alert-investigation

โดย launchdarkly

ตรวจสอบการแจ้งเตือนด้านการสังเกตการณ์ที่ถูก触发 และส่งคืนการวินิจฉัยที่มีโครงสร้าง พร้อมสาเหตุที่เป็นไปได้ ขอบเขต และขั้นตอนถัดไป

npx skills add https://github.com/launchdarkly/ai-tooling --skill alert-investigation

Alert investigation

You are investigating a specific triggered alert. Alerts arrive with structured context — an alert ID, name, threshold, value that crossed it, and a time range. Your job is to explain why it fired, assess scope, and recommend action.

Prerequisites

This skill uses the following LaunchDarkly observability MCP tools:

  • query-logs — query log records
  • query-traces — query distributed traces
  • query-error-groups — query error groups
  • query-sessions — query sessions
  • query-aggregations — query aggregated/time-bucketed metrics
  • get-keys — discover available attribute keys before filtering

Workflow

  1. Parse the alert context. The first turn of the conversation carries alert variables: alertID, alertName, alertValue, group, groupValue, query, thresholdWindow, timeRange, plus a product-specific link. Use these, don't re-derive them.
  2. Load the per-product companion. Based on the alert's product type, load the matching companion: logs.md, traces.md, errors.md, sessions.md, or metrics.md. Each captures the per-product investigation shape.
  3. Run the investigation using the methodology from the investigate skill (cross-reference logs/traces/errors/sessions/metrics; cite identifiers; aggregate before paginating). Scoped to the alert's time range and filter.
  4. Produce a structured diagnosis. See output template below.

Output template

Alert investigations have a consistent structure so consumers (notification channels, dashboards) can parse them.

## What triggered

<1-2 sentences naming the alert, the threshold, and the value that crossed it.>

## Likely cause

<Root-cause narrative citing specific evidence: trace IDs, log timestamps, error group IDs, flag keys, deploy timing.>

## Scope

<Who or what is affected. Number of users, services, sessions, error groups. Time window of impact.>

## Next steps

<1-3 concrete actions the on-call or owner should take. Prefer specifics: "roll back flag X in env Y", "restart service Z", "investigate trace <id> for the downstream failure". Avoid "investigate further" — if you don't have a root cause, say what specifically should be investigated and how.>

When to load which companion

  • logs.md — log alert, log pattern alert
  • traces.md — latency alert, trace-error-rate alert, span-specific alert
  • errors.md — error-rate alert, new-error-group alert, crash-rate alert
  • sessions.md — session-health alert, user-facing-error-rate alert
  • metrics.md — custom metric threshold, aggregated metric alert, composite alert

If the alert crosses product boundaries (e.g. a metric alert driven by error data), load both companions.

Guidelines

  • Stay tight. Alert investigations feed notifications — keep the output structured and scannable. No preamble ("Here is my analysis..."), no repeated framing.
  • Cite identifiers. Every claim in the diagnosis should reference a specific trace ID, error group ID, session ID, or log timestamp.
  • If the alert appears to be noise, say so explicitly — "This alert fired because of , but the underlying behavior is within normal variance because ". Noise is a legitimate outcome; don't invent root causes.
  • Don't redo the investigation you just did. The diagnosis output should let the on-call act without re-querying.

Skills เพิ่มเติมจาก launchdarkly

aiconfig-online-evals
launchdarkly
เลิกใช้งานแล้ว เปลี่ยนเส้นทาง — สกิลนี้ถูกเปลี่ยนชื่อเป็น online-evals อย่าใช้สกิลนี้ ให้เรียกใช้ online-evals แทน เก็บไว้เพียงเพื่อให้การอ้างอิงเก่าๆ ยังคง...
aiconfig-tools
launchdarkly
เลิกใช้งานแล้ว เปลี่ยนเส้นทาง — สกิลนี้ถูกเปลี่ยนชื่อเป็น tools แล้ว อย่าใช้สกิลนี้ ให้เรียกใช้ tools แทน เก็บไว้เพียงเพื่อให้การอ้างอิงเก่าๆ ไปยัง aiconfig-tools ยังคงชี้ไปที่...
launchdarkly-flag-targeting
launchdarkly
ควบคุมการกำหนดเป้าหมายของฟีเจอร์แฟล็ก LaunchDarkly รวมถึงการเปิด/ปิดแฟล็ก การเปิดตัวแบบเปอร์เซ็นต์ กฎการกำหนดเป้าหมาย เป้าหมายรายบุคคล และการคัดลอกแฟล็ก…
launchdarkly-flag-drift
launchdarkly
ตรวจจับและปรับความคลาดเคลื่อนระหว่างค่าเริ่มต้นสำรองของ SDK ในโค้ดของฟีเจอร์แฟล็กกับกฎเริ่มต้น (fallthrough) ของ LaunchDarkly ใช้เมื่อค่าเริ่มต้นของแฟล็ก...
snippets
launchdarkly
สร้างและจัดการสไนปเป็ตพรอมต์ — บล็อกข้อความที่นำกลับมาใช้ซ้ำได้ซึ่งอ้างอิงภายในพรอมต์การแปรผันของคอนฟิก เก็บคำแนะนำทั่วไป บุคลิก และการ์ดเรล…
create-skill
launchdarkly
เพิ่มทักษะใหม่ไปยัง repo agent-skills ของ LaunchDarkly ใช้เมื่อสร้าง SKILL.md ใหม่ เพิ่มทักษะในแคตตาล็อก หรือปรับให้สอดคล้องกับข้อกำหนดของ repo
skill-name
launchdarkly
คำอธิบายที่ชัดเจนเกี่ยวกับสิ่งที่สกิลนี้ทำและเมื่อใดที่เอเจนต์ควรใช้ รวมถึงคำสำคัญที่ช่วยให้เอเจนต์ระบุงานที่เกี่ยวข้องได้
agent-graphs
launchdarkly
สร้างและจัดการกราฟเอเจนต์ — กราฟแบบมีทิศทางของคอนฟิกที่เชื่อมต่อด้วยขอบพร้อมตรรกะการส่งต่อ ใช้เมื่อสร้างเวิร์กโฟลว์แบบหลายเอเจนต์ที่คอนฟิกกำหนดเส้นทาง…