Grafana Cloud
Last reviewed: August 19, 2026

Investigate incidents

During an incident, you can add notes, dashboard panels, and queries to the incident timeline so responders share the same context. Grafana IRM no longer starts Sift investigations from the incident view.

This topic explains how investigation works in an incident today, and where to find Sift results that were saved before this change.

Investigate from an incident

Use the incident timeline to collect what you learn as you work:

  • Add notes, queries, and dashboard panels so other responders can follow your investigation.
  • Attach links and images that point to runbooks, dashboards, or related alerts.

For steps, refer to Use the incident timeline.

You can also send incident or alert group events to Grafana Assistant with an outgoing webhook. For details, refer to Outgoing webhooks and Grafana Assistant investigations.

Sift results in incidents

Sift remains available in Grafana Cloud through the Machine Learning plugin. The incident sidebar no longer includes a Sift Suggestions panel, and IRM no longer starts Sift from an incident.

To run a new Sift investigation, open Sift in Grafana Cloud.

You can still trigger Sift from an alert group event with the Grafana Sift for alert groups outgoing webhook preset. For details, refer to Outgoing webhooks.

View historical Sift results

If an incident already has Sift results or suggestions in its activity log, those entries stay available.

To review them:

  1. Open the incident.
  2. Scan the activity log for Sift investigation or Sift Suggestion entries.
  3. Open an entry to view the saved analysis.