Report on Actionable Alerts

Matt Spiewak
Tera Contributor

I'm curious if anyone has a good strategy on reporting how actionable their alerts are. Most of our alerts are from monitoring sources that send clearing events when the alerting conditions resolve so the alerts and incidents are automatically closed as soon as there is no longer an issue. This is good from a visibility perspective but it makes it hard to tell whether any action was taken on them. Aside from the alerts that become major incidents or the few alerts that don't send clearing events and have to be manually resolved, we don't have a good way to report on if any action was taken. Our goal in this is to try and track which alerts are useful and what alerts might be considered noise. Anyone have suggestions on how to track this type of data?

1 REPLY 1

Jeffreys Quinti
Tera Contributor

Hi Matt,


Leaving incidents open for manual review and using resolutions codes to track how it was resolved is the only way I know to accomplish what you're trying to do.