I believe the most important cause of alert fatigue come from being notified for irrelevant events. The risk just being that "receiving an alert" will not be asociated by team members, to the idea something really happened and should be investigated quickly.
My wish would be to have the option to mark any acked alerts as being either a false or true positive with a kind of drop down field.
This way, in a second time, my team and I would have the chance to export the list of alerts where the monitor that triggered it should be reviewed.
Is that wish already feasible in OpsGenie? 🙏
The easiest way would simply be to have the responder add a tag that indicates whether the alert is a false positive (or true positive). This would, however, not be a simple drop-down.
If your Opsgenie level supports Actions, you could add a "Mark as False Positive" action, with the action channel adding that tag via an OEC script. That script could also export that alert to another system for further analysis.
I didn't know about opsGenie action interesting.
via an OEC script
If I'm right that require of me to run a kind of daemon somewher? Is there no integration that bring the same result and would be managed by Atlasian?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.