Alert Incidents

Understand Incident lifecycle, bounded Occurrences, acknowledgement, resolution, and Analytics investigation.

Last verified 2026-08-30

An Incident is the durable lifecycle for one Alert and deterministic group. Status is open, acknowledged, or resolved.

  • Open means the condition has created an active lifecycle.
  • Acknowledged records who accepted ownership and when. Matching Occurrences continue to merge.
  • Resolved queues a closing notification and closes the lifecycle. The next qualifying condition opens a new Incident.

The detail view shows first and last seen time, count, group context, up to 20 recent bounded samples, and notification delivery status. Full raw event history remains in the warehouse.

Use Open in Explorer to carry the Incident reference, selected model, group context, and time window into the existing investigation path. This keeps the workflow focused: detect, alert, investigate, analyze.

Acknowledgement and resolution are project-authorized, audited mutations. Another tenant cannot read or update the Incident by guessing its ID.

Notification delivery is incident-first: the opening delivery is immediate, matches during cooldown merge into the same Incident, and a later qualifying match may queue one summary after cooldown. Pending work for the same Incident and channel is coalesced. This preserves every occurrence count without sending one message per event.

Was this page helpful?Send feedback