Skip to main content

Alert List

The alert management page provides an alert-centric view independent of incidents, where you can see detailed information about all alerts regardless of whether they have been grouped into incidents. Go to Incident ListAlert List to access the alert management page. The alert list displays the following information:
Silenced or inhibited alerts display a special marker before the title to help you quickly identify them.

Field Reference

The alert list involves three easily confused field dimensions — please distinguish them carefully: The following filters are available at the top of the alert list: Filter conditions are retained per view and are automatically restored after refreshing or re-entering the page.

View Settings

Click the view settings button at the top of the list to adjust the following options in the popup panel: View settings are retained per view and persist long-term in the current browser.

Batch Operations

You can select multiple alerts in the list and click the Merge button at the top to merge them into a specified incident in one action.

Using Aggregate View

In addition to the standard list view, the alert list also supports Aggregate View. Aggregate view groups alerts by specified dimensions, displaying group cards on the left and alert details for the selected group on the right.
1

Create aggregate view

After switching to aggregate view, if no aggregation rules have been created, the system guides you to create your first aggregate view.
2

Select grouping dimension

Select the aggregation rule for grouping. The system groups alerts by that dimension.
3

Browse groups

The left panel shows group cards including group title, severity, and alert count. Click a group card to display all alerts in that group in the right panel.
In aggregate view, the system matches at most 100 records for grouping display. To view full data, switch to list view.

Alert Details

Click an alert title to enter the alert details page. The top of the page is a HeaderInfo bar that shows the alert title, severity tag, alert ID (hover to copy the full ID), recovery status (Recovered / Not Recovered), and the progress tag of the incident it belongs to. If the alert has ever been silenced or inhibited, the corresponding icon is displayed before the title. The right side of the header provides a Merge action button to merge the current alert into an incident. The details page body is split into two tabs:
You can also choose to view details in the Side Panel mode from the alert list view settings, allowing you to quickly browse alert information without navigating to a new page.

Alert Lifecycle Records

The entire process from trigger to close is fully recorded by the system. Common record types include:
Differences between silence and inhibit:
  • Silence: Alerts matching a silence rule do not send notifications at all. Suitable for planned maintenance windows.
  • Inhibit: While certain “source alerts” are active, related target alerts’ notifications are proactively suppressed. Suitable for secondary alerts triggered by a common underlying failure.

What is an Incident

Understand the relationship between incidents, alerts, and events

Noise Reduction

Learn about alert grouping, silence, and inhibit rules