get_alert
Retrieve full details for a single alert by UUID, including triggered symptoms and resource information. Use after list_alerts to drill into one alert's impact and status.
Instructions
[READ] Get full details for one alert by UUID, including its contributing (triggered) symptoms. Use this after list_alerts to drill into a single alert; use list_alerts to discover or filter them. Returns one alert object: name, criticality, status, impact, resource_id, start/update/cancel timestamps (epoch ms, and *_time_utc ISO-8601; cancel_time_utc is null when never cancelled), control state, and symptoms (each with the condition that triggered it, and the object it is on: resource_id, resource_name, resource_kind, stat_key — for "vCenter appliance health service is down" that names the service, e.g. mem). resource_lookup says how that was found (not_needed / resolved / not_found / failed / no_symptom_id / instance_names_no_resource); a "symptom_resources_note" key appears when some could not be — an empty resource_id there is unknown, not absent. Cost: on Aria 8.18.7 no symptom carries its resource id, so every call pages GET /symptoms (one request per 1,000 symptoms in the appliance, at most 20, stopping once all are found) plus one batched GET /resources. Gotcha: an empty symptoms list normally means the alert has no triggered symptoms, but if a "symptoms_note" key is present the list is UNKNOWN rather than empty — the response shape was unrecognised or the lookup failed, so do not tell the user the alert fired for no reason. Symptom name and severity come from the symptom definition when the instance carries none; each symptom's definition_lookup says whether that worked (resolved / not_needed / not_found / failed / no_definition_id), and a "symptom_definitions_note" key appears when some did not — an empty name there is unknown, not blank. The Alert model does not carry a resource name — resolve it via get_resource(resource_id), or call investigate_alert to do that correlation in one step. Recommendations hang off the alert definition, not the alert. To act on the alert afterwards, use acknowledge_alert or cancel_alert.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | Aria target name from config; default when omitted. | |
| alert_id | Yes | The alert UUID (from list_alerts). |