Workflow Actions
Workflow Actions
An overview of Incident Workflow actions
Incident Workflows provide a powerful solution for automating your incident response processes, ensuring that your team can respond more quickly and efficiently to critical events. Customize your incident response by selecting from the actions listed below.
Note
Availability
Actions marked in the Pro column are available on the Professional pricing plan.
Actions marked in the Bus column are available on the Business pricing plan.
Actions marked in the EIM column are available on the following pricing plans:
- Enterprise plan for Incident Management
- Enterprise plan for Customer Service
Actions marked in the Essentials column are available on the OpsCloud Essentials pricing plan.
Actions marked in the Plus/Ultimate column are available on the OpsCloud Plus/Ultimate pricing plan.
Contact our Sales Team to upgrade your account plan.
Incident Workflow Actions
Category | Action Name | Description | Pro | Bus | EIM | Essentials | Plus/ Ultimate |
|---|---|---|---|---|---|---|---|
AWS | Enable or disable "Protected from scale-in" on selected instances in an Auto Scaling Group (ASG). | ||||||
Fetch Auto Scaling Group (ASG) membership and lifecycle details for one or more EC2 instances. | |||||||
Retrieve AWS CloudWatch logs by running a CloudWatch Logs Insights query. | |||||||
Invoke an AWS Lambda function with a custom payload. | |||||||
Move one or more EC2 instances in an Auto Scaling Group (ASG) into Standby. | |||||||
Retrieve capacity, health, and instance membership for one or more Auto Scaling Groups (ASGs). | |||||||
Terminate an EC2 instance that belongs to an Auto Scaling Group (ASG). | |||||||
Update configuration values such as min size, max size, desired capacity, or launch template. | |||||||
Azure Functions | Invoke an Azure function with a custom payload. | ||||||
Azure Monitor | Execute a KQL query against an Azure Monitor Log Analytics workspace to retrieve log data within a specified time range. | ||||||
Coralogix | Search for logs in Coralogix within a specified time range. | ||||||
Datadog | Generate a snapshot graph from a metric query. | ||||||
Get the overall status of a monitor. | |||||||
Get the ID of the Datadog monitor that triggered the incident. | |||||||
Retrieve logs from Datadog using search queries and filters. | |||||||
Dynatrace | Retrieve logs from Dynatrace | ||||||
Elasticsearch | Retrieve logs from Elasticsearch | ||||||
Add users to an existing Google chat. | |||||||
Create a new private Google Chat space. | |||||||
Search for log entries in Google Cloud Platform Logging using Logging Query Language (LQL). | |||||||
Create a new Google Meet conference bridge via the Google Workspace Integration. | |||||||
Create a new meeting that anyone in your Google Workspace can join. | |||||||
Grafana | This action retrieves a list of all datasources configured in your Grafana instance. | ||||||
List available Prometheus metric names from a Grafana datasource, optionally scoped by a series selector and lookback window. | |||||||
Execute a PromQL query against a Grafana Prometheus datasource, either as an instant evaluation or as a range query across a time window. | |||||||
Search and retrieve logs from Grafana Loki datasources using LogQL queries. | |||||||
JavaScript | Execute JavaScript code to process data, use conditional logic, perform advanced calculations, and more. | ||||||
Jeli | Create a post-incident review in Jeli. | ||||||
Jira Cloud | Create Jira issues based on the workflow trigger condition(s) and the field options defined in the workflow configuration form. | ||||||
Jira Server | Create Jira issues based on the workflow trigger condition(s) and the field options defined in the workflow configuration form. | ||||||
JSON | Lookup a value in a JSON dictionary. | ||||||
Linear | Linear: Create Issue | Create a new issue in Linear. | |||||
| Linear: Update Issue - Assignee | Update an Assignee in Linear | ||||||
| Linear: Update Issue - Content | Update content in Linear | ||||||
| Linear: Update Issue - Label | Update a label in Linear | ||||||
| Linear: Update Issue - Project | Update project in Linear | ||||||
| Linear: Update Issue - State | Update state in Linear | ||||||
| Linear: Update Priority | Update an existing Linear issue. | ||||||
Logic | Execute a series of steps when a condition is met. | ||||||
Set a time delay before moving to the next step. | |||||||
Execute a series of steps repeatedly until a condition is met. | |||||||
Logz.io | Collect incident data from PagerDuty and use it to initiate a Root Cause Analysis (RCA) in Logz.io. | ||||||
Search for logs in Logz.io using Elasticsearch DSL query syntax within a specified time range. | |||||||
Microsoft Teams | Create a channel within a team in MS Teams. | ||||||
Add a user to an incident in a dedicated chat in Microsoft Teams. | |||||||
Create a Dedicated Chat in MS Teams | |||||||
Add a Microsoft Teams conference bridge to an incident. | |||||||
Link an incident notification channel to an incident | |||||||
New Relic | Search for logs in New Relic using NRQL (New Relic Query Language). | ||||||
PagerDuty Advance | Schedule a Scribe Agent to join incident calls and record key decisions, action items, and events once a conference bridge is available. | ||||||
Update responders every 15 minutes on an incident's status. | |||||||
PagerDuty AIOps | Use the REST API to set the value of an existing Event Orchestration Cache Variable. | (with AIOps add-on) | (with AIOps add-on) | ||||
Use the REST API to remove a specific value from an existing Event Orchestration Cache Variable. | (with AIOps add-on) | (with AIOps add-on) | |||||
Use the REST API to append a specific value to the end of an existing Event Orchestration Cache Variable value. | (with AIOps add-on) | (with AIOps add-on) | |||||
PagerDuty Incident Management | Add a phone number and/or URL to an incident. | ||||||
Add users or escalation policies as responders to an incident. | |||||||
Subscribe Teams or users to status updates for an incident. | |||||||
PagerDuty IM: Assign an Incident Role to an Escalation Policy | Assign an Incident Role to an Escalation Policy to designate the current on-call responder to a specific incident role. | ||||||
Escalate an incident to the next level in an escalation policy. | |||||||
Get Details of a Business Service. | |||||||
Return the name and ID of an on-call user from a schedule. | |||||||
Retrieve the list of users associated with a specific team. | |||||||
Retrieve a list of Business Services that are being impacted by the given Incident. | |||||||
Lists the last 100 related Change Events for an Incident, as well as the reason these changes are correlated with the incident. | |||||||
Post to an External Status Page and notify subscribers. | |||||||
Reassign the incident to a different escalation policy or user. | |||||||
Run a PagerDuty Automation Action. | |||||||
Post an update to the internal status page and notify subscribers. | |||||||
Returns details about a Service. | |||||||
Retrieve all notes associated with an incident | |||||||
Get the set of alerts associated with an incident, as well as alert details for the first alert associated with that incident. | |||||||
Retrieve a specific user. | |||||||
Transition an incident to a new incident type | |||||||
Set the value of a custom field on an incident. | |||||||
Add a note to an existing incident. | |||||||
Mark a business service experiencing impact from a specific incident. | |||||||
Create a new incident on a specified service. | |||||||
Retrieves all status updates for a specified incident, including detailed information about the latest update. | |||||||
Updates incident priority levels enabling automated priority adjustments based on incident conditions, service context, or time-based triggers. | |||||||
Automatically pauses the workflow until the incident meets the specified status. | |||||||
Roles | Assign an Incident Role to a User. | ||||||
Remove the user assigned to a role, leaving it unassigned. | |||||||
Sentry | Search Sentry for error events during incident triage. | ||||||
ServiceNow | Create a ServiceNow Incident. | ||||||
Retrieve runbook or knowledge article content. | |||||||
Slack | Archives an incident's dedicated channel in a Slack workspace. | ||||||
Add important links to a Slack channel header. | |||||||
Create a new Slack channel for an incident. | |||||||
Link an existing Slack channel to an incident. | |||||||
Send a Slack message to a channel with a button to add a note for the incident. | |||||||
Send a Slack message to a channel with a button to Add Responders to the incident. | |||||||
Send a Slack message to a channel with a button to escalate the incident. | |||||||
Send a Slack message to a channel with a button to reassign the incident. | |||||||
Send a Slack message to a channel with a button to run an Automation Action on the incident. | |||||||
Send a Slack message to a channel with a button to run an Incident Workflow on the incident. | |||||||
Send a Slack message to a channel with a button to send a status update for the incident. | |||||||
Send a Slack message to a channel with a button to update the priority on the incident. | |||||||
Send a message to a Slack user. | |||||||
Send a temporary message, visible only to a specific user. | |||||||
Send a message to a Slack channel. | |||||||
Send a message to a channel in Slack with an Incident Action. | |||||||
Set a Slack channel's topic. | |||||||
Rename a Slack channel. | |||||||
Splunk | Search and retrieve logs from Splunk. | ||||||
Sumo Logic | Search and retrieve logs from Sumo Logic. | ||||||
Tasks | Create and assign an Incident Task to a responder on an incident. | ||||||
Update the user assigned to an Incident Task. | |||||||
Update the details of an Incident Task. | |||||||
Update the name of an Incident Task. | |||||||
Update the status of an Incident Task. | |||||||
Text | Generates a random adjective from a list of positive adjectives. | ||||||
Generates a random animal from a list of animals. | |||||||
Generates a random color from a list of colors. | |||||||
Web API | Sends a DELETE request to a given URL with given headers. | ||||||
Sends a GET request to a given URL with given headers. | |||||||
Sends a HEAD request to a given URL with given headers. | |||||||
Sends a PATCH request to a given URL with given headers and body. | |||||||
Sends a POST request to a given URL with given headers and body. | |||||||
Sends a PUT request to a given URL with given headers and body. | |||||||
Send a POST request with a customized body and headers. | |||||||
Zoom | Add a Zoom Meeting to an incident. |
IP Addresses
Incident Workflow actions that make external HTTP requests, including Web API actions (e.g., Send GET Request, Send POST Request, etc.), will originate from the list of IP addresses in our developer documentation Webhook IPs.