Definition

Alerts are notifications that a monitored condition matched a rule or detector; they describe symptoms that need triage.

Question it answers

What condition fired, which system is affected, and where should investigation begin?

Role in an investigation

Use alert labels and links to preserve scope when opening charts or traces. Keep the original alert identity when associating several alerts with an incident. Review grouping when one notification covers unrelated services or different failure mechanisms.

Correlation fields

Fields that make the connection possible
Field or dimensionPurpose
rule identity and deduplication keyRecognize repeats of one condition without conflating different symptoms.
service, environment, and severityRoute the investigation and identify the affected scope.
trigger time and evidence linksOpen the relevant chart or query using the alert evaluation window.

Group symptoms of a shared outage

Checkout, billing, and reporting alert during a database outage. Their dependency relationship supports one coordinated investigation. A separate payment-provider timeout should stay visible if it has a different cause, even when its alert arrives at the same time.

Limitations

  • A triggered threshold describes a condition, not necessarily its cause.
  • Grouping can hide independent incidents if criteria are too broad.
  • Silenced or deduplicated notifications still require reliable evidence retention.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

  • PagerDuty — Configured alert grouping associates related notifications with incidents.

Investigation patterns

Related concepts

Related guides

FAQ

Is one grouped incident proof of one root cause?

No. Grouping is an operational choice that should be revised as investigation uncovers different mechanisms.