Updating an incident when an alert escalation occurs - how can this be done?

tammykuhns
Kilo Guru

I need to find a way for the incident to be updated with new information (description & severity) based on the alerts which are coming in to event management.   I have tried to add additional Alert Management rules which would update the incident but it appears that the rules are not launched once an incident is related. 

Any ideas how to make this work?  How do others handle an alert being a low severity and then increases to a critical -- how does the support team get notified via an incident?  Any assistance would be appreciated. 

1 ACCEPTED SOLUTION

Hi - There is no OOB Update Incident flow, you would use the OOB Create Incident flow, and click the 3 vertical dots in the top right hand corner and copy it (change the name) - then in the Create Task step, change that to Update Incident ...

I know Terry will reach out to you and assist - we can also setup a zoom to go over this where I can help as well.

View solution in original post

5 REPLIES 5

tammykuhns
Kilo Guru

Thank you for the clarification.  I misunderstood at first.  I followed your direction and used the OOB create incident flow - modified it as you indicated.  Works like a charm!!!