> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Alert details

> Palo Alto Networks Cortex XCOR lists triggered alerts and generates detailed visualizations of each alert.

export const AddToDashboardIcon = props => {
  return <svg viewBox="0 0 20 20" className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }} {...props}>
      <path fillRule="evenodd" clipRule="evenodd" d="M3 3H9V9H3V3ZM11 3H17V9H11V3ZM3 11H9V17H3V11ZM13.25 11H14.75V13.25H17V14.75H14.75V17H13.25V14.75H11V13.25H13.25V11ZM12.5 4.5V7.5H15.5V4.5H12.5ZM4.5 4.5V7.5H7.5V4.5H4.5ZM4.5 12.5V15.5H7.5V12.5H4.5Z" />
    </svg>;
};

export const CollectionIcon = props => {
  const drawPath = "M21 6.5c-1.66 0-3 1.34-3 3 0 .07 0 .14.01.21l-2.03.68c-.64-1.21-1.82-2.09-3.22-2.32V5.91C14.04 5.57 15 4.4 15 3c0-1.66-1.34-3-3-3S9 1.34 9 3c0 1.4.96 2.57 2.25 2.91v2.16c-1.4.23-2.58 1.11-3.22 2.32l-2.04-.68C6 9.64 6 9.57 6 9.5c0-1.66-1.34-3-3-3s-3 1.34-3 3 1.34 3 3 3c1.06 0 1.98-.55 2.52-1.37l2.03.68c-.2 1.29.17 2.66 1.09 3.69l-1.41 1.77C6.85 17.09 6.44 17 6 17c-1.66 0-3 1.34-3 3s1.34 3 3 3 3-1.34 3-3c0-.68-.22-1.3-.6-1.8l1.41-1.77c1.36.76 3.02.75 4.37 0l1.41 1.77c-.37.5-.59 1.12-.59 1.8 0 1.66 1.34 3 3 3s3-1.34 3-3-1.34-3-3-3c-.44 0-.85.09-1.23.26l-1.41-1.77c.93-1.04 1.29-2.4 1.09-3.69l2.03-.68c.53.82 1.46 1.37 2.52 1.37 1.66 0 3-1.34 3-3S22.66 6.5 21 6.5zm-18 4c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1zM6 21c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1zm5-18c0-.55.45-1 1-1s1 .45 1 1-.45 1-1 1-1-.45-1-1zm1 12c-1.38 0-2.5-1.12-2.5-2.5S10.62 10 12 10s2.5 1.12 2.5 2.5S13.38 15 12 15zm6 4c.55 0 1 .45 1 1s-.45 1-1 1-1-.45-1-1 .45-1 1-1zm3-8.5c-.55 0-1-.45-1-1s.45-1 1-1 1 .45 1 1-.45 1-1 1z";
  return <svg viewBox="0 0 24 25" data-testid="CollectionIcon" aria-label="CollectionIcon" {...props} className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }}>
      <path d={drawPath} />
    </svg>;
};

export const CollectionNavIcon = props => {
  const drawPath = "M8.4 18.2C8.8 18.7 9 19.3 9 20C9 21.7 7.7 23 6 23S3 21.7 3 20 4.3 17 6 17C6.4 17 6.8 17.1 7.2 17.3L8.6 15.5C7.7 14.5 7.3 13.1 7.5 11.8L5.5 11.1C5 11.9 4.1 12.5 3 12.5C1.3 12.5 0 11.2 0 9.5S1.3 6.5 3 6.5 6 7.8 6 9.5V9.7L8 10.4C8.6 9.2 9.8 8.3 11.2 8.1V5.9C10 5.6 9 4.4 9 3C9 1.3 10.3 0 12 0S15 1.3 15 3C15 4.4 14 5.6 12.8 5.9V8.1C14.2 8.3 15.4 9.2 16 10.4L18 9.7V9.5C18 7.8 19.3 6.5 21 6.5S24 7.8 24 9.5 22.7 12.5 21 12.5C19.9 12.5 19 11.9 18.5 11.1L16.5 11.8C16.7 13.1 16.3 14.5 15.4 15.5L16.8 17.3C17.2 17.1 17.6 17 18 17C19.7 17 21 18.3 21 20S19.7 23 18 23 15 21.7 15 20C15 19.3 15.2 18.7 15.6 18.2L14.2 16.4C12.8 17.2 11.2 17.2 9.8 16.4L8.4 18.2Z";
  return <svg viewBox="0 0 24 24" data-testid="Collections" aria-label="Collections" {...props} className="inline-block h-5 w-5" style={{
    fill: "#28a561"
  }}>
      <path d={drawPath} />
    </svg>;
};

export const ServiceIcon = props => {
  return <svg viewBox="0 0 22 20" {...props} className="inline-block h-5 w-5" aria-label="ServiceIcon" style={{
    fill: "#28a561"
  }}>
      <path fillRule="evenodd" clipRule="evenodd" d="M10.7339 0.0766817C10.8966 -0.0255606 11.1034 -0.0255606 11.2661 0.0766817L16.2661 3.21954C16.4117 3.31104 16.5 3.47092 16.5 3.64286V8.35714C16.5 8.52908 16.4117 8.68896 16.2661 8.78046L11.2661 11.9233C11.1034 12.0256 10.8966 12.0256 10.7339 11.9233L5.73391 8.78046C5.58834 8.68896 5.5 8.52908 5.5 8.35714V3.64286C5.5 3.47092 5.58834 3.31104 5.73391 3.21954L10.7339 0.0766817ZM6.5 4.54772V8.08086L10.5 10.5951V7.062L6.5 4.54772ZM11.5 7.062V10.5951L15.5 8.08086V4.54772L11.5 7.062ZM15.0605 3.64286L11 6.19514L6.93955 3.64286L11 1.09057L15.0605 3.64286Z" />
      <path fillRule="evenodd" clipRule="evenodd" d="M5.73391 8.07668C5.89657 7.97444 6.10343 7.97444 6.26609 8.07668L11.2661 11.2195C11.4117 11.311 11.5 11.4709 11.5 11.6429V16.3571C11.5 16.5291 11.4117 16.689 11.2661 16.7805L6.26609 19.9233C6.10343 20.0256 5.89657 20.0256 5.73391 19.9233L0.733914 16.7805C0.588344 16.689 0.5 16.5291 0.5 16.3571V11.6429C0.5 11.4709 0.588344 11.311 0.733914 11.2195L5.73391 8.07668ZM1.5 12.5477V16.0809L5.5 18.5951V15.062L1.5 12.5477ZM6.5 15.062V18.5951L10.5 16.0809V12.5477L6.5 15.062ZM10.0605 11.6429L6 14.1951L1.93955 11.6429L6 9.09057L10.0605 11.6429Z" />
      <path fillRule="evenodd" clipRule="evenodd" d="M15.7339 8.07668C15.8966 7.97444 16.1034 7.97444 16.2661 8.07668L21.2661 11.2195C21.4117 11.311 21.5 11.4709 21.5 11.6429V16.3571C21.5 16.5291 21.4117 16.689 21.2661 16.7805L16.2661 19.9233C16.1034 20.0256 15.8966 20.0256 15.7339 19.9233L10.7339 16.7805C10.5883 16.689 10.5 16.5291 10.5 16.3571V11.6429C10.5 11.4709 10.5883 11.311 10.7339 11.2195L15.7339 8.07668ZM11.5 12.5477V16.0809L15.5 18.5951V15.062L11.5 12.5477ZM16.5 15.062V18.5951L20.5 16.0809V12.5477L16.5 15.062ZM20.0605 11.6429L16 14.1951L11.9395 11.6429L16 9.09057L20.0605 11.6429Z" />
    </svg>;
};

export const ServiceNavIcon = props => {
  return <svg viewBox="0 0 20 20" {...props} className="inline-block h-5 w-5" aria-label="Services" style={{
    fill: "#28a561"
  }}>
      <path d="M0 13.5463C0 13.3708 0.157997 13.2607 0.284979 13.3478L4.18974 16.0263C4.24909 16.067 4.28571 16.1427 4.28571 16.2248V19.7709C4.28571 19.9465 4.12772 20.0566 4.00074 19.9695L0.0959735 17.291C0.0366259 17.2503 0 17.1745 0 17.0925V13.5463Z" />
      <path d="M5.2381 16.2248C5.2381 16.1427 5.27472 16.067 5.33407 16.0263L9.23883 13.3478C9.36581 13.2607 9.52381 13.3708 9.52381 13.5463V17.0925C9.52381 17.1745 9.48718 17.2503 9.42784 17.291L5.52307 19.9695C5.39609 20.0566 5.2381 19.9465 5.2381 19.7709V16.2248Z" />
      <path d="M4.85641 15.0372L8.75079 12.3658C8.87876 12.2781 8.87876 12.0566 8.75079 11.9688L4.85641 9.29746C4.79785 9.25729 4.72596 9.25729 4.6674 9.29746L0.773017 11.9688C0.645052 12.0566 0.645052 12.2781 0.773016 12.3658L4.6674 15.0372C4.72596 15.0774 4.79785 15.0774 4.85641 15.0372Z" />
      <path d="M5.23804 4.279C5.23804 4.10344 5.39603 3.99337 5.52302 4.08048L9.42778 6.75893C9.48713 6.79964 9.52375 6.8754 9.52375 6.95746V10.5036C9.52375 10.6792 9.36575 10.7892 9.23877 10.7021L5.33401 8.02368C5.27466 7.98297 5.23804 7.90721 5.23804 7.82515V4.279Z" />
      <path d="M10.4761 6.95746C10.4761 6.8754 10.5128 6.79964 10.5721 6.75893L14.4769 4.08048C14.6039 3.99337 14.7618 4.10344 14.7618 4.279V7.82515C14.7618 7.9072 14.7252 7.98297 14.6659 8.02368L10.7611 10.7021C10.6341 10.7892 10.4761 10.6792 10.4761 10.5036V6.95746Z" />
      <path d="M10.0944 5.76985L13.9888 3.09851C14.1168 3.01073 14.1168 2.78924 13.9888 2.70147L10.0944 0.0301261C10.0359 -0.010042 9.964 -0.010042 9.90544 0.0301261L6.01105 2.70147C5.88309 2.78924 5.88309 3.01073 6.01105 3.09851L9.90544 5.76985C9.964 5.81002 10.0359 5.81002 10.0944 5.76985Z" />
      <path d="M10.4761 13.5463C10.4761 13.3708 10.6341 13.2607 10.7611 13.3478L14.6658 16.0263C14.7252 16.067 14.7618 16.1427 14.7618 16.2248V19.7709C14.7618 19.9465 14.6038 20.0566 14.4768 19.9695L10.572 17.291C10.5127 17.2503 10.4761 17.1745 10.4761 17.0925V13.5463Z" />
      <path d="M15.7142 16.2248C15.7142 16.1427 15.7508 16.067 15.8101 16.0263L19.7149 13.3478C19.8419 13.2607 19.9999 13.3708 19.9999 13.5463V17.0925C19.9999 17.1745 19.9633 17.2503 19.9039 17.291L15.9991 19.9695C15.8722 20.0566 15.7142 19.9465 15.7142 19.7709V16.2248Z" />
      <path d="M15.3325 15.0372L19.2269 12.3658C19.3548 12.2781 19.3548 12.0566 19.2269 11.9688L15.3325 9.29746C15.2739 9.25729 15.202 9.25729 15.1435 9.29746L11.2491 11.9688C11.1211 12.0566 11.1211 12.2781 11.2491 12.3658L15.1435 15.0372C15.202 15.0774 15.2739 15.0774 15.3325 15.0372Z" />
    </svg>;
};

export const CSharpIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="m11.5 15.97.41 2.44c-.26.14-.68.27-1.24.39-.57.13-1.24.2-2.01.2-2.21-.04-3.87-.7-4.98-1.96C2.56 15.77 2 14.16 2 12.21c.05-2.31.72-4.08 2-5.32C5.32 5.64 6.96 5 8.94 5c.75 0 1.4.07 1.94.19s.94.25 1.2.4l-.58 2.49-1.06-.34c-.4-.1-.86-.15-1.39-.15-1.16-.01-2.12.36-2.87 1.1-.76.73-1.15 1.85-1.18 3.34 0 1.36.37 2.42 1.08 3.2.71.77 1.71 1.17 2.99 1.18l1.33-.12c.43-.08.79-.19 1.1-.32M13.89 19l.61-4H13l.34-2h1.5l.32-2h-1.5L14 9h1.5l.61-4h2l-.61 4h1l.61-4h2l-.61 4H22l-.34 2h-1.5l-.32 2h1.5L21 15h-1.5l-.61 4h-2l.61-4h-1l-.61 4h-2m2.95-6h1l.32-2h-1l-.32 2Z" style={{
  fill: "#28a561"
}} />
  </svg>;

export const PipeIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="M22 14h-2v2h-6v-3h2v-2h-2V6a2 2 0 0 0-2-2H4V2H2v8h2V8h6v3H8v2h2v5a2 2 0 0 0 2 2h8v2h2" style={{
  fill: "#28a561"
}} />
  </svg>;

export const AiMessageIcon = props => <svg style={{
  display: "inline-block",
  width: "1.5rem",
  height: "1.5rem"
}} viewBox="0 0 24 24" {...props}>
    <path d="M2.5 3C2.08782 3.00012 1.73499 3.14696 1.44141 3.44043C1.14766 3.73418 1 4.0875 1 4.5V19L4 16H15.5C15.9124 16 16.2659 15.8532 16.5596 15.5596C16.8533 15.2658 17.001 14.9125 17.001 14.5V10H15.5V14.5H3.375L2.5 15.375V4.5H10V3H2.5Z" style={{
  fill: "#28a561"
}} />
    <path fillRule="evenodd" clipRule="evenodd" d="M14.1154 3.11538L11 4.5L14.1154 5.88461L15.5 9L16.8846 5.88461L20 4.5L16.8846 3.11538L15.5 0L14.1154 3.11538Z" style={{
  fill: "#28a561"
}} />
  </svg>;

export const MicroscopeIcon = props => <svg viewBox="0 0 24 24" {...props} className="inline-block h-5 w-5" aria-label="Microscope" style={{
  fill: "#28a561"
}}>
    <path d="M9.46,6.28L11.05,9C8.47,9.26 6.5,11.41 6.5,14A5,5 0 0,0 11.5,19C13.55,19 15.31,17.77 16.08,16H13.5V14H21.5V16H19.25C18.84,17.57 17.97,18.96 16.79,20H19.5V22H3.5V20H6.21C4.55,18.53 3.5,16.39 3.5,14C3.5,10.37 5.96,7.2 9.46,6.28M12.74,2.07L13.5,3.37L14.36,2.87L17.86,8.93L14.39,10.93L10.89,4.87L11.76,4.37L11,3.07L12.74,2.07Z" />
  </svg>;

Palo Alto Networks Cortex XCOR lists all triggered alerts and their status, and
generates detailed visualizations of each alert. The visualizations and related tools
help you analyze when, why, and how an alert was triggered.

Each alert instance is identified by the unique combination of series labels and
static entity labels that remain after any signal grouping is applied. This means
two triggered alerts are distinct instances when their label sets differ, even if
they come from the same monitor.

Each alert instance has a unique URL.

Click <Icon icon="link-2" /> **Copy URL** in the page header to copy a shareable URL
to your clipboard. Share it with teammates so they can view the same page directly.

The alert details page is mobile-responsive so you can view alert status,
examine chart data, and [mute alerts](#mute-an-alert) from a mobile device.

## View the list of alerts

To view the list of triggered alerts, select
**<Icon icon="bell" /> Alerting <span aria-label="and then">></span> Alerts**
in the navigation menu.

Each listed alert includes several columns of information:

* The date and time that it was **Created at**
* Its **Status**, designated with an icon, text, and color (see [Alert status](#alert-status))
* Its title (**Alert**), as a link to its alert details page
* The duration that the alert has been **Alerting for**
* The **Configuration entity** related to the alert, as a link to the associated
  entity, such as a [monitor](/investigate/alerts/monitors) or [SLO](/observe/slo)

You can define the number of **Rows per page** to display by clicking its dropdown
and selecting a value. To navigate between pages, click the **\< Go to previous page**
and **> Go to next page** buttons.

### Alert status

The alerts list and alert details page designate status with an icon, text, and color:

| Icon | Text | Description |
| - | - | - |
| <Icon iconType="solid" icon="badge-alert" color="#ee6c6cff" /> | **Critical** | Actively triggered alert that exceeds the defined critical conditions. |
| <Icon iconType="solid" icon="triangle-alert" color="#ffb249ff" /> | **Warning** | Actively triggered alert that exceeds the defined warning conditions. |
| <Icon iconType="solid" icon="info" color="#a6bff8ff" /> | **Muted** | Alert that's muted by an active muting rule. |
| <Icon iconType="solid" icon="circle-check" color="#59cc8dff" /> | **Resolved** | A resolved alert. |

## View an alert's details

Access an alert's detail page from the alerts list or another reference to the
triggered alert. References include the source
[monitor](/investigate/alerts/monitors) or
[service level objective (SLO)](/observe/slo) that defined the alert's triggers.

### Status and signals

Each alert presents **alert details** in a dedicated section. This section
includes the alert's status, a visualization of the triggering queries and
change events, and a table of the series and conditions that triggered the alert.
For status icon and label descriptions, see [Alert status](#alert-status).

The page also lists any triggering **[Signal](/investigate/alerts/notifications/signals)** as chips
that identify its keys and their values.

### Query tabs

The alert details section provides two tabs for viewing query results:

* **Stored data**: Default. Visualizes the alert's original query of currently stored
  metric data. Results typically match what the alerting engine evaluated, but can
  differ if late-arriving data has since been ingested. To account for ingestion
  delays, consider
  [adding an offset to your query](/investigate/alerts/troubleshooting#add-offsets-to-your-query).
* **Evaluated data**: Queries the `ALERTS_VALUE` metric, which records the values the
  alerting engine computed at each evaluation interval. See
  [Alert metrics](/investigate/querying/metrics/alert-metrics) for reference
  documentation about the `ALERTS` metric and its labels. This view shows what the
  monitor actually saw when it made its alerting decision, regardless of data that
  arrived later. The table for this tab includes **alertstate** and **severity**
  columns. A series with `alertstate` set to `pending` triggers an alert after it has
  been continuously breaching the threshold for the sustain duration configured on
  the monitor.

Use the **Evaluated data** tab to determine if the alerting engine observed data
differently than what's currently stored, such as when late-arriving metrics change
the stored view.

Both tabs display query results as a
[time series chart](/observe/dashboards/panels/time-series-chart). You can optionally:

* Toggle **Show thresholds**, which draws dotted horizontal lines on the time series chart
  depicting the alert's triggering thresholds.
* Toggle **Show query** or **Show queries**, which displays the active tab's underlying queries.
* Click **Open in explorer** to open [Metrics Explorer](/investigate/querying/metrics)
  with the active tab's query.
* Click [**Analyze anomaly (DDx)**](/investigate/analyze/differential-diagnosis)
  to analyze the data with Cortex XCOR Differential Diagnosis.
* On narrower screens, click the <Icon icon="ellipsis-vertical" /> three vertical
  dots icon to find actions that don't appear as direct buttons.
* Hold the pointer over the chart to display an additional
  <Icon icon="ellipsis-vertical" /> three vertical dots icon with additional
  [common panel actions](/observe/dashboards/panels#common-panel-elements).

The **Open in explorer** and **Show query** controls reflect whichever tab is active.
When viewing the **Evaluated data** tab, the explorer link and query preview display
the `ALERTS_VALUE` query. When viewing the **Stored data** tab, they display the
alert's source query.

### Late-arriving data notice

A warning banner can display with the alert's time series chart to indicate that
late-arriving data might have affected the alert. This banner appears on the
**Stored data** tab, and on the **Availability** tab for SLO alerts, in the following
situations:

* The firing alert's data is delayed: For an actively firing alert, the most
  recent data point for the firing series is older than the rate at which the
  data usually updates. The banner reports how old the latest data point is and
  the expected update cadence, and cautions that the alert might have triggered
  on incomplete data. Check the alert again in a few minutes, after the data
  catches up.
* Stored data no longer meets the triggering condition: Late-arriving data changed
  the stored result after the monitor or SLO evaluated it. Use the **Evaluated data**
  tab to see the values recorded when the alert triggered.

If either situation happens regularly, add an offset to your query to account for
ingestion delays. For more information, see
[Add offsets to your query](/investigate/alerts/troubleshooting#add-offsets-to-your-query).

### Chart and series tables

In the time series table, select from visualized series to highlight them in the
visualization, and you can use the **Search series** query box to filter the list.
You can also toggle between two views. The default
**<Icon icon="grid-3x3" /> table view**, lists the time series' status as an icon and
its labels and their values. The **<Icon icon="list" /> list view** lists only each
series' status and the query that produces it.

You can optionally reveal the **Conditions** that triggered the alert. Cortex XCOR lists
these conditions as a table of each condition's status, operator,
sustained duration, time to resolution, and the signals to which the alert's
conditions apply.

### SLO panels

If the alert's source is an SLO, the alert details page also reproduces the SLO's
**SLI breakdown** and **Burn/Error rates** sections for reference. For more information,
see [Service level objectives](/observe/slo).

## Mute an alert

To mute an alert, create a [muting rule](/investigate/alerts/muting-rules). You
can do this directly from an alert details page by clicking the **Mute alert** button.
This opens a panel to [create a muting rule](/investigate/alerts/muting-rules#create-a-muting-rule)
that's populated with the alert's relevant source and name, and without requiring
you to leave the alert details page.

If a muting rule is already muting a triggered alert, clicking this button instead
opens a panel to edit the associated muting rule.

Alternatively, you can select
**<Icon icon="bell" /> Alerting <span aria-label="and then">></span> Muting Rules**
in the navigation menu to create new muting rules or edit existing muting rules.
However, doing so doesn't populate the muting rule with details from a specific
alert's source.

## Define the alert detail view's time range

You can customize the chronological scope of an alert's details by selecting a
[time range](/navigate/time-ranges), which defaults to the **Last 1 hour**. The chart
and time series table update to depict time series data only within the selected time
range, but the alert's status always displays its current state.

<Warning>
  Selecting a time span that lacks data related to the alert can cause the alert's
  tables or visualizations to report **No data**. Confirm that the time range selector
  is set to a range relevant to the alerting event.
</Warning>

## View an alert's history

The **Alert history** section on the alert details page lists past instances of
the same alert. Past instances are previous occurrences with the same signal labels from the same
monitor or SLO.

Each past instance appears as a link labeled with the relative time it was created,
such as `2 hours ago`. Click any link to navigate to that instance's alert details
page. The current instance is labeled with the relative time followed by
**(This instance)** and can be expanded to show the events associated with it.

If more recent instances exist outside the initially loaded window, a
**Show more recent alerts** button appears at the top of the list.

## Navigate to an alert's source

Each alert detail page includes a link to the source of its trigger. An alert triggered
by a monitor has a **Source monitor** link, and an alert triggered by an SLO has a
**Source SLO** link.

If you navigate to an alert's source, you can return to the alert either by clicking
the triggered alert in the source entity. You can also return to the
[alerts list](#view-the-list-of-alerts) and filter it by the alert's title.

## Investigate an alert with Operator

<Note>
  This feature is in Early Access (EA), and might not be visible in your app. To learn
  more about this program and the features it contains, see the
  [Early access](/early-access) page.
</Note>

[Operator](/navigate/operator) reads triggered and resolved alerts, and
explains what changed around one. Because it knows which alert page you're viewing,
you can ask about the open alert without identifying it.

To investigate the open alert, click **<AiMessageIcon /> Ask Operator** in the page
header or press <kbd>A</kbd>, and then describe what you want to know. For example:

<Prompt description="Why did this alert trigger, and what changed in the 30 minutes beforehand?">
  Why did this alert trigger, and what changed in the 30 minutes beforehand?
</Prompt>

Operator correlates the alert's signal against logs, traces, and
[change events](#examine-an-alerts-related-change-events).

<Note>
  This feature isn't available to all Palo Alto Networks Cortex XCOR users and
  might not be visible in your app. For information about enabling this feature in your
  environment, contact [Cortex XCOR Support](/support).
</Note>

Operator can start a deep investigation that runs while you continue triaging. See
[Start an investigation](/navigate/operator/capabilities#start-an-investigation).

When a report is ready, you can [save it as a new
notebook](/navigate/notebooks#save-an-investigation-report).

<Warning>
  Generative AI features can produce incorrect results, hallucinate data, and deliver
  inaccurate analysis. Use generative AI features with care, and independently verify
  all information produced by generative AI tools before applying it.

  Certain prompts, data, or other inputs might produce irrelevant content. Don't rely on
  generative AI features or responses for any uses that exceed their designed scope.
</Warning>

## Examine an alert's related change events

If you've [enabled change events](/observe/enable-events), the alert details page
displays associated events in the time series chart and lists them in the **Change events**
section.

To configure which change events appear in the chart, click **<Icon icon="layers" /> Events**
to open the **Display events** panel. Under **Change events**:

* Toggle **Show event markers** to show or hide event markers on the chart.
* Use the **Code** or **Builder** mode toggle to configure the change events query.
  In **Builder** mode, use the category table to select which event categories to display.

Click **Save** to apply your changes.

The change events list includes each [Alert change event](/overview/concepts/change-events)
related to the displayed alert. The section's table lists events that occurred during
the selected time span in chronological order, starting with the most recent event.

To view a change event's details, click the event's row in the list to open its
**Change event** panel. This displays the event's title, category, source, type,
time of occurrence, and label names and values. It also links to the alert's source
and provides tabs to **Comments** and the change event entity's **JSON** depiction.

To further explore all listed change events, click **Open explorer** in the alert
details page's **Change events** section. Clicking this link opens
[Changes Explorer](/overview/concepts/change-events) and populates it with the same
time range and query used to populate the alert details page's list of change events.

## View an alert's related information

The **Alert information** sidebar identifies the [collection](/administer/collections)
identified as the alert's **Owner** and its associated **[Team](/administer/accounts-teams/teams)**.
If the alert's source is an SLO, this section also lists the SLO's **Runbook** link
if one is defined.

When designing collections and teams, add contextual links, details, and default
notification policies to ensure that responders can quickly identify and notify
responsible colleagues or follow established policies and processes when an alert
is triggered.

The **Additional information** section of the sidebar lists any **Annotations**
defined on the alert's triggering source. For example, if you defined
[annotations](/investigate/alerts/monitors/monitor-annotations) or
[templated links](/investigate/alerts/monitors/annotation-links) on a monitor or SLO,
the alert's additional information lists each entry and populates any variables
defined in them. Link-valued annotations render as clickable links scoped to the
alert's time range when the destination supports it.

When designing something that can trigger an alert, such as a monitor or SLO, use
annotations to conditionally contextualize these alert views with information pertinent
to responders.

### Monitor or SLO information

The sidebar includes **Monitor information** or **SLO information**, depending on
whether the alert was triggered by a [monitor](/investigate/alerts/monitors) or
[service level objective (SLO)](/observe/slo). This card shows the source's current
status and other alerting signals active on that same source.

* **Current status**: The overall state of the source monitor or SLO.
* **Status** and **Signal values**: A table of other actively alerting signals from
  the same source. The table excludes the signal for the alert you're viewing. Each
  **Signal values** entry links to that signal's alert details page. Hover over an
  entry to see its full label key-value pairs. A footer displays the count of other
  alerting signals on the source, for example, `3 related alerts`.

If the source has more than 10 other alerting signals, a **Signal labels** field
appears so you can filter the table to specific label key-value pairs.

If no other signals are firing on the source, the card displays
`No other alerting signals found for this monitor` or
`No other alerting signals found for this SLO`.

If the source monitor or SLO is unavailable, the card displays
`Source monitor unavailable` or `Source SLO unavailable`.

Click **Open details** to open the source
[monitor](/investigate/alerts/monitors/monitor-details) or
[SLO](/observe/slo) detail page.

## Document an alert's resolution

When an alert is resolved, document its resolution in the alert's **Resolution notes**
section. These notes can provide context to identify recurring issues and capture
actions for incident reviews.

### View resolution notes

The alert details page's **Resolution notes** section lists any resolution notes
associated with an alert.

In addition to the note's contents, each resolution note includes:

* The user ID of the note's author.
* The date and time that the note was added.
* An **(edited)** indicator, if the note was edited.
* The note's associated signals.
* The date and time of the alert's most recent resolution at the time the note was
  added.

You can [filter the list of resolution notes](#filter-resolution-notes),
[edit a note](#edit-a-resolution-note), or [delete a note](#delete-a-resolution-note).

### Add a resolution note

You can add multiple resolution notes to an alert. To add a resolution note from
an alert details page:

1. Click **+ Add** to open the **Create resolution note** panel.
2. Enter the note in the **Resolution note** field. The field accepts Markdown formatting,
   with shortcut buttons for Bold, Italics, code, and links.

   To preview formatting, enable the **Show preview** toggle.
3. Click **Create** to create the note, or **Cancel** to return to the alert details
   page.

### Edit a resolution note

To edit a resolution note:

1. Click **<Icon icon="pencil" /> Edit resolution note** for the note you
   want to edit.
2. Edit the resolution note's contents.
3. Click **Save** to save the changes, or **Cancel** to return to the alert details
   page.

### Delete a resolution note

To delete a resolution note:

1. Click **<Icon icon="trash" /> Delete resolution note** for the note you want
   to delete.
2. Click **Delete** to confirm that you want to delete the note.

### Filter resolution notes

You can filter resolution notes [by signal](#filter-notes-by-signal) or
[by text](#filter-notes-by-text).

#### Filter notes by signal

By default, the alert details page filters resolution notes by the actively firing
signal.

Toggle **Show current signal only** off to include notes from all alert instances on
the same source. Duplicate notes can appear if the same note was added to more than
one instance.

#### Filter notes by text

To filter resolution notes by their contents:

1. On the alert details page, click the **Search resolution notes** field.
2. Enter text to display only the resolution notes that contain that text.


## Related topics

- [Monitor details](/investigate/alerts/monitors/monitor-details.md)
- [Respond to incidents](/overview/guides/incident-response.md)
- [Manage service level objectives](/investigate/alerts/manage-slos.md)
- [Overview of alerting](/investigate/alerts.md)
- [Add templated links to monitors](/investigate/alerts/monitors/annotation-links.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.