Skip to main content
Glama

get_alert

Read-onlyIdempotent

Retrieve full details for a single alert by UUID, including triggered symptoms and resource information. Use after list_alerts to drill into one alert's impact and status.

Instructions

[READ] Get full details for one alert by UUID, including its contributing (triggered) symptoms. Use this after list_alerts to drill into a single alert; use list_alerts to discover or filter them. Returns one alert object: name, criticality, status, impact, resource_id, start/update/cancel timestamps (epoch ms, and *_time_utc ISO-8601; cancel_time_utc is null when never cancelled), control state, and symptoms (each with the condition that triggered it, and the object it is on: resource_id, resource_name, resource_kind, stat_key — for "vCenter appliance health service is down" that names the service, e.g. mem). resource_lookup says how that was found (not_needed / resolved / not_found / failed / no_symptom_id / instance_names_no_resource); a "symptom_resources_note" key appears when some could not be — an empty resource_id there is unknown, not absent. Cost: on Aria 8.18.7 no symptom carries its resource id, so every call pages GET /symptoms (one request per 1,000 symptoms in the appliance, at most 20, stopping once all are found) plus one batched GET /resources. Gotcha: an empty symptoms list normally means the alert has no triggered symptoms, but if a "symptoms_note" key is present the list is UNKNOWN rather than empty — the response shape was unrecognised or the lookup failed, so do not tell the user the alert fired for no reason. Symptom name and severity come from the symptom definition when the instance carries none; each symptom's definition_lookup says whether that worked (resolved / not_needed / not_found / failed / no_definition_id), and a "symptom_definitions_note" key appears when some did not — an empty name there is unknown, not blank. The Alert model does not carry a resource name — resolve it via get_resource(resource_id), or call investigate_alert to do that correlation in one step. Recommendations hang off the alert definition, not the alert. To act on the alert afterwards, use acknowledge_alert or cancel_alert.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
targetNoAria target name from config; default when omitted.
alert_idYesThe alert UUID (from list_alerts).

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv1.10.0
    • addedInput schema / additionalProperties
      Added value: +false
    • addedInput schema / properties / alert_id / description
      Added value: +"The alert UUID (from list_alerts)."
    • addedInput schema / properties / target / description
      Added value: +"Aria target name from config; default when omitted."
  2. Addedv1.5.29
  3. Removedv1.5.28
  4. First observedv1.3.2

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

While annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint=false, the description adds significant behavioral context: it details the cost (paging through symptoms, batching), the gotchas around empty vs. unknown lists (symptoms_note, symptom_definitions_note), the fact that the Alert model does not carry a resource name, and where recommendations live. This goes far beyond the annotations and provides crucial runtime behavior. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but every sentence carries important information, covering purpose, usage, return details, cost, gotchas, and related tools. It is front-loaded with the core purpose and then organized logically. While it is verbose, it is not redundant or wasteful, and the length is justified given the complexity of the tool. A score of 4 reflects its efficiency for its length.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description is exceptionally complete. With no output schema, it explains the full return shape (fields like name, criticality, status, symptoms, notes), the cost implications, edge cases (unknown vs. empty), and relationships to other tools (get_resource, investigate_alert, acknowledge_alert, cancel_alert). It covers everything an agent needs to invoke the tool correctly and interpret the results, making it fully contextual.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema covers both parameters with 100% description coverage: alert_id is described as 'The alert UUID (from list_alerts)' and target as 'Aria target name from config; default when omitted.' The description adds a small clarification that alert_id comes from list_alerts, but it does not significantly expand on the schema. Since the schema already provides full parameter documentation, a baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's specific purpose: 'Get full details for one alert by UUID, including its contributing (triggered) symptoms.' It distinguishes itself from list_alerts by explicitly saying to use it after list_alerts for drilling into a single alert, and it names the sibling investigate_alert for correlation. This leaves no ambiguity about what the tool does.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly provides usage guidance: 'Use this after list_alerts to drill into a single alert; use list_alerts to discover or filter them.' It also mentions alternative tools for acting on the alert (acknowledge_alert, cancel_alert) and for resolving resource names (get_resource, investigate_alert). This clearly indicates when to use this tool vs. alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.