Details
-
Suggestion
-
Resolution: Unresolved
-
None
Description
User Problem
There is no way to trigger incident creation based on the count of the alert, i..e when an alert has been de-duplicated X times.
The Alert De-duplication Count field may represent the frequency of the issues impacting the same service.
It would be ideal to include this useful indicator in the Filter of the Incident Rules to determine an incident creation when the same alert has been de-duplicated within a certain timeframe
Possible Solutions
Within incident rules, add a filter condition for de-duplication count threshold
Known Workarounds
- Create a "Dummy" team and add the incident rule to that dummy team
- On the team that the alerts are going to, create an escalation policy that routes these alerts to that dummy team. And add a routing rule on this team to filter for these specific alerts, and route them to this escalation policy
- On this (original not dummy) team, add a notification policy that filters for these alerts, and delays notifications until the count reaches X.
How it works
- Alert gets created and applies notification rule which delays notifications until count reaches X
- Once count reaches X, notification flow begins and alert matches routing rule which routes it to the escalation which has the "route to dummy team" step
- Alert gets routed to dummy team and matches incident rule on this team which creates inicdent.
Attachments
Issue Links
- is related to
-
OPSGENIE-103 Trigger incident creation based on the presence of 2 or more alerts
- Gathering Interest