Working with alerts
Filter the alert list down to what you care about, save those views, and act on alerts in bulk.
The Alerts page is where triage happens. On a busy account it lists far more than any one person needs, so most of the work is narrowing it — by label, by source, by status — and then acting on what is left.
Filter alerts by labels
Labels come from the events your tools send. Filtering on them narrows the list to a service, an environment, or a cluster.
Save a view
A filter you rebuild every morning should be a saved view instead.
Managing a saved view
Click the three-dot icon on a saved filter tab:
Edit
Change the name or visibility
Copy link
Share a direct link to this filtered view
Duplicate
Copy it as a starting point for another view
Pin filter
Make it the view you land on when opening Alerts
Delete
Remove it permanently
Act on alerts in bulk
During a noisy period, handling alerts one at a time is the bottleneck. Select several and act on them together.
Tick the checkboxes on the left of each row — or the checkbox in the header row to select everything in the current filtered view — and a bulk action bar appears above the list.
Accept
Take ownership. This stops escalation on every selected alert.
Reroute
Move the selected alerts to a different escalation policy
Resolve
Close them, if the underlying problem is fixed
Link incident
Attach them to an existing incident
Merge
Combine them into one parent alert — see Merging alerts
An alert that is already a parent — one that has other alerts merged into it — cannot be merged into another alert.
Last updated
Was this helpful?