Skip to content
Notifications
Clear all

Maybe the real problem isn't the tool but how we define incidents

1 Posts
1 Users
0 Reactions
6 Views
(@lisam3)
Eminent Member
Joined: 1 week ago
Posts: 13
Topic starter   [#5628]

I’ve been evaluating incident response tools for a small team, and I keep hitting a wall. We can’t agree on what even *counts* as an incident.

Before we buy a tool, I think we need to get this right. Our current "definition" is so vague it leads to alert noise or missing real problems.

* Is it only customer-impacting?
* Does a failed cron job on a dev server count?
* What about a 10% performance dip that’s not breaking SLA?

How does your team define it? Specifically, I’m looking for:

* Criteria you use to classify something as an incident.
* How you document this so everyone follows it.
* Any examples from a small business context.



   
Quote