I have an Incident Rule created for a team to create an Incident based on From criteria of the Alert that was created(I'm using the Email integration). It created the first Incident beautifully.
I'm noticing on subsequent Alerts, the Alert logs say they are creating the Incident, but they are really associating to the first Incident (the first Incident is still open).
How do I change the behavior so that each alert creates a separate Incident?
Thanks in advance!
Hi @Robert Wen_Cprime_ ,
What you're seeing is called "Auto-matched alert behavior."
After an incident is opened, alerts matching the same incident rule automatically become associated alerts of that incident. Opsgenie doesn’t send alert notifications for these alerts. This aims to reduce alert fatigue.
The best ways to avoid this are to:
1. Close incidents in a timely manner to prevent unwanted auto-matching (only open incidents can be auto-matched).
2. Create incident rules that are specific enough to only match the intended alerts (incident rules with filters that are too broad or vague will likely cause unwanted auto-matching).
3. Since matching occurs from top to bottom, if you are using multiple incident rules be sure place the most specific at the top and the lease specific at the bottom (this will allow alerts to match the correct rule).
Thanks, @John M ! I had a feeling it was a feature and not a bug!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.