Appearance
Alerts
An alert is a current signal that needs attention. Alerts can represent device connectivity, monitor state, metric rules, or security activity. They carry severity, audience, status, and resource context.
Alerts and incidents are not interchangeable:
- Use an alert for a discrete condition that an operator can inspect and resolve.
- Use an incident where enabled when acknowledgement, escalation, delivery tracking, on-call ownership, or selected public communication is required.
- Use a log alert rule when a saved log query should call a webhook. Log rule grouping and throttling are separate from incident escalation.
Alert lifecycle
Alerts can be active, resolved, or expired depending on their source. A source heartbeat can refresh an existing alert rather than create duplicates. Recovery resolves an active connectivity or monitor alert when the evaluator observes enough successful samples.
Notification preferences decide which eligible product notifications a user receives. They do not replace access control, and they do not make every alert an incident.
Respond safely
Use From signal to verified recovery as the canonical response method: establish scope and ownership, gather evidence, choose the least invasive action, verify recovery independently, and review the available history.