Auto Investigations
guided tour · part 4 of 5 resolve overview docid\ ctmycol8s0io8g1giztix → connect an integration docid\ ig yfnpcmge2yt3oq5i4b → team knowledge docid\ d5xhezjtrrw k5spbvoob → auto investigations → tuning accuracy docid mempyfopnqpmkk 1vowo auto investigations let resolve start working the moment an alert fires — scoping impact, gathering evidence, and posting findings before your on call engineer even opens the alert this part walks through setting them up find your alerts open investigations from the sidebar and switch to the alerts tab you'll typically see far more alerts than investigations — for example, 188 alerts in the last 24 hours versus 39 investigations some alerts are already investigated in triage mode you can segment alerts by team and add filters to focus on a specific set of alerts the goal define a filter for the alerts you care about, then have resolve auto investigate them as they arrive create an alert filter go to the relevant team (for example, the product team) and open its alerts configuration you'll see any filters already defined click the + to create a new filter you'll see the same alert view add a condition — for example, severity is critical the view updates to show matching alerts (say, 41 in the last 24 hours) save the filter filters live in your team's knowledge configuration alongside runbooks — see teams & knowledge docid\ m4f0bsnc1so f7zedqxrw and the knowledge setup guide docid\ ejosivxhatgxk4mm4ngbd turn on auto investigation and pick a mode open the saved filter and enable auto investigate resolve offers three modes, each matching a different amount of effort to the alert triage — scopes impact, follows your runbooks docid\ d5xhezjtrrw k5spbvoob , and stops when done you decide whether to go deeper adaptive — resolve decides how deep to go, adjusting based on initial findings investigation — always performs a thorough, multi agent deep investigation to find the root cause you set the mode per alert filter, so different alerts can get different levels of scrutiny for a full explanation of each mode and when to use it, see alert investigations docid\ z6j1w4ll2 pmc8te2syz auto investigations draw on per mode budgets and rate limits — see limits docid 0u4r5jj0einulam7lbzje better runbooks and dashboard guidance make auto investigations dramatically more useful if you haven't yet, work through part 3 — team knowledge docid\ d5xhezjtrrw k5spbvoob first respond automatically in slack or ms teams to have resolve reply directly in chat, connect the app for slack docid 1h6snyqoiyvttj4utlq4v or app for ms teams docid\ qahtx0wbw9pc2 ba4clks , then open slack channels and add the channel your alerts land in set the channel type to alert now any alert that arrives in that channel — if it matches a filter with auto investigation enabled — gets an automatic reply with resolve's investigation see workplace collaboration tools docid\ suk9kssv8nrqvzkkiw6ap for how channel types work, and auto investigations in the slack app docid 1h6snyqoiyvttj4utlq4v for details for collaborative, human in the loop incident response in these same channels, see incident investigations docid\ sun7tyfsahbp5azy9qcc what's next once auto investigations are running, the last step is making them consistently accurate — a short, iterative loop of feedback and knowledge updates next part 5 — tuning accuracy docid mempyfopnqpmkk 1vowo previous part 3 — team knowledge docid\ d5xhezjtrrw k5spbvoob