alert_triage_rca
Triage active Prism alerts: get per-severity counts, flag unacknowledged critical alerts, and identify the oldest unresolved alert with its age.
Instructions
[READ] Triage active Prism alerts: per-severity counts + oldest unresolved.
Groups every unresolved alert by severity with a count per level, flags
critical alerts nobody has acknowledged, and surfaces the oldest unresolved
alert with its age in days (aged against the newest alert in the same feed,
so the analysis is clock-free and reproducible). Use analyze_alert on an
individual extId for the per-alert event correlation.
Args:
target: Prism Central target name from config; omit for the default.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No |