|docs
Start Trial

Workflow Actions

Workflow Actions

An overview of Incident Workflow actions

Incident Workflows provide a powerful solution for automating your incident response processes, ensuring that your team can respond more quickly and efficiently to critical events. Customize your incident response by selecting from the actions listed below.

Note

Availability

Actions marked in the Pro column are available on the Professional pricing plan.

Actions marked in the Bus column are available on the Business pricing plan.

Actions marked in the EIM column are available on the following pricing plans:

  • Enterprise plan for Incident Management
  • Enterprise plan for Customer Service

Actions marked in the Essentials column are available on the OpsCloud Essentials pricing plan.

Actions marked in the Plus/Ultimate column are available on the OpsCloud Plus/Ultimate pricing plan.

Contact our Sales Team to upgrade your account plan.

Incident Workflow Actions

Category

Action Name

Description

Pro

Bus

EIM

Essentials

Plus/ Ultimate

AWS

AWS: Enable or Disable Instance Protection in an ASG

Enable or disable "Protected from scale-in" on selected instances in an Auto Scaling Group (ASG).

AWS: Fetch ASG Membership and Lifecycle Details

Fetch Auto Scaling Group (ASG) membership and lifecycle details for one or more EC2 instances.

AWS: Get CloudWatch Logs by Query

Retrieve AWS CloudWatch logs by running a CloudWatch Logs Insights query.

AWS: Invoke a Lambda Function

Invoke an AWS Lambda function with a custom payload.

AWS: Move Auto Scaling Group Into Standby

Move one or more EC2 instances in an Auto Scaling Group (ASG) into Standby.

AWS: Retrieve Capacity, Health, and Instance of ASG

Retrieve capacity, health, and instance membership for one or more Auto Scaling Groups (ASGs).

AWS: Terminate an EC2 Instance Belonging to an ASG

Terminate an EC2 instance that belongs to an Auto Scaling Group (ASG).

AWS: Update ASG Configuration Values

Update configuration values such as min size, max size, desired capacity, or launch template.

Azure Functions

Azure: Invoke an Azure Function

Invoke an Azure function with a custom payload.

Azure Monitor

Azure Monitor: Query Logs

Execute a KQL query against an Azure Monitor Log Analytics workspace to retrieve log data within a specified time range.

Coralogix

Coralogix: Search Logs

Search for logs in Coralogix within a specified time range.

Datadog

Datadog: Create a Graph Snapshot

Generate a snapshot graph from a metric query.

Datadog: Get a Monitor's Details

Get the overall status of a monitor.

Datadog: Get the Alerting Monitor

Get the ID of the Datadog monitor that triggered the incident.

Datadog: Search Logs

Retrieve logs from Datadog using search queries and filters.

Dynatrace

Dynatrace: Search Logs

Retrieve logs from Dynatrace

Elasticsearch

Elasticsearch: Search Logs

Retrieve logs from Elasticsearch

Google

Google Chat: Add Member to Google Chat Space

Add users to an existing Google chat.

Google Chat: Create a Google Chat Private Space

Create a new private Google Chat space.

Google Cloud Platform: Search Logs

Search for log entries in Google Cloud Platform Logging using Logging Query Language (LQL).

Google Meet: Add a Conference Bridge to an Incident

Create a new Google Meet conference bridge via the Google Workspace Integration.

Google Meet: Create a Meeting

Create a new meeting that anyone in your Google Workspace can join.

Grafana

Grafana: Get Datasources

This action retrieves a list of all datasources configured in your Grafana instance.

Grafana: List Metrics

List available Prometheus metric names from a Grafana datasource, optionally scoped by a series selector and lookback window.

Grafana: Query Metrics

Execute a PromQL query against a Grafana Prometheus datasource, either as an instant evaluation or as a range query across a time window.

Grafana: Search Logs

Search and retrieve logs from Grafana Loki datasources using LogQL queries.

JavaScript

JavaScript: Run Code

Execute JavaScript code to process data, use conditional logic, perform advanced calculations, and more.

Jeli

Jeli: Create A Post-Incident Review

Create a post-incident review in Jeli.

Jira Cloud

Jira Cloud: Create an Issue for an Incident

Create Jira issues based on the workflow trigger condition(s) and the field options defined in the workflow configuration form.

Jira Server

Jira Server: Create an Issue for an Incident

Create Jira issues based on the workflow trigger condition(s) and the field options defined in the workflow configuration form.

JSON

JSON: Lookup Value by Key

Lookup a value in a JSON dictionary.

Linear

Linear: Create Issue

Create a new issue in Linear.

Linear: Update Issue - Assignee

Update an Assignee in Linear

Linear: Update Issue - Content

Update content in Linear

Linear: Update Issue - Label

Update a label in Linear

Linear: Update Issue - Project

Update project in Linear

Linear: Update Issue - State

Update state in Linear

Linear: Update Priority

Update an existing Linear issue.

Logic

Logic: Condition

Execute a series of steps when a condition is met.

Logic: Delay

Set a time delay before moving to the next step.

Logic: Loop Until

Execute a series of steps repeatedly until a condition is met.

Logz.io

Logz.io: Initiate RCA in Logz.io

Collect incident data from PagerDuty and use it to initiate a Root Cause Analysis (RCA) in Logz.io.

Logz.io: Search Logs

Search for logs in Logz.io using Elasticsearch DSL query syntax within a specified time range.

Microsoft Teams

MS Teams: Create a Channel

Create a channel within a team in MS Teams.

MS Teams: Add User to Incident Dedicated Chat

Add a user to an incident in a dedicated chat in Microsoft Teams.

MS Teams: Create a Dedicated Chat in Microsoft Teams

Create a Dedicated Chat in MS Teams

MS Teams: Create Conference Bridge in Microsoft Teams

Add a Microsoft Teams conference bridge to an incident.

MS Team: Link Notification Channel

Link an incident notification channel to an incident

New Relic

New Relic: Search Logs

Search for logs in New Relic using NRQL (New Relic Query Language).

PagerDuty Advance

PagerDuty Advance: Add PagerDuty Advance Scribe Agent

Schedule a Scribe Agent to join incident calls and record key decisions, action items, and events once a conference bridge is available.

PagerDuty Advance: Add Periodic Incident Progress

Update responders every 15 minutes on an incident's status.

PagerDuty AIOps

PagerDuty AIOps: Set a Cache Variable Value

Use the REST API to set the value of an existing Event Orchestration Cache Variable.

(with AIOps add-on)

(with AIOps add-on)

PagerDuty AIOps: Remove from a Cache Variable Value

Use the REST API to remove a specific value from an existing Event Orchestration Cache Variable.

(with AIOps add-on)

(with AIOps add-on)

PagerDuty AIOps: Append to a Cache Variable Value

Use the REST API to append a specific value to the end of an existing Event Orchestration Cache Variable value.

(with AIOps add-on)

(with AIOps add-on)

PagerDuty Incident Management

PagerDuty IM: Add Conference Bridge

Add a phone number and/or URL to an incident.

PagerDuty IM: Add Responders

Add users or escalation policies as responders to an incident.

PagerDuty IM: Add Stakeholders

Subscribe Teams or users to status updates for an incident.

PagerDuty IM: Assign an Incident Role to an Escalation Policy

Assign an Incident Role to an Escalation Policy to designate the current on-call responder to a specific incident role.

PagerDuty IM: Escalate Incident to Next Level

Escalate an incident to the next level in an escalation policy.

PagerDuty IM: Get Business Service Details

Get Details of a Business Service.

PagerDuty IM: Get On-Call User from a Schedule

Return the name and ID of an on-call user from a schedule.

PagerDuty IM: Get Users on a Team

Retrieve the list of users associated with a specific team.

PagerDuty IM: List Impacted Business Services

Retrieve a list of Business Services that are being impacted by the given Incident.

PagerDuty IM: List Related Change Events for an Incident

Lists the last 100 related Change Events for an Incident, as well as the reason these changes are correlated with the incident.

PagerDuty IM: Post to External Status Page

Post to an External Status Page and notify subscribers.

PagerDuty IM: Reassign the Incident

Reassign the incident to a different escalation policy or user.

PagerDuty IM: Run an Automation Action

Run a PagerDuty Automation Action.

PagerDuty IM: Send Status Update

Post an update to the internal status page and notify subscribers.

PagerDuty IM: Get Service Details

Returns details about a Service.

PagerDuty IM: Get Notes for an Incident

Retrieve all notes associated with an incident

PagerDuty IM: Get Alerts for an Incident

Get the set of alerts associated with an incident, as well as alert details for the first alert associated with that incident.

PagerDuty IM: Get User

Retrieve a specific user.

PagerDuty IM: Update Incident Type

Transition an incident to a new incident type

PagerDuty IM: Set Incident Custom Field

Set the value of a custom field on an incident.

PagerDuty IM: Add Note to an Incident

Add a note to an existing incident.

PagerDuty IM: Add an Impacted Business Service

Mark a business service experiencing impact from a specific incident.

PagerDuty IM: Create an Incident

Create a new incident on a specified service.

PagerDuty IM: Get Status Updates for an Incident

Retrieves all status updates for a specified incident, including detailed information about the latest update.

PagerDuty IM: Update Incident Priority

Updates incident priority levels enabling automated priority adjustments based on incident conditions, service context, or time-based triggers.

PagerDuty IM: Wait For Status To Change

Automatically pauses the workflow until the incident meets the specified status.

Roles

PagerDuty Roles: Assign a Role

Assign an Incident Role to a User.

PagerDuty Roles: Unassign a Role

Remove the user assigned to a role, leaving it unassigned.

Sentry

Sentry: Search Logs

Search Sentry for error events during incident triage.

ServiceNow

ServiceNow ITSM: Create an Incident

Create a ServiceNow Incident.

ServiceNow: Retrieve Runbook or KB Article

Retrieve runbook or knowledge article content.

Slack

Slack: Archive Incident Dedicated Channel

Archives an incident's dedicated channel in a Slack workspace.

Slack: Add a Bookmark

Add important links to a Slack channel header.

Slack: Create a Slack Channel for an Incident

Create a new Slack channel for an incident.

Slack: Link a Slack Channel to an Incident

Link an existing Slack channel to an incident.

Slack: Prompt to Add a Note to the Incident

Send a Slack message to a channel with a button to add a note for the incident.

Slack: Prompt to Add Responders to the Incident

Send a Slack message to a channel with a button to Add Responders to the incident.

Slack: Prompt to Escalate the Incident

Send a Slack message to a channel with a button to escalate the incident.

Slack: Prompt to Reassign the Incident

Send a Slack message to a channel with a button to reassign the incident.

Slack: Prompt to Run an Automation Action on the Incident

Send a Slack message to a channel with a button to run an Automation Action on the incident.

Slack: Prompt to Run an Incident Workflow on the Incident

Send a Slack message to a channel with a button to run an Incident Workflow on the incident.

Slack: Prompt to Send a Status Update for the Incident

Send a Slack message to a channel with a button to send a status update for the incident.

Slack: Prompt to Update Priority on the Incident

Send a Slack message to a channel with a button to update the priority on the incident.

Slack: Send a Direct Message

Send a message to a Slack user.

Slack: Send an Ephemeral Message

Send a temporary message, visible only to a specific user.

Slack: Send a Message to a Channel

Send a message to a Slack channel.

Slack: Send a Message to a Channel with an Incident Action

Send a message to a channel in Slack with an Incident Action.

Slack: Set a Channel Topic

Set a Slack channel's topic.

Slack: Rename a Slack Channel

Rename a Slack channel.

Splunk

Splunk: Search Logs

Search and retrieve logs from Splunk.

Sumo Logic

Sumo Logic: Search Logs

Search and retrieve logs from Sumo Logic.

Tasks

PagerDuty Tasks: Create a Task

Create and assign an Incident Task to a responder on an incident.

PagerDuty Tasks: Update Task Assignee

Update the user assigned to an Incident Task.

PagerDuty Tasks: Update Task Details

Update the details of an Incident Task.

PagerDuty Tasks: Update Task Name

Update the name of an Incident Task.

PagerDuty Tasks: Update Task Status

Update the status of an Incident Task.

Text

Text: Generate Random Positive Adjective

Generates a random adjective from a list of positive adjectives.

Text: Generate Random Animal

Generates a random animal from a list of animals.

Text: Generate Random Color

Generates a random color from a list of colors.

Web API

Web API: Send DELETE Request

Sends a DELETE request to a given URL with given headers.

Web API: Send GET Request

Sends a GET request to a given URL with given headers.

Web API: Send HEAD Request

Sends a HEAD request to a given URL with given headers.

Web API: Send PATCH Request

Sends a PATCH request to a given URL with given headers and body.

Web API: Send POST Request

Sends a POST request to a given URL with given headers and body.

Web API: Send PUT Request

Sends a PUT request to a given URL with given headers and body.

Web API: Send a Webhook POST

Send a POST request with a customized body and headers.

Zoom

Zoom: Create a Zoom Meeting

Add a Zoom Meeting to an incident.

IP Addresses

Incident Workflow actions that make external HTTP requests, including Web API actions (e.g., Send GET Request, Send POST Request, etc.), will originate from the list of IP addresses in our developer documentation Webhook IPs.