We have auto incident creation rules in place for a particular team / service. If we trigger mutliple incidents with different messages, but the same priority, only one incident gets created.How do we allow an incident to be created per alert?
The behavior I am noticing is alerts being associated to the same incident. How does one dissociate alerts upon triggering an incident?
-
Hi Sterling,
If an incident is left open and there is an alert that comes in that matches the same incident rule that created the incident, it will associate that alert with the already open incident, rather than creating a new incident.
Here is the incident rule documentation, which explains that in more detail:
https://support.atlassian.com/opsgenie/docs/automatically-create-an-incident-via-incident-rules/
If alerts with different messages are being associated with open incidents, you may want to make sure your incident rule is set to 'Match All Conditions' - if it's set to 'Match Any Conditions' the matching priority alone will associate the alert with an open incident with the same priority.
If those settings look correct and you're still seeing this behavior, please go ahead and open a support ticket and we can help you troubleshoot this further:
https://support.atlassian.com
> associate the alert with an open incident with the same priorityThis implies that if the priorities are different between two separate alerts that match the same rule, that each would create a separate incident?Or do the alerts both go to the same incident based purely on something like last incident with the same incident-creation-rule ?
It would depend on whether the rule was filtering for the priority. If not, and it was just a single condition looking for a matching message, it would associate all alerts that match that message with the original incident that was opened - so long as that incident has not been closed.
If there was a second condition to match a particular priority, and it was set to "Match all Conditions" then an alert without a matching priority would not be associated with an incident at all - but if there was a separate incident rule where all the conditions matched, including priority, it would create a separate incident.
It sounds like any alert received for processing by team incident-rules by the Incident Management Rule engine uses the rule-id to find a matching prior incident. Is that statement correct?
Whether the message field in the alert matched the incident summary field or the prior alert message does not seem to matter. Is that correct?
It looks like you're new here. Sign in or register to get started.