microsoft / microsoft/sre-agent

[Feature] Incident Management

Open
#162 4 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
PowerShell
Stars
160
Forks
97
Avg merge
2d 5h
Merged PRs (30d)
12

Description

We had a discussion with the SRE product team on 13th Apr 2026 and requested the implementation of the below-mentioned feature for incident management, it is been a month. thhere is mo update on this.

Incident Management

- Option to download incident reports from the incident management
- Provide an option to configure Incident Response Handlers based on:
- Subscription
- Severity level
- Provide more flexibility

- Enable alert sync without automatic analysis for low-priority incidents (configurable via Incident Handler)
- Provide an “Investigate” option to trigger analysis manually when required
- Assess feasibility to perform investigation without using LLM tokens (e.g.,azure cli, kubectl rule-based or predefined logic)

- Add an “Investigate” button for repeated alerts that are merged without analysis
- currently, RCA is generated only once by the SRE agent; enable users to manually trigger investigation again for recurring alerts on demand

- Ensure seamless integration of Defender alerts with the SRE agent for ingestion, processing, and response handling

- Reduce unnecessary investigation for noisy or repeated alerts by minimizing duplicate analysis and focusing only on unique or high-value incidents

- Frequent alerts are being triggered and resolved within 5–10 minutes, but the same alerts keep repeating for hours or days. In this scenario:
- Duplicate alerts within the same subscription should be merged into a single alert
- The alert should be analyzed only once per day
- Provide an “Investigate” button for manual deep analysis when required

- Requirement to add filter to view incidents by subscription.
- SRE Product team working on to get this feature

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by mapping the existing incident-management flow and Incident Handler configuration, then review how Defender alerts reach the SRE agent. Done would require agreeing on scope and implementing the listed report, filtering, deduplication, manual investigation, alert-sync, and response-handling behaviors.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud, observability
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.