Incident lifecycle

This document outlines the lifecycle of an incident, detailing the states and transitions involved.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.

Incidents follow a two-state lifecycle:

  • Active: The incident is ongoing and editable. Alerts can be added or removed, and severity/timeline updates continue.
  • Closed: The final, read-only state. No alerts can be added or removed, and the incident cannot be reopened.

State transitions

Incidents are created in the Active state. They move to the Closed state via: Auto-closure (alerts clear), Manual closure, Agent closure, or Dismissal.

All state changes appear in the incident timeline.

Incidents are dynamic while active. As Splunk Observability Cloud detects new related alerts, the alerts can be added to the active incident so that you can continue investigating the issue from one place.