Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Can you search for alerts that don't have an incident association

Diego Link January 8, 2022

I am new to OPsGenie and also coming from pagerDuty and finding the workflow in OpsGenie to be very cumbersome when you have a large amount of incoming alerts. It all revolves around acknowledging alerts

I start  my workflow by looking at un-acked alerts.    Since these alerts  should be addressed. My problems are:

  • Auto incident-associated aren't auto-acked
  • There's no way to search for alerts that are associated to an incident (That I can see from the search fields). Hence the subject of my question - this would make the process more streamlined but not really solve it 
  • Going to the incident and showing associated alerts only allows me to close the alerts not ack them.  The incident is still opened and acked but incoming alerts that are auto-associated remain un-acked - creating noise
  • For some reason not all alerts even with the same message do not seem to get auto associated.
    • Selecting those alerts and associating to an incident also does not acknowledge them and worse the action DESELECTS the alerts requiring the user to reselect them and acknowledge them

We have 50+ services with a continual flow of alerts.   Finding and selecting and acknowledging alerts  is not really scalable under my current understanding of this UX.

Now maybe the issue is I should not look at un-acknowledged alerts , but then I still want to see what alerts aren't associated to an incident. Those will help me perhaps write incident rules   Again with the summary of my question - can I search for alerts that are no associated to an incident?

And finally is there a better workflow that I'm missing here.

 

 

 

 

1 answer

0 votes
Agaci Avinas
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 10, 2022
Hi Diego,
Welcome to Opsgenie. I am Agaci, happy to help you today. Please find answers for your workflow below,
  • Auto incident-associated aren't auto-acked
                 
              You do not have to worry about associated alert being auto-ack because notifications would not be triggered for alerts associated with Incidents.
  • There's no way to search for alerts that are associated to an incident (That I can see from the search fields). Hence the subject of my question - this would make the process more streamlined but not really solve it 
               You could make use of the alert search queries. To search alerts associated with the Incident you could use query like - details.key: "incident-id" and message: "test"
  • Going to the incident and showing associated alerts only allows me to close the alerts not ack them. The incident is still opened and acked but incoming alerts that are auto-associated remain un-acked - creating noise
  
              For Associated alerts in an Incident, the notification flow would be suppressed. Only the owner and Responder alert would sent the notifications. You could learn more about different alert types in this link.
  • For some reason not all alerts even with the same message do not seem to get auto associated.
  • Selecting those alerts and associating to an incident also does not acknowledge them and worse the action DESELECTS the alerts requiring the user to reselect them and acknowledge them
 
          You could make use of the search query to list the alerts with same message which is not associated with any Incident. Below query could help you with that.
message: "test" and not details.value: "Associated"
You might want to take a look at your incident rules, to make sure that the filter are matching and creating /associating incidents based on the Alert messages.
Regards,
Agaci 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events