Documentation for automated readers
A curated documentation index is available at: https://grafana.com/llms.txt
A complete documentation index is available at: https://grafana.com/llms-full.txt
These indexes can help with page discovery before fetching individual documents.
This page is also available in Markdown, which may be easier for automated readers and AI tools to parse than HTML. The Markdown version is available at https://grafana.com/docs/grafana-cloud/observe-and-act/respond-to-incidents/manage-incidents/investigate.md, or by sending Accept: text/markdown to https://grafana.com/docs/grafana-cloud/observe-and-act/respond-to-incidents/manage-incidents/investigate/. For broader documentation discovery, the curated index is available at https://grafana.com/llms.txt and the complete index is available at https://grafana.com/llms-full.txt.
Investigate incidents
During an incident, you can add notes, dashboard panels, and queries to the incident timeline so responders share the same context. Grafana IRM no longer starts Sift investigations from the incident view.
This topic explains how investigation works in an incident today, and where to find Sift results that were saved before this change.
Investigate from an incident
Use the incident timeline to collect what you learn as you work:
- Add notes, queries, and dashboard panels so other responders can follow your investigation.
- Attach links and images that point to runbooks, dashboards, or related alerts.
For steps, refer to Use the incident timeline.
You can also send incident or alert group events to Grafana Assistant with an outgoing webhook. For details, refer to Outgoing webhooks and Grafana Assistant investigations.
Sift results in incidents
Sift remains available in Grafana Cloud through the Machine Learning plugin. The incident sidebar no longer includes a Sift Suggestions panel, and IRM no longer starts Sift from an incident.
To run a new Sift investigation, open Sift in Grafana Cloud.
You can still trigger Sift from an alert group event with the Grafana Sift for alert groups outgoing webhook preset. For details, refer to Outgoing webhooks.
View historical Sift results
If an incident already has Sift results or suggestions in its activity log, those entries stay available.
To review them:
- Open the incident.
- Scan the activity log for Sift investigation or Sift Suggestion entries.
- Open an entry to view the saved analysis.
Related documentation
Was this page helpful?
Related resources from Grafana Labs


