Skip to main content

Understand incidents and incident details


Supported operations

You can do the following in this view:

  • Update the assignee and status (In Progress, Resolve, Close):

    Select one or more incidents using the check boxes, right-click, and then select the new status or Assign from the menu.

  • View and leave comments related to the incident

    Click Comment (speech bubble icon). See Moogsoft Cloud Comments to learn more.

  • Copy visible attributes for one or more incidents (with or without headers) and paste into a text file:

    Select the incidents using the check boxes, right-click, and then click one of the Copy options on the menu.

  • Copy a link to an incident:

    Click Copy Link to Incident (chain link icon) in the bottom pane.

  • Open the incident in the Situation Room:

    Click Open Situation Room in the bottom pane to collaborate with your team on a selected incident.

Incident attributes

The following table lists the incident attributes visible in the Incidents table and Incident Details pane.


Moogsoft Cloud stores all timestamps in UTC format. The dates and times displayed in the UI are based on your browser's local time.




A list of the alerts in this incident.


The person assigned to the incident.


A list of the classifications (class field) of all alerts in the incident. The class field is used to categorize the events and metric anomalies that make up an alert. For example, an alert with a "WebServerMonitor" class might include a "web-server-down" event and a "http-requests-failed-rate" anomaly.

Closed on

Timestamp when this incident was closed.

Correlation definition

The name of the correlation definition which resulted in the creation of the incident. The name is linked to the correlation definition.

Created at

Timestamp when the Correlation Engine created this incident.


Auto-generated description of the incident, based on the description field in the correlation definition that generated the incident.

External names

If the incident triggered an external notification based on an outbound webhook, this indicates the object (such as a ticket number) in the external system.

First event time

Timestamp of the earliest event in this incident.

Integration ID

The outbound integration ID, if the incident triggered an external notification based on an outbound webhook.

Integration name

The outbound integration name, if the incident triggered an external notification based on an outbound webhook.


Moogsoft Cloud auto-generates this ID when it creates the incident.

In progress on

The time when the incident status was set to "In Progress."

Last event time

Timestamp of the most recent event in this incident.

Last state change

The last time a user updated the incident status or severity.

Resolved on

Time when the incident was resolved.


A list of all services that generated the events and metrics included in this incident. This list is derived from the service field in the member alerts in this incident.


The incident severity equals the highest severity of any alert in that incident.


Status of the incident.

Superseded by

An incident that was created after this one which includes all of the alerts in this incident.

An incident is superseded by another incident when alerts initially included in one incident combine to form a more comprehensive and descriptive incident (such as incidents indicating several system failures combining into a single overarching switch failure incident). Reference the incident superseding the original incident for the most recent information.

Total alerts

The total number of alerts in the incident.


The list of types from alerts in this incident.