A condition opening an incident generates an event, which passes important information downstream.
For more about the definition of incidents and other terms, see our glossary.
What is an incident event?
An incident event is an event where a condition threshold defined in a an alert policy is breached. This event has various attributes (metadata) attached to it and different attributes can be used by different features.
重要
The incident event is a concept used to determine alerting features. While you can query some of its associated attributes via NerdGraph, you cannot directly query the incident event.
NrAiIncident
event attributes
This table shows incident event attributes. The incident event data type is collected in NrAiIncident.
You may be wondering why we're using NrAiIncident
as the name for the incident event data type. Although sometime you can see these events as "violations," they are called "incidents" in our UI.
All attributes are available for use in a description. Read about attributes available for muting rules.
Attribute | Description |
---|---|
| The ID of the account where the incident occurred. Available for muting rules. |
| The active condition's aggregation window. |
| If applicable, what caused the incident to close. Available values:
|
| If applicable, the timestamp when the incident was closed. |
| If true, open incidents on the signal are closed if the signal is lost. Default is false. To use this field, an |
| The ID of the condition that triggered the incident. Available for muting rules. |
| The name of the condition that triggered the incident. Available for muting rules. |
| The timestamp when the targeted metric started to breach the active condition's threshold. |
| The contents of the active condition's NRQL or infrastructure conditions only. Not available for use with alert condition title or description templates. |
| The targeted entity's globally unique identifier, if available. Available for muting rules. |
| The targeted entity's name, if available. |
| The targeted entity's type, if available. |
| The active condition's evaluation offset. A time delay (in seconds) to ensure data points are placed in the correct aggregation window. If you use the Delay/timer setting in the UI, it clears |
| The reason the incident was opened. Available values:
|
| The record's event type. Available values: |
| The active condition's signal loss time window. |
| The unique identifier of the incident. Not available for use with alert condition title or description templates. |
| Shows whether the active condition was muted at the time of the incident event. |
| The unique identifier of the muting rule that caused the incident to be muted. |
| The type of data targeted by a NRQL condition. In this context, this refers to any NRQL-queryable data type. Available for muting rules. |
| The full string of the NRQL query. Can be used for sub-string matching on attributes in the Available for muting rules. |
| The timestamp when the incident was opened. |
| The incident threshold's operator, such as For signal loss incidents, this is an empty string. |
| The ID of the policy that triggered the incident. Available for muting rules. |
| The name of the policy that triggered the incident. Available for muting rules. |
| The level of the incident: |
| The timestamp when the active condition's targeted metric stops breaching the threshold. |
| The runbook URL for the condition that triggered the incident. Available for muting rules. |
| Arbitrary key-value metadata, or tags, associated with the incident. Available for muting rules. |
| The name of the incident's target. This can be an entity or a query. Available for muting rules. |
| The active condition's threshold value. |
| The active condition's threshold time window. |
| Shows whether |
| The event's wall clock time using an epoch timestamp. |
| The incident's title. |
| The incident's type. Available value: |
| The active condition's aggregation function. Used in APM, browser, and mobile alert condition types. |
| The active condition's incident time limit setting. |
| Deprecated. Do not use. |