Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

View alert execution information

You can click any link in the Alert Executions list to view the alert execution information of the referenced item. This information appears in the Alert Management Rule record only after an alert matched the filter in the rule and an action was performed.

Before you begin

Role required: evt_mgmt_admin

About this task

Among the information shown in the Alert Executions list is:

  • The list of alerts that matched the filter of the rule.
  • The tasks, including incidents, that were opened.
  • Which remediation workflows ran and which subflows ran.

Procedure

  1. Navigate to All > Event Management > Rules > Alert Management Rules.

  2. In the Alert Management Rules list, click the rule.

    If an alert matched the filter in the rule and an action was performed, the Alert Executions list appears in the Alert Management Rules record. The list appears irrespective of the stage of the selected alert management rule.

ColumnDescription
AlertAlert number of the alerts that matched the alert management rule.
Action nameName of the action that was taken to resolve the alert \(subflow or workflow\).
Link to executionLink to the action execution log that was created when the action was performed.
Related taskLink to the task that was created when the alert was resolved. For example, if the action for a rule is to create an incident, this field provides the incident number with a link to open the incident.A link is provided to the workflow remediation task that is created to monitor the remediation.
LogNotice or information showing the result of the execution action, for example, how executions took place, "`1 out of 2 executions`". When the alert closes, the execution count number \(the first number\) resets to 0.This information does not indicate that the subflow was executed successfully, rather that the call to that subflow was successful and that the subflow is correctly configured.
Automatic runIndication of how the action ran: automatically \(true\) or manually \(false\).
CreatedDate and time that the entry was created.

Parent Topic:Alert executions information