An Instana operator sees multiple simultaneously firing events for high CPU, high memory, and slow response time on the same host in the Events view, but no incident has been created. What is the most likely reason?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Instana does not automatically group individual events into incidents unless specific incident rules have been configured to define which event combinations or patterns should be correlated into a single incident. Without a matching incident rule, the events remain discrete entries in the Events view regardless of how many occur simultaneously. Incidents are not exclusively triggered by SLO breaches—they can be configured for any event pattern—but they do require explicit incident rule configuration.
Full explanation below image
Full Explanation
Instana does not automatically group individual events into incidents unless specific incident rules have been configured to define which event combinations or patterns should be correlated into a single incident. Without a matching incident rule, the events remain discrete entries in the Events view regardless of how many occur simultaneously. Incidents are not exclusively triggered by SLO breaches—they can be configured for any event pattern—but they do require explicit incident rule configuration. The correct answer is 'No incident rule has been configured to group or correlate these events into an incident'. The incorrect options — 'Incidents in Instana must always be created manually by an operator through the web UI', 'Events from different monitoring categories cannot be correlated into a single incident', 'Incidents are only generated automatically when an SLO breach is detected' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 1: Operations domain of the IBM Instana Observability certification.