Events, noise reduction and routing
What happens to an event between the rule that fired it and the person who receives it — mute rules, subscriptions, event pipelines, and self-healing.
Downstream of the rule: mute rules, subscriptions, and event pipelines — grouping, label rewriting and conditional routing. Wire up ibex when an alert should fix itself rather than wake somebody.
Active and historical events
Active events hold alerts that have not recovered; on recovery they move to history. Both lists are searchable by label, severity and business group, in bulk.
Event aggregation and deduplication
One rule plus one label set is one event, so repeated evaluations never create a second; the aggregation view folds hundreds of active events into a few cards.
Mute rules
Silence by label match, time window or maintenance schedule, and see what a mute rule is currently swallowing.
Alert subscriptions
Let a team receive events from rules they do not own, with their own channel and severity filter.
Event pipelines
Ordered processors that transform, enrich, drop or route an event before notification.
Rewrite labels and enrich context
Rename or add labels, or call your own service and write what it returns back onto the event.
AI summary processor
Have an LLM write a short summary onto each event before it is notified: model setup, the prompt template, where the result lands, and what happens when the call fails.
Conditional routing
Send an event to different channels or teams depending on its labels and severity.
Try a workflow with a mock event
Run a pipeline against a hand-written event and see each processor's output before anything is live.
Inspect workflow execution records
Execution records trace each event through every processor: what each one changed, whether the event was dropped, and where it was sent.
Trigger self-healing with ibex / webhook
Run a script on the affected host through ibex, or call a webhook, when a specific event fires.
Noise reduction patterns
Recipes that hold up in production: flapping, storms during deploys, duplicate sources, and what should never page a human.