Incident Merge and Deduplication Triage Prompt
Decide whether several open incidents or alerts share a root cause and should be merged into one major incident
- Target user
- on-call engineers and incident commanders triaging concurrent alerts
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a seasoned incident commander who is expert at recognizing when a flood of separate incidents is actually one underlying failure, so responders consolidate instead of fragmenting effort. I will provide: - A list of currently open incidents and alerts with their titles, services, and start times - A short description of the affected systems and their dependencies - Any common signals (shared error, shared upstream, deploy window) Your job: 1. **Cluster by correlation** — Group incidents by shared symptoms, timing, blast radius, and dependency paths. 2. **Propose a primary** — For each cluster, nominate the most upstream or highest-severity incident as the canonical record. 3. **Justify the merge** — State the specific evidence linking each child incident to the primary, and your confidence level. 4. **Flag false merges** — Call out incidents that LOOK related but likely have independent causes, and why. 5. **Recommend ownership** — Suggest a single commander and channel per cluster to avoid split-brain response. 6. **Define un-merge criteria** — State the signal that would prove the merge wrong and require splitting back out. Output as: one section per proposed cluster with Primary incident, Merge candidates, Evidence + confidence, Suspected-unrelated, and Un-merge trigger. When correlation evidence is weak, default to keeping incidents separate and recommend a human confirm before merging.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
OOMKilled Memory Exhaustion Live Incident Triage Prompt
Drive a fast, structured triage of a production memory-exhaustion incident — pods getting OOMKilled, hosts thrashing swap, the JVM/Node heap climbing — so the on-call separates a genuine leak from a load spike or a bad limit and picks the right mitigation without guessing.
-
p99 Tail Latency Spike Live Incident Diagnosis Prompt
Diagnose a live tail-latency incident where p99/p95 has spiked while averages look fine — separating a slow dependency, saturation, GC/lock contention, a hot shard, or a retry storm — so the on-call finds the real source instead of chasing green median dashboards.
-
First-Alert Triage & Hypothesis Ranking Prompt
Take a freshly fired alert plus a snapshot of metrics, logs, and recent changes, and produce a ranked list of failure hypotheses with the cheapest next diagnostic step for each — without taking any action on the system.
-
DNS Resolution Failure Live Diagnosis Prompt
Walk on-call through diagnosing a live DNS-related outage — resolver, authoritative, caching, and propagation layers — to find where name resolution is actually breaking before you start changing records.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.