Create a Rule
Configure a rule and preview it against your recent alerts before saving.Open Investigation Rules
/account/ai/surfaces/investigation_rules to the Rootly app URL.Create the Rule
Critical checkout alerts.Add Conditions
Review Matching Alerts
Add Rule Instructions
Choose the Run Mode
Rule Settings
0 to disable the cooldown. The value must be a whole number from 0 through 2147483647. Editing other rule settings doesn’t reset a cooldown that’s already running. Setting the cooldown to 0 or clearing it ends any running cooldown at once. Changing it to another positive value doesn’t shorten or extend one that’s already running.Condition Fields
- is one of matches when the whole value equals a selected value, without case sensitivity.
- contains one of matches when the field contains a selected value without case sensitivity.
- is not one of excludes the selected exact values.
details.region, shows that path in the editor. The field picker doesn’t offer payload conditions for new rows, and the 90-day counts leave them out. An alert without the payload path never matches a payload condition, even with is not one of.
Run Modes
Account-Level Automatic Investigation
Your Rootly account team can also turn on automatic investigation for the selected team. It may not be enabled for your team, and there’s no setting for it in AI & Agents. When it’s on, it changes what the run modes do:- An alert that matches no Auto-run rule is still investigated automatically, without rule instructions.
- An alert that matches only a Manual or Paused rule is still investigated automatically, without that rule’s instructions.
- While the matching Auto-run rule’s cooldown is active, the alert isn’t investigated automatically. It doesn’t fall through to a later rule or to account-level automatic investigation.
How Overlapping Rules Behave
More than one rule can match the same alert. Only one rule applies to a run, and AI SRE doesn’t merge instructions from other matching rules. AI SRE handles the overlap in two parts:- Starting the run: the matching Auto-run rule created first (the oldest) controls the automatic start and its cooldown.
- Applying instructions: for a run someone starts, the matching non-paused rule (Manual or Auto-run) created first (the oldest) contributes its rule instructions. For an automatic run, the Auto-run rule that started it contributes them, even when an older Manual rule also matches.
Design Reliable Rules
- Start in Manual mode and compare the preview with the alert class you intended to match.
- Use Auto-run for alerts with a clear owner and enough connected evidence to investigate.
- Add a cooldown when a noisy alert class can create many distinct alerts in a short period. A cooldown is shared by every alert matched by that rule.
- Keep rule instructions scoped to the matched alert class. Put shared guidance in AI SRE instructions.
- Prefer stable normalized fields over free-form title text when both are available.
- Pause a rule while changing an alert source or payload contract.
- Review the Alerts (7d) column in the rule list for unexpected growth or inactivity. It counts investigations started under the rule in the last seven days, including manual runs and reruns, so one alert can count more than once.
Troubleshooting
A rule matches more alerts than expected
A rule matches more alerts than expected
An automatic investigation didn't start
An automatic investigation didn't start
An alert was investigated automatically without an Auto-run rule
An alert was investigated automatically without an Auto-run rule
AI SRE followed the wrong rule instructions
AI SRE followed the wrong rule instructions
Frequently Asked Questions
Do rule instructions apply when I start a run manually?
Do rule instructions apply when I start a run manually?
Can a rule automatically investigate an incident?
Can a rule automatically investigate an incident?
What does a rule with no conditions do?
What does a rule with no conditions do?
Do rule instructions replace my AI SRE instructions?
Do rule instructions replace my AI SRE instructions?
Can I manage rules through the API?
Can I manage rules through the API?