Incident notification rules

Learn how incident notification rule enables you to define who receives notification.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.

Incident notification rules enable you to define who receives notifications when incidents impact specific services, infrastructure, or environments. Each rule has affected entities scope, optional environment criteria, and the notification destinations for incidents that match the rule.

Notification details

When an incident matches a notification rule, you receive an email notification or a Slack message in the configured channel. The message summarizes the incident so that the receipients can quickly understand what happened and decide whether action is needed. It includes key details such as the incident title, current severity, affected services or infrastructure, and a link to open the full incident details. When the incident is resolved, the receipients receives a closure message with the final status and duration information when available.

View incident notification rules

Learn how to view your existing incident notification rules.

To view incident notification rules:
  1. From the Splunk Observability Cloud main menu, select Alerts.
  2. Select Incident notifications.
The page displays all the existing incident notification rules.
Incident notification rules

Create incident notification rules

Learn how to create incident notification rules.

To create an incident notification rule:
  1. Select + Create rule.
  2. Enter a Rule Name and an optional Description.
  3. Select the Entity scope field to define the specific entity type, such as service, cluster, namespace, environment to which this rule applies. Use '=' for environments you want to match, or '!=' for environments that should not be matched.
  4. Select the desired Severity levels to configure how notifications are routed based on severity.
  5. Select + Add recipient for each severity level to specify where notifications should be sent. You can send notifications to emails and slack channels.
    Note: For Slack integration, see Send alerts to Slack.
  6. Click Create rule to save your configuration.
Create incident notification rule