Replies: 3 comments 1 reply
|
Hi @minrat! I'm Dosu and I'm helping the Keep team. There are two main approaches to write external RCA results back to Keep: direct API calls and Keep Workflows. Option 1: Direct API Calls (from your external LLM/Agent) Enrich an Alert — curl -X POST https://<keep-api>/alerts/enrich \
-H "X-API-KEY: <your-api-key>" \
-H "Content-Type: application/json" \
-d '{
"fingerprint": "<alert-fingerprint>",
"enrichments": {
"rca_analysis": "Root cause: network timeout in upstream service",
"rca_remediation": "Restart pod X"
}
}'The Update an Incident Summary — curl -X PUT "https://<keep-api>/incidents/<incident-id>?generatedByAi=true" \
-H "X-API-KEY: <your-api-key>" \
-H "Content-Type: application/json" \
-d '{
"user_summary": "RCA: Network timeout in upstream service caused cascading failures..."
}'The Option 2: Keep Workflows (Keep calls the external LLM for you) Instead of having the external system call back, you can define a workflow that triggers on an alert, calls your LLM, and writes the result back — all declaratively: workflow:
id: rca-enrichment
triggers:
- type: alert
actions:
- name: run-rca
provider:
type: http
config: "{{ providers.my-http }}"
with:
url: "https://your-llm-service.com/rca"
method: POST
body: '{"alert": "{{ alert.name }}", "description": "{{ alert.description }}"}'
enrich_alert:
- key: rca_analysis
value: "{{ steps.run-rca.results.body.analysis }}"The Authentication: All API calls require the Let me know if you'd like more detail on any of these approaches! To reply, just mention @dosu. Docs are dead. Just use Dosu. |
|
Hi @ dosubot How can I obtain the incident_id? |
|
Hi @ dosubot @ Fingerprint |
Uh oh!
There was an error while loading. Please reload this page.
Keep receives an Alert, and at the same time an Incident is generated. Meanwhile, the Alert is sent via webhook to an external LLM or Agent for RCA analysis. How can the external RCA analysis result be written back to the enriched field of the Alert, or to the Summary of the Incident?
All reactions