The CreatorCon Call for Content is officially open! Get started here.

Changing Incident Priority Based on Alert Metric Name

lvenna
Tera Expert

Hello Everyone,

We have incidents being created through Event Management. Our requirement is to update the priority (impact and urgency) of these incidents based on the metric name of the originating alert.

I tried configuring this using Alert Management Rules, but I don’t see any option to modify the incident priority there.

Has anyone come across a similar requirement or found a way to achieve this? Any suggestions or guidance would be greatly appreciated.

Thank you in advance for your help!
— Laxma

1 ACCEPTED SOLUTION

Hello Swapna, 

 

Thank you for the response,

 

I have tried to look into the flow, Impact and Urgency is setting based on the alert severity, but the flow is applying for all incidents. We need to change the priority only for few metric type alerts (not based on the alert severity). If I change the flow it is going to impact on other incidents too.

 

Thank you,

Laxma

View solution in original post

7 REPLIES 7

Swapna Abburi
Mega Sage
Mega Sage

Hi @lvenna 

usually, the incident field mapping takes place in the Sub flow (you can access the sub flow details from Alert management rule). You can check the sub flow and understand how the impact and urgency are set in the Incident for that particular event source.

Hello Swapna, 

 

Thank you for the response,

 

I have tried to look into the flow, Impact and Urgency is setting based on the alert severity, but the flow is applying for all incidents. We need to change the priority only for few metric type alerts (not based on the alert severity). If I change the flow it is going to impact on other incidents too.

 

Thank you,

Laxma

Hi @lvenna 

You may need to copy the default subflow and customize it according to your requirement. Update the customized subflow to the corresponding Alert Management rule.

Hello Swapna,

 

Sure, I will try that,

If it isn't work, can I go with business rule on incident table to check the Alert.metric_name filed and add the priority for the specific incidents,

 

Thank you,

Laxma.