You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/en/observability/create-alerts.asciidoc
+12Lines changed: 12 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -124,6 +124,18 @@ list an alert on the {observability} Alerts page.
124
124
Only alerts generated by rules relating to Applications, Logs, Infrastructure, Synthetics, and Uptime
125
125
can be viewed on the Alerts page.
126
126
127
+
[discrete]
128
+
[[add-investigation-resources-to-rules]]
129
+
=== Add resources for investigating alerts
130
+
131
+
When creating or editing a rule, add the following resources to help you get started with investigating alerts:
132
+
133
+
* **Investigation guide**: Investigation guides can help you respond to alerts more efficiently and consistently. When creating them, you can include instructions for responding to alerts, links to external supporting materials, and more. When the rule generates an alert, the investigation guide can be accessed from the **Investigation guide** tab on the alert details page.
134
+
+
135
+
TIP: Use Markdown to format and structure text in your investigation guide.
136
+
+
137
+
* **Related and suggested dashboards**: Link to dashboards that provide useful insights about your environment, active events, and any other information that might be relevant during your investigations. When the rule generates an alert, linked dashboards can be accessed from the **Related dashboards** tab on the alert's details page. From the tab, you can also review and add suggested dashboards (available for custom threshold rules only).
Copy file name to clipboardExpand all lines: docs/en/observability/view-observability-alerts.asciidoc
+22-6Lines changed: 22 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,6 +58,20 @@ To view the alert in the app that triggered it:
58
58
* From the alert detail flyout, click *View in app*.
59
59
* From the Alerts table, click the image:images/icons/eye.svg[View in app] icon.
60
60
61
+
[discrete]
62
+
[[view-related-alerts]]
63
+
== Review related alerts
64
+
65
+
Check related alerts to find other alerts that might be related to the same incident. You can add these alerts to a case and investigate them as a group instead of analyzing them individually.
66
+
67
+
From an alert's details page, go to the **Related alerts** tab to view related alerts. Within the table, alerts are ordered from most to least relevant. To only view alerts that were created around the same time as the current alert (+/- 30 minutes), apply the **Triggered around the same time** filter.
68
+
69
+
The relevancy of alerts is determined by how closely they match the current alert and other similiarites that they might share:
70
+
71
+
. Alerts in the space are filtered down to only include alerts that were created about one day before or after the current alert.
72
+
. Data from the new subset of alerts is compared against the current alert to identify matching values and similarities. Data such as the time at which alerts were generated or recovered, tags added to the alerts, group values, and more are evaluated.
73
+
. Alerts are scored based on how closely they match the current alert. Alerts with a score above a certain threshold are considered relevant and are included in the list of related alerts.
74
+
61
75
[discrete]
62
76
[[understand-alert-statuses]]
63
77
== Understand alert statuses
@@ -119,22 +133,24 @@ NOTE: Each case can have a maximum of 1,000 alerts.
119
133
120
134
To add an alert to a new case:
121
135
122
-
. Select **Add to new case**.
136
+
. From the **More actions** menu (image:images/icons/boxesHorizontal.svg[More actions]) in the Alerts table or the alert detail flyout, click *Alert details*, then select **Add to new case**.
123
137
. Enter a case name, add relevant tags, and include a case description.
124
138
. Under *External incident management system*, select a connector. If you’ve previously added one, that connector
125
139
displays as the default selection. Otherwise, the default setting is No connector selected.
126
-
. After you’ve completed all of the required fields, click *Create case*. A notification message confirms you successfully
127
-
created the case. To view the case details, click the notification link or go to the <<create-cases,Cases>> page.
140
+
. After you’ve completed all of the required fields, click *Create case*.
141
+
142
+
After creating the case, a confirmation message with an option to view the newly-created case displays. Click the notification link or go to the <<create-cases,Cases>> page to view the case details.
128
143
129
144
[discrete]
130
145
[[existing-case-observability-alerts]]
131
146
=== Add an alert to an existing case
132
147
133
148
To add an alert to an existing case:
134
149
135
-
. Select **Add to existing case**.
136
-
. From the Select case pane, select the case for which to attach an alert. A confirmation message displays
137
-
with an option to view the updated case. To view the case details, click the notification link or go to the <<create-cases,Cases>> page.
150
+
. From the **More actions** menu (image:images/icons/boxesHorizontal.svg[More actions]) in the Alerts table or the alert detail flyout, click *Alert details*, select **Add to existing case**.
151
+
. Select the case for which to attach an alert.
152
+
153
+
After choosing a case, a confirmation message with an option to view the updated case displays. Click the notification link or go to the <<create-cases,Cases>> page to view the case details.
0 commit comments