Incidents
Incidents group related alerts together and track their lifecycle from detection to resolution.How Incidents Work
- Alert fires - A rule condition is met
- Incident created - New incident or grouped with existing
- Notifications sent - Team is alerted
- Investigation - Team acknowledges and investigates
- Resolution - Issue is fixed, incident closed
Incident Grouping
Related alerts are automatically grouped:- Same service/source
- Within time window (default: 5 minutes)
- Similar tags
Incident States
| State | Description |
|---|---|
open | New incident, not yet acknowledged |
acknowledged | Team is aware and investigating |
resolved | Issue fixed, incident closed |
Managing Incidents
List Incidents
Get Incident
Acknowledge Incident
Resolve Incident
Add Note
Incident Timeline
Every incident maintains a timeline:| Event | Description |
|---|---|
incident_created | Incident opened |
alert_added | New alert added to incident |
alert_resolved | Alert in incident resolved |
acknowledged | Team acknowledged |
note_added | Note added |
escalated | Escalated to next level |
resolved | Incident resolved |
Escalation
Incidents can escalate if not acknowledged:Incident Metrics
Track incident performance:| Metric | Description |
|---|---|
| MTTA | Mean Time to Acknowledge |
| MTTR | Mean Time to Resolve |
Best Practices
Acknowledge Quickly
Set targets for acknowledgment time
Add Notes
Document investigation steps in timeline
Include Root Cause
Record root cause when resolving
Review Metrics
Track MTTA/MTTR to improve response