Skip to content

Commit 543db71

Browse files
[Internal][Observability][UX Management][8.19]: Document related alerts, related dashboards, and investigation guides (#4955)
* First draft * Re-arrange * revisions * Removed duplicate section * Update docs/en/observability/create-alerts.asciidoc * Technical and editorial feedback * Update docs/en/observability/view-observability-alerts.asciidoc
1 parent eeb3d1f commit 543db71

File tree

2 files changed

+34
-6
lines changed

2 files changed

+34
-6
lines changed

docs/en/observability/create-alerts.asciidoc

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,18 @@ list an alert on the {observability} Alerts page.
124124
Only alerts generated by rules relating to Applications, Logs, Infrastructure, Synthetics, and Uptime
125125
can be viewed on the Alerts page.
126126

127+
[discrete]
128+
[[add-investigation-resources-to-rules]]
129+
=== Add resources for investigating alerts
130+
131+
When creating or editing a rule, add the following resources to help you get started with investigating alerts:
132+
133+
* **Investigation guide**: Investigation guides can help you respond to alerts more efficiently and consistently. When creating them, you can include instructions for responding to alerts, links to external supporting materials, and more. When the rule generates an alert, the investigation guide can be accessed from the **Investigation guide** tab on the alert details page.
134+
+
135+
TIP: Use Markdown to format and structure text in your investigation guide.
136+
+
137+
* **Related and suggested dashboards**: Link to dashboards that provide useful insights about your environment, active events, and any other information that might be relevant during your investigations. When the rule generates an alert, linked dashboards can be accessed from the **Related dashboards** tab on the alert's details page. From the tab, you can also review and add suggested dashboards (available for custom threshold rules only).
138+
127139
[discrete]
128140
[[create-alerts-configure]]
129141
== Configure alerts

docs/en/observability/view-observability-alerts.asciidoc

Lines changed: 22 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,20 @@ To view the alert in the app that triggered it:
5858
* From the alert detail flyout, click *View in app*.
5959
* From the Alerts table, click the image:images/icons/eye.svg[View in app] icon.
6060

61+
[discrete]
62+
[[view-related-alerts]]
63+
== Review related alerts
64+
65+
Check related alerts to find other alerts that might be related to the same incident. You can add these alerts to a case and investigate them as a group instead of analyzing them individually.
66+
67+
From an alert's details page, go to the **Related alerts** tab to view related alerts. Within the table, alerts are ordered from most to least relevant. To only view alerts that were created around the same time as the current alert (+/- 30 minutes), apply the **Triggered around the same time** filter.
68+
69+
The relevancy of alerts is determined by how closely they match the current alert and other similiarites that they might share:
70+
71+
. Alerts in the space are filtered down to only include alerts that were created about one day before or after the current alert.
72+
. Data from the new subset of alerts is compared against the current alert to identify matching values and similarities. Data such as the time at which alerts were generated or recovered, tags added to the alerts, group values, and more are evaluated.
73+
. Alerts are scored based on how closely they match the current alert. Alerts with a score above a certain threshold are considered relevant and are included in the list of related alerts.
74+
6175
[discrete]
6276
[[understand-alert-statuses]]
6377
== Understand alert statuses
@@ -119,22 +133,24 @@ NOTE: Each case can have a maximum of 1,000 alerts.
119133

120134
To add an alert to a new case:
121135

122-
. Select **Add to new case**.
136+
. From the **More actions** menu (image:images/icons/boxesHorizontal.svg[More actions]) in the Alerts table or the alert detail flyout, click *Alert details*, then select **Add to new case**.
123137
. Enter a case name, add relevant tags, and include a case description.
124138
. Under *External incident management system*, select a connector. If you’ve previously added one, that connector
125139
displays as the default selection. Otherwise, the default setting is No connector selected.
126-
. After you’ve completed all of the required fields, click *Create case*. A notification message confirms you successfully
127-
created the case. To view the case details, click the notification link or go to the <<create-cases,Cases>> page.
140+
. After you’ve completed all of the required fields, click *Create case*.
141+
142+
After creating the case, a confirmation message with an option to view the newly-created case displays. Click the notification link or go to the <<create-cases,Cases>> page to view the case details.
128143

129144
[discrete]
130145
[[existing-case-observability-alerts]]
131146
=== Add an alert to an existing case
132147

133148
To add an alert to an existing case:
134149

135-
. Select **Add to existing case**.
136-
. From the Select case pane, select the case for which to attach an alert. A confirmation message displays
137-
with an option to view the updated case. To view the case details, click the notification link or go to the <<create-cases,Cases>> page.
150+
. From the **More actions** menu (image:images/icons/boxesHorizontal.svg[More actions]) in the Alerts table or the alert detail flyout, click *Alert details*, select **Add to existing case**.
151+
. Select the case for which to attach an alert.
152+
153+
After choosing a case, a confirmation message with an option to view the updated case displays. Click the notification link or go to the <<create-cases,Cases>> page to view the case details.
138154

139155
[discrete]
140156
[[clean-up-alerts-obs]]

0 commit comments

Comments
 (0)