Alert Runbooks
Alert Runbooks
7 skills in Alert Runbooks.
7 skills in this category.
AV/EDR Agent Offline Alert
Triage an "endpoint protection agent not reporting" alert from any AV/EDR product — decide whether the device is off or up-with-a-dead-agent, quantify how long the endpoint has been unprotected, and route on that protection-gap. Use for agent-offline, agent-not-checked-in, or sensor-unhealthy alerts.
Backup Missed vs Failed Alert
Distinguish a backup job that never ran (missed) from one that ran and errored (failed) — two different diagnoses and routes — and always state the client's actual exposure via last-known-good. Use when a backup alert is ambiguous about whether the job executed at all.
Certificate Expiry Alert
Triage a certificate-expiring/expired alert — tier urgency by days remaining, identify what the certificate secures and who owns renewal, and route into the renewal work. Use when a cert-expiry alert fires from monitoring, Liongard, or a vendor console.
Disk Space Alert
Triage a low-disk-space alert regardless of which monitor raised it — separate threshold noise from real pressure, read the growth rate from the alert history, and route with ranked consumer hypotheses. Use when a disk/volume-space alert lands and needs a verdict, not yet a cleanup.
High CPU/Memory Alert
Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure using alert history, offer top-consumer hypotheses by device role, and route servers vs workstations differently. Use when a performance-threshold alert lands from any monitor.
Patch Failure Alert
Triage a patch/update-failure alert — separate a one-off the next cycle will fix from a repeat offender, detect reboot-pending as the usual culprit, and correlate against the device's patch window. Use when a patch-failed or update-failed alert lands, from any patch engine.
RAID Degradation Alert
Triage a RAID degraded/failed-member alert with zero-margin urgency — a degraded array is one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule. Use for any degraded-array, failed-disk-in-array, or rebuild alert from a server, NAS, or storage controller.
Was this page helpful?
⌘I