Definition
Alerts are notifications that a monitored condition matched a rule or detector; they describe symptoms that need triage.
Question it answers
What condition fired, which system is affected, and where should investigation begin?
Role in an investigation
Use alert labels and links to preserve scope when opening charts or traces. Keep the original alert identity when associating several alerts with an incident. Review grouping when one notification covers unrelated services or different failure mechanisms.
Correlation fields
| Field or dimension | Purpose |
|---|---|
| rule identity and deduplication key | Recognize repeats of one condition without conflating different symptoms. |
| service, environment, and severity | Route the investigation and identify the affected scope. |
| trigger time and evidence links | Open the relevant chart or query using the alert evaluation window. |
Group symptoms of a shared outage
Checkout, billing, and reporting alert during a database outage. Their dependency relationship supports one coordinated investigation. A separate payment-provider timeout should stay visible if it has a different cause, even when its alert arrives at the same time.
Limitations
- A triggered threshold describes a condition, not necessarily its cause.
- Grouping can hide independent incidents if criteria are too broad.
- Silenced or deduplicated notifications still require reliable evidence retention.
Supported by
Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.
- PagerDuty — Configured alert grouping associates related notifications with incidents.
Investigation patterns
Related concepts
Related guides
FAQ
Is one grouped incident proof of one root cause?
No. Grouping is an operational choice that should be revised as investigation uncovers different mechanisms.