Overview
Alert incidents give you a centralized view of every alert Business Activity Monitoring (BAM) has generated, along with the actionable records created when a monitor detects a violation. From the Incidents tab you can review alert details, manage incident states, investigate notification delivery, and export a PDF report — all without leaving the monitoring section.
Business value
Alert incidents reduce the time it takes to diagnose notification gaps, triage monitoring violations, and audit alert activity. The state lifecycle — from open through acknowledgement to close — provides accountability and a clear audit trail of who acted on an alert and when. Instead of checking external notification channels individually, you can review all alerts, their delivery status, and linked saved queries in one place.
How it works
When BAM monitoring detects a violation, it creates an alert incident. Incidents are visible in the Incidents tab under Monitoring for the relevant business process. The list shows each incident's status, alert type, issue count, and creation time.
Each incident supports four states:
- Open — violations are present and unaddressed.
- Acknowledge — the incident has been noted and is under investigation. Acknowledging an incident also stops any active escalation policy sequence.
- Close — the violations are resolved and the incident is no longer active.
- Reopen — the incident requires further attention after being closed.
State changes can be applied to a single incident via the Actions menu, or to multiple incidents simultaneously using the Actions dropdown after selecting the relevant incidents.
BAM records every generated alert in the incident list. Each entry captures the alert type, the saved query that triggered it, and any notification delivery details. Clicking View notification details from the Actions menu shows the per-channel delivery status and escalation rule level. Clicking the status link on an incident opens the Alert details panel, which shows the saved query name, the query expression, and the number of instances matched during the evaluation window.
Steps
Use the following steps to manage alert incidents and review alert history. Navigate to the relevant business process and select Monitoring > Incidents to get started.
Change an incident state
Changing an incident state moves it through the triage lifecycle and, when acknowledged, halts any active escalation sequence.
- In the Incidents list, locate the incident you want to update.
- Click the Actions menu ( ⋮ ) next to the incident.
- Select the target state: Acknowledge, Close, or Reopen.
To update multiple incidents at once:
- Select the checkboxes next to the incidents you want to update.
- Click the Actions dropdown at the top of the list.
- Select the target state.
View alert details
Viewing alert details lets you inspect the saved query and the conditions that triggered a specific alert.
- In the Incidents list, locate the incident you want to review.
- Click the Status link (for example, Open) on the incident row.
- Review the Alert details panel, which shows:
- The business process name.
- Each saved query that contributed to the alert, including the query expression and the number of instances matched within the evaluation window.
View notification details
Viewing notification details lets you confirm which channels received the alert, check delivery timestamps, and investigate any escalation or delivery failures.
- In the Incidents list, locate the incident you want to inspect.
- Click the Actions menu next to the incident.
- Select View notification details.
- In the Notification details panel, review the following:
- Escalation rule level — the escalation level at which this notification was sent.
- Current iteration — the repeat count for the escalation sequence.
- Transmitted at — the timestamp of the notification.
- Per-channel list — each configured channel is listed with its name and transmission timestamp. Channels with delivery failures display an error indicator.
- Enable View details of all levels to see notification history across all escalation rule levels for this incident.
View user action history
Viewing user actions lets you audit every state change made on an incident, including who acted and when.
- In the Incidents list, locate the incident you want to audit.
- Click the Actions menu next to the incident.
- Select View user actions.
- Review the action history, which includes the user's name, the timestamp, and the state change applied.
Filter incidents
Filtering narrows the incident list so you can focus on the relevant state, alert type, or time period.
- In the Incidents list, use the filter controls at the top of the list.
- Apply one or more of the following filters:
- Incident status — show only open, acknowledged, or closed incidents.
- Alert type — filter by the monitor type that generated the incident.
- Date — restrict results to a specific date range.
- The list updates to show matching incidents.
Export alert history
Exporting generates a PDF report of transmitted alerts for a selected date range and delivers it to a notification channel.
- In the Monitoring section, click the Download icon.
- Select a Date range covering the alerts you want to export.
- Select one or more Notification channels to receive the report.
- Click Export.
A link to access the report will be sent to the selected notification channel(s).
BAM initiates a background task. The report is forwarded to the selected notification channels when generation completes.
Troubleshooting
-
Incident state cannot be changed
Cause: The incident is already in a terminal state (Closed) or the user does not have the required permissions to update incident states.
Fix: Confirm the incident state and your role permissions. If the incident needs to be reopened, select Reopen from the Actions menu ( ⋮ ). -
Escalation policy does not stop after acknowledging an incident
Cause: The acknowledgement was applied to the wrong incident, or the escalation sequence had already advanced before the acknowledgement was saved.
Fix: Verify that the correct incident is in the Acknowledge state. If escalation continues, check whether additional open incidents exist for the same monitor. -
Notification details shows no delivery records
Cause: The notification channel was not configured at the time the alert was generated, or the channel was deleted after the alert fired.
Fix: Review the notification channel configuration in the monitor settings and ensure at least one active channel is assigned. -
Bulk state change applies to unintended incidents
Cause: Additional incidents were selected inadvertently before clicking the Actions dropdown.
Fix: Deselect all incidents and re-select only the intended ones before applying the bulk state change. -
Export report is not received on the notification channel
Cause: The notification channel selected for the export is misconfigured or the delivery endpoint (email, Teams, webhook) is unreachable.
Fix: Test the notification channel from the channel configuration page and confirm delivery before retrying the export. -
Incidents tab shows no alerts despite active monitors
Cause: No monitor conditions have been met within the current view period, or the monitors were recently configured and have not yet triggered.
Fix: Confirm that the monitors are enabled and that the thresholds are set correctly. Check whether any transactions match the query conditions in the Tracking section.