Incident Feed

The incident feed provides a consolidated view of all active incidents from any integrated monitoring systems. After you’ve configured your integrations, you can use the incident feed to manage your incidents.

Viewing the Incident Feed

BigPanda digests all the alerts from your integrated monitoring systems and intelligently correlates related alerts into incidents. Alerts are correlated and updated in real time, so your incident feed is always up to date with the latest system and application statuses.

  1. At the top of the screen, click the Incidents tab.
    By default, the incident feed displays all active incidents.
  2. (Optional) In the left pane, select an Environment.
  3. (Optional) In the left pane, select a folder.
  4. Review basic information about each incident.



Status Indicator

Displays a colored ribbon on the left to indicate the incident status, which is determined by the most severe status of the related alerts.

Number of Active Alerts

Counts the number of related alerts that are in the Critical or Warning state.


Assigned level of importance (most important on top). Incidents that do not have a priority assigned will be listed at the bottom by Last Changed.


Displays the type of monitoring tool (such as Nagios or Zabbix) and the integration name (such as Production) that the alerts came from.

Main Title

Shows why the alerts are correlated into an incident.


Summarizes the subjects (such as hosts or applications) that are part of the incident.

Last change, Created, or Duration

Shows information relevant to the current sort order. You can point to it to see more specific information. See Sorting Incidents.

  1. (Optional) Perform any of the available actions, such as Snooze, Share, or Comment.
    The number of existing shares and comments are displayed for each incident. You can click either number to view relevant details.


Viewing Incident Details

To view more information about an incident, click the incident in the feed. The incident details appear in the right pane. You can view related alert details, a timeline of the incident life cycle, sharing history, comments, and more. For more information, see Working With Incidents.

Selecting a Folder

A folder filters the incident feed by predefined criteria. You can select a folder to see all the incidents within an Environment that meet the folder criteria.

  1. From the incident feed, select an Environment in the left pane.
    The incident feed shows the active incidents in the Environment, and the list of available folders expands.
  2. In the left pane, select the folder with the desired criteria.




Incident has active alerts and is not snoozed.


Incident has active alerts and has not been shared or snoozed.


Incident is active, and has been shared with users manually or by AutoShare.


Incident is active, was snoozed, and is within the snooze period. When the snooze period elapses, the incident again appears in the Active folder and no longer appears in the Snoozed folder.

Resolved (24h)

Incident was marked as resolved within the past 24 hours. When an incident is reopened, it again appears in the Active folder and no longer appears in the Resolved folder.

Searching for Incidents

You can search for incidents that meet specific criteria within the selected Environment and folder.

  1. (Optional) Select an Environment and a folder.
  2. At the top of the incident feed, enter a keyword search term or exact phrase in quotes keyword search (term or exact phrase in quotes) or a query in BigPanda Query Language (BPQL).


Regular Expression Support

Both keyword search and BPQL support regular expressions. Use a regular expression by entering a slash (/) as the first and last character of your search term. For example, /prod-.*-[0-9]+/. Regex queries are limited to 32,000 characters and are case sensitive. See Elasticsearch Regular Expression Syntax and BPQL for more regex support.

  1. Click the search icon or press Enter.


Search Logic and Results

Enter a term or an exact phrase in quotes to perform a keyword search of the incidents in the selected Environment and folder. The search finds alerts with matching values in descriptions, source systems, and in any standard or custom tag (such as host, check, or status).

Use BPQL to search for values in a specific alert tag or to create an advanced query. You can search any standard or custom tags, define precise conditions with operators, and include multiple conditions.

  1. (Optional) Scroll down to view more results.

Sorting Incidents

The feed lists incidents that meet the current folder and search criteria. By default, the incidents are listed in order by when they were last changed, with the most recently changed incident on top. You can change the sort order of the incidents in your feed.

  1. From the incident feed, click the Sort icon beside the search field.
  2. Select the desired sort order.



Last Changed

Time of last change to incident (most recently changed on top). A change includes status changes on related alerts and the addition of new alerts to the incident.


Current status of the incident (most severe status on top, in the order: critical > warning > unknown > acknowledged > resolved). Secondary sorting is based on Last Changed.


Time the first alert on the incident was received (newest on top). The order is preserved even if the status of an incident changes.

No. of Alerts

Number of active alerts (highest number on top). Secondary sorting is based on Last Changed. In the Resolved folder only, the number of alerts is the total number of alerts, as no alerts are active on a resolved incident.


Amount of time that the incident has been open (longest on top). Secondary sorting is based on Last Changed.


Assigned level of importance (most important on top). Incidents that do not have a priority assigned will be listed at the bottom by Last Changed.

Responding to Incidents

You are able to respond to incidents right in the Incident feed.

Incident ActionsIncident Actions

Incident Actions

Take action using the prioritize, assign, resolve, snooze, comment, or share icons on each incident, or use the selection boxes to take action on multiple incidents at once. Click any incident in the incident feed to open the incident details in the incident pane.

To learn more about taking action on incidents, see the Working with Incidents documentation.

Mobile Support

In the lightning-fast world of ITOps, it’s vital to be able to respond to outages no matter where you are. The BigPanda incident feed is mobile compatible, allowing you to find and view incidents, dig into their details, and take action even on the go.

Mobile Incident FeedMobile Incident Feed

Mobile Incident Feed

BigPanda mobile works on any device capable of running a Supported browser.

Viewing Incidents on Mobile

To optimize the interface for mobile screens, the BigPanda mobile incident feed is streamlined and simplified.

By default, the BigPanda mobile screen will open your view on the All Incidents/Active environment folder. To change the environment or folder, select the three lines icon in the top left of the page, and select the environment or folder from the flyout list. Filter environments at the top of the flyout, by entering a term or an exact phrase in quotes.

To maximize performance, you are able to toggle the feed between Live and Manual Updates. Live Updates update the incident feed with new incidents, comments, and changing incident statuses automatically. Manual Updates will only update the incident feed when you refresh your browser page, or when reopening the page after closing. To change to a different feed setting, select the Settings wheel and click the desired frequency.

Select an incident to open the incident details. From the incident details page, you are able to take action on the incident, or delve into alert details, timeline, and potentially related changes. To learn more about the incident details pane, see the Working with Incidents documentation.

To return to the incident feed, click the back button on your mobile browser.

Mobile Incident DetailsMobile Incident Details

Mobile Incident Details


Incident Preview

When opening an incident preview on a mobile device, it will open automatically in the BigPanda mobile incident details view.

Learn more about incident previews in the Sharing Incidents documentation

Incident search is available in the mobile incident feed using both keyword and formula queries. To search the incident feed, click the magnifying glass icon at the top right, and enter your query in the field that appears.

Incident information is condensed within the mobile view to maximize visibility of key information such as priority, assignment, severity, and action status. To view a full incident title, description, or tag click the shortened text and a tooltip will appear with the full text.

Mobile Incident Actions

You can take action on incidents using the mobile incident feed. Click the icon for the action you would like to take and the action dialog box will open.

Mobile SharingMobile Sharing

Mobile Sharing

To learn more about incident actions, see the Working with Incidents documentation.