
Go to the Alerts page to view the snooze setting in the Action/Status column.