Skip to main content
Some signals flap: they fire, auto-resolve when the monitor recovers, then fire again minutes later, over and over. Without help, one flapping signal buries your alert list in duplicates and pages you on every cycle. Warrn folds those rapid repeats into a single alert, called an episode, without hiding or discarding anything.

Episodes

When a signal re-fires shortly after it auto-resolved, Warrn reopens the same alert instead of creating a new one. The alert’s occurrence count climbs, the timeline records every open and auto-resolve cycle, and anything attached to it (your acknowledgment, assignment, comments) stays put. An episode ends when either:
  • A person resolves the alert. The next matching fire is a brand-new alert. Resolving is how you say “this problem is done.”
  • The signal goes quiet past the re-fire window (5 minutes for critical alerts by default, up to 30 minutes for low). A fire after a real quiet gap is treated as a new problem, not a continuation.
Only automatic resolutions are folded together. If you resolved an alert yourself and it fires again, that is real news, so it becomes a new alert and pages normally.

When you get paged

Three behaviors are fixed:
  • A new alert always pages: the first fire, a fire after a real quiet gap, or a fire after a person resolved.
  • A repeat that merges into an already open or acknowledged alert never pages again; it just raises the occurrence count.
  • A snoozed alert never pages, whatever the settings say, until the snooze ends.
Everything else is a setting, per severity:

Controls on the alert

  • Resolve ends the episode. The next matching fire starts fresh and pages.
  • Keep open pins the alert so monitor recoveries and integration resolves cannot auto-close it. Acknowledging an alert pins it automatically, so nothing closes an alert while you are investigating it. Un-acknowledging releases the automatic pin; a pin you set by hand stays until you clear it with Allow auto-resolve.
  • Snooze paging (1h, 3h, 12h, or 24h) stops pages for that alert while everything else keeps working: re-fires still reopen it, counts still climb, and it stays visible in the list and the weekly digest. Resume paging ends the snooze early. Nothing is ever muted permanently or dropped.

Settings

Everything above lives in Settings → Incident Policies → Alert noise: a master toggle for episode grouping, the per-severity table, and an Advanced section holding auto-snooze and episode safety caps (an episode seals and starts fresh after 100 occurrences or 24 hours, so one runaway signal cannot grow a single endless alert). The same page also has Auto-group similar alerts. This is separate from episodes: episodes join exact re-fires of one signal, while auto-grouping nests different alerts that are at least 95% similar and belong to the same team and service. The setting applies across the organisation. See Auto-grouping. Until an administrator saves different values, Warrn applies the defaults above directly. They are built-in policy defaults, not rows created by a migration. Episodes contain the noise minute to minute. The weekly digest is the other half: a ranked weekly report of the monitors worth going to fix.