Working with Incidents
An incident is a trouble ticket attached to a monitored object. Where an alarm signals that something is wrong, an incident tracks the work of investigating and fixing it: who is handling it, what state the work is in, and the discussion along the way. Incidents can be linked to alarms, but can also be created on their own.
Incidents are managed in the Incidents perspective (in the Monitoring section of the perspective switcher).
Incident States
- Open
-
The incident has been created and is waiting to be picked up.
- In Progress
-
Someone is actively working on the incident.
- Blocked
-
Work cannot proceed for now. Moving an incident to Blocked requires a comment explaining the reason.
- Resolved
-
The problem is fixed. Resolving an incident also resolves all alarms linked to it.
- Closed
-
The incident is finished and archived. Closing an incident terminates all alarms linked to it. A closed incident is final — it can no longer be modified, commented on, or reopened.
Only a Resolved incident can be reopened (returned to Open); use this when a problem turns out not to be fixed after all.
The Incident List
The Incidents perspective lists incidents with their ID, state, title, source object, assignee, creation and last-change times, and the number of linked alarms.
-
Double-click an incident to open its details view.
-
Use Hide closed incidents in the context menu to filter out finished incidents.
-
The view menu offers CSV export of the list.
-
Resolve and Close can be applied to several selected incidents at once; the other operations work on one incident at a time.
Creating an Incident
- Manually
-
Select Create incident… in the Incidents perspective. Choose the source object (required), enter a title (required), and optionally an initial comment describing the problem.
- From an alarm
-
Right-click a single alarm in any alarm list and select Create incident. The incident is created for the alarm’s source object, linked to the alarm, and titled with the alarm message. An alarm can be linked to only one incident.
- Automatically
-
Event processing rules can create incidents when they create alarms, optionally with AI-based analysis and automatic assignment. This is configured by administrators — see the EPP Reference in the Administrator Guide.
Working on an Incident
The incident details view shows the title, an overview panel (source object, assignee, created, last change, resolved, and closed times), the comment thread, and the list of linked alarms.
-
Change state with the buttons in the details view: Start (moves to In Progress), Resolve, Reopen, Close, and Mark as blocked… (asks for the reason). The same operations are available from the incident’s context menu in the list.
-
Assign the incident to a user with Assign…; unassigned incidents show (unassigned).
-
Comment with Add comment… to record findings and progress. Comments are permanent — they cannot be edited or deleted afterwards. When AI-based incident analysis is enabled, analysis results appear in the thread as comments.
-
Edit the title directly in the details view using the Edit / Save buttons.
-
Review linked alarms in the alarms table; double-click an alarm to open its details.
-
Discuss with AI opens an AI assistant chat about the incident (when the AI assistant is configured).
Before an incident is resolved or closed you are asked to confirm, since the operation also affects the linked alarms: resolving the incident resolves them, closing the incident terminates them. The relationship is one-directional — resolving or terminating alarms directly does not change the incident they are linked to.