Incidents

Learn how incidents consolidate related alerts to provide a comprehensive view of system issues.

Note: In the Controlled Availability release stage, Splunk products may have limitations on customer access, features, maturity, and regional availability. For additional information on Controlled Availability please contact your Splunk representative.

An incident is a correlated group of related alerts that represent a system degradation or disruption. Instead of responding to individual alerts in isolation, incidents provide a single, unified view of an issue, including all related alerts and context.

Purpose and benefits

  • Simplify alert correlation: Connect related alerts from infrastructure and applications into a single incident.
  • Reduce alert noise: Group related alerts so teams can focus on issues that matter.
  • Contextual information: View related alerts, severity, and timelines in one place.