elastic / elastic/roadmap

Alert enrichment in the New Kibana Alerting Experience

Open
#323 0 comments 0 reactions 1 assignee Claimed by @tiamliu View on GitHub
Component: Kibana product-area:observability product-area:platform
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**What the feature is (as Title)**

Alert enrichment in the New Kibana Alerting Experience

**Value proposition**

Most alerts arrive with too little context. A threshold breach might name a host or service, but not the owning team, tier, upstream dependencies, environment, or runbook. On-call often spends the first minutes of every incident reconstructing information that already exists elsewhere in Elastic or in internal systems. Alert enrichment closes that gap at the episode level, before the Dispatcher hands alerts to action policies. Teams can add topology and operational metadata to each episode so policies can match on richer fields, group related incidents more intelligently, and send notifications that already contain what responders need.

**Expected outcome**
Responders spend less time hunting for ownership and dependency context after an alert fires, because the episode already carries the organizational and operational data they need to triage. The New Kibana Alerting Experience will let teams attach custom enrichment data to alert episodes before they are evaluated by action policies and dispatched to workflows.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.