Incident lifecycle
This document outlines the lifecycle of an incident, detailing the states and transitions involved.
Incidents follow a two-state lifecycle:
- Active: The incident is ongoing and editable. Alerts can be added or removed, and severity/timeline updates continue.
- Closed: The final, read-only state. No alerts can be added or removed, and the incident cannot be reopened.
State transitions
Incidents are created in the Active state. They move to the Closed state via: Auto-closure (alerts clear), Manual closure, Agent closure, or Dismissal.
All state changes appear in the incident timeline.
Incidents are dynamic while active. As Splunk Observability Cloud detects new related alerts, the alerts can be added to the active incident so that you can continue investigating the issue from one place.