Agent skill

Dt Alerting

by Dynatrace in Dynatrace/dynatrace-for-ai

End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

Apache-2.0Auto-check passedDevelopment

Install Dt Alerting

skills CLI
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dynatrace/dynatrace-for-ai dt-alerting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-alerting .claude/skills/dt-alerting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dt-alerting
GitHub stars
163
Token cost
~3.3k tokens
SKILL.md length
1,240 words
Files
4 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

  • Works in 7 steps: Match the model to the metric's behavior… → Scope detectors narrowly — An entity… → Tune sensitivity before going to… → …
  • Configuring alerting
  • SKILL.md covers The Alerting Lifecycle, When to Use This Skill, Agent Instructions and Prerequisites, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dt Alerting is an agent skill from Dynatrace/dynatrace-for-ai. End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and denoising by root cause analysis, and workflow-based notification routing (email, Slack, ServiceNow, webhook). Use when configuring alerting, choosing between detector types, querying alert event history, understanding why alerts merged into a problem, or setting up problem-triggered notifications.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anomaly-detectors.md`, `references/davis-events.md` and `references/workflow-notifications.md`).

It sits in Development, covering Root cause analysis and Webhooks. It works with Slack and ServiceNow. The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.

When your agent uses it

  • Configuring alerting
  • Choosing between detector types
  • Querying alert event history
  • Understanding why alerts merged into a problem

Example prompts

  • “/dt-alerting”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Match the model to the metric's behavior — Use static for hard SLO
  2. Scope detectors narrowly — An entity selector that covers only relevant
  3. Tune sensitivity before going to production — Start with LOW sensitivity
  4. Let Davis denoise before notifying — Trigger workflow notifications on
  5. Filter notifications by severity level — Route event.severity <= 2 problems to
  6. Use dt.alert_group event property for routing — Assign dt.alert_group to route alerts to the right team. Either set a static value in the…
  7. Combine same-condition alerts into one detector and one workflow — When

What it can do on your machine

Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are dql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dt Alerting loads about 3.3k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 1,240 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~26k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 1,240 words, ~3,250 tokens.

Download SKILL.mdSave it as .claude/skills/dt-alerting/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
dt-alerting
description
End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and denoising by root cause analysis, and workflow-based notification routing (email, Slack, ServiceNow, webhook). Use when configuring alerting, choosing between detector types, querying alert event history, understanding why alerts merged into a problem, or setting up problem-triggered notifications.
license
Apache-2.0

dt-alerting

Configure and understand the full alerting lifecycle in Dynatrace — from anomaly detector setup through Grail event storage, problem grouping, and workflow notification delivery.

The Alerting Lifecycle

┌─────────────────────────────────────────────────────────────────────┐
│  Alert Sources — five categories, each fires a DAVIS_EVENT          │
│  ─────────────────────────────────────────────────────────────────  │
│  1. DQL-based  · Grail-scheduled server-side detector               │
│  2. Edge       · OneAgent on monitored host or process              │
│  3. Pipeline   · OpenPipeline ingest-stream filter matcher          │
│  4. Synthetic  · Worldwide synthetic checker node                   │
│  5. External   · Events API, Workflow, or OneAgent local ingest     │
└──────────────────────────────┬──────────────────────────────────────┘
                               │ DAVIS_EVENT created per trigger per entity
                               ▼
             ┌─────────────────────────────────────┐
             │  Event stored in Grail              │  Persisted and queryable via DQL.
             └──────────────────┬──────────────────┘  One event per trigger per entity.
                                │ correlated by root-cause and impact graph
                                ▼
             ┌─────────────────────────────────────┐
             │  Problem (Denoising)                │  Events sharing the same root-cause
             └──────────────────┬──────────────────┘  and impact graph → one Problem.
                                │ problem event triggers workflow
                                ▼
             ┌─────────────────────────────────────┐
             │  Workflow Notification              │  Filters problems and routes to
             └─────────────────────────────────────┘  email, Slack, ServiceNow, webhook.

When to Use This Skill

  • Detector setup — "How do I create an anomaly detector?", "What kind of detector should I use?", "What is the difference between adaptive and seasonal?"
  • Alert event history — "Query all alert events for this service", "Show me which metrics triggered alerts last week"
  • Problem denoising — "Why did these two alerts merge into one problem?", "How does Davis group alerts?"
  • Notification setup — "How do I send a Slack message when a problem opens?", "Set up a ServiceNow ticket on critical problems"
  • Best practices — "How do I avoid alert storms?", "Which sensitivity setting should I use?"
  • Over-alerting analysis — "Why am I getting too many alerts?", "How do I reduce alert fatigue?", "Which detector is firing the most?", "How do I tune sensitivity or thresholds to avoid noise?"
  • Notification routing — "How do I route alerts to the right team?", "Set up scalable problem filters in workflows", "Send Slack notifications only to the team responsible for the affected service"

Agent Instructions

First step for any alerting setup request — Before recommending a specific detector or model, load references/anomaly-detectors.md and use its category and model decision guide to identify which detector category (DQL-based, Edge, Pipeline, Synthetic, External) and which model (Static, Adaptive, Seasonal) best fits the user's use-case. Only proceed with configuration guidance once the right detector type has been established.

Consolidate, don't multiply — When a user asks to alert on multiple entities of the same kind (e.g. "alert on services A, B, and C"), always recommend a single combined detector rather than one detector per entity. Use by: { <dimension> } in the DQL timeseries call to split results per entity, and a single filter: clause to scope to the relevant entities. Pair the combined detector with a single dt.alert_group tag shared across all alert conditions and the corresponding workflow notification filter. This keeps the number of detector configs small, ensures consistent routing, and makes the workflow notification channel reusable for future entities added to the same group.

Example for three services — one detector, one workflow:

dql
timeseries avg(dt.service.request.response_time),
  by: { dt.smartscape.service },
  filter: { in(dt.smartscape.service, {toSmartscapeId("SERVICE-0000000000000001"), toSmartscapeId("SERVICE-0000000000000002"), toSmartscapeId("SERVICE-0000000000000003")}) }

Set dt.alert_group: "checkout-team" in the detector's event properties, then filter the notification workflow on matchesPhrase(dt.alert_group, "checkout-team"). If a new service must be covered, add it to the single filter: list — no new detector or workflow rule needed.

Intent Mapping
User RequestActionReference
"how to alert on ...", "create an alert on ...", "create anomaly detector", "set up alerting", "configure alert rule"Explain detector categories and variants, guide through model selectionanomaly-detectors.md
"what kinds of anomaly detectors", "edge alert", "pipeline alert", "synthetic alert", "OneAgent alert"Explain the five alert source categories and their trade-offsanomaly-detectors.md
"static vs adaptive", "which detector model", "seasonal detector"Compare models, apply decision guideanomaly-detectors.md
"query alert history", "which alerts fired", "Davis events in Grail"Query dt.davis.events in Grail via fetch dt.davis.eventsdavis-events.md
"why did alerts merge", "problem grouping", "denoising"Do NOT explain merging rules here — load dt-obs-problems and refer to problem-merging.md for the full merge logicdt-obs-problems/references/problem-merging.md
"send Slack notification", "email on problem", "ServiceNow ticket", "notify on alert"Explain problem-triggered workflow setupworkflow-notifications.md
"alert storm", "too many notifications", "reduce noise"Filtering strategy, denoising, sensitivity tuningworkflow-notifications.md + anomaly-detectors.md

Analyzing existing problems — If the user wants to query or investigate active/closed problems (root cause, impact, trending), load dt-obs-problems instead. This skill covers configuration and flow, not problem query analytics.

Detector health monitoring — If the user asks whether detectors are running or failing, load dt-platform (ANALYZER_EXECUTION_EVENT, ANOMALY_DETECTOR_STATUS_EVENT). This skill covers setup, not operational health.

Prerequisites

  • Access to a Dynatrace environment with Settings v2 write permissions for detector configuration
  • For querying alert history: DQL permissions on dt.davis.events
  • Load dt-dql-essentials before writing DQL queries

Knowledge Base Structure

#ReferenceContent
1anomaly-detectors.mdDetector types, model selection, configuration, best practices
2davis-events.mdDavis event storage in Grail, key fields, DQL query patterns
3workflow-notifications.mdProblem-triggered workflows, filtering, notification channels

Key Concepts

Alert Source Categories

Five fundamental categories of anomaly detectors, distinguished by where detection runs and how the alert event reaches Dynatrace:

#CategoryDetection runs onLatencyAlert logic owner
1DQL-basedGrail (server-side, scheduled)MinutesDynatrace
2EdgeOneAgent on the monitored host/processSecondsDynatrace (OneAgent)
3PipelineOpenPipeline ingest path (in-stream)Near-zeroDynatrace (pipeline rule)
4SyntheticSynthetic checker node (worldwide)SecondsDynatrace (synthetic node)
5ExternalCustomer / external toolCaller-definedCustomer

See references/anomaly-detectors.md for the full breakdown of each category, including trade-offs and configuration entry points.

Show full SKILL.md (495 more words)Show less
Detector Models at a Glance
ModelThresholdBest for
StaticFixed value you defineKnown hard limits (e.g. error rate > 5%)
Adaptive baselineLearned from recent historyMetrics with no fixed limit but clear normal behavior
Seasonal baselineLearned with time-of-day / day-of-week awarenessTraffic, request rate, or any metric with recurring patterns
Davis Events vs. Problems
ConceptTableScope
Davis eventfetch dt.davis.eventsOne record per detector trigger per entity
Problemfetch dt.davis.problemsOne record per correlated group of events sharing root-cause and impact

A single problem typically contains multiple events. Querying problems gives the operational view; querying events gives the raw alert history.

Problem Denoising

For questions about why alerts merged into a problem or how Davis groups events, load dt-obs-problems — the merge logic and rules are documented in dt-obs-problems/references/problem-merging.md. This skill covers alert configuration and flow only.

Quick Start

Check What Alerts Fired in the Last 24 Hours
dql
fetch dt.davis.events, from: -24h
| filter event.status == "ACTIVE"
| summarize alert_count = count(), by: {event.name, event.category, dt.smartscape_source.id}
| sort alert_count desc
| limit 20
Check Alert Volume by Category
dql
fetch dt.davis.events, from: -24h
| summarize count = count(), by: {event.category, event.status}
| sort count desc
See All Active Problems (→ load dt-obs-problems for full query patterns)
dql
fetch dt.davis.problems, from: -24h
| filter not(dt.davis.is_duplicate) and event.status == "ACTIVE"
| fields event.start, display_id, event.name, event.category
| sort event.start desc
| limit 20

Best Practices

  1. Match the model to the metric's behavior — Use static for hard SLO boundaries, adaptive for metrics without a natural fixed limit, seasonal for anything that follows business hours or weekly patterns.
  2. Scope detectors narrowly — An entity selector that covers only relevant entities reduces noise and makes problems more actionable.
  3. Tune sensitivity before going to production — Start with LOW sensitivity and move to MEDIUM or HIGH only after observing false-positive rates.
  4. Let Davis denoise before notifying — Trigger workflow notifications on problems, not individual alert events. A problem groups correlated alerts so you notify once per incident, not once per metric.
  5. Filter notifications by severity level — Route event.severity <= 2 problems to on-call channels immediately; route event.severity >= 3 problems to lower- urgency channels. Either set severity in the detector config or assign in a pipeline rule or workflow.
  6. Use dt.alert_group event property for routing — Assign dt.alert_group to route alerts to the right team. Either set a static value in the detector config, use dynamic assignment through DQL query result mapping or assign in a pipeline rule.
  7. Combine same-condition alerts into one detector and one workflow — When alerting on multiple entities with the same metric and threshold, merge them into a single DQL-based detector using by: { <dimension> } and a combined filter: clause. Assign the same dt.alert_group value to every condition in that detector and point the workflow notification channel at that single group. One detector + one workflow per logical alert group scales better than N detectors + N notification rules, and adding a new entity is a one-line filter change rather than a full detector/workflow addition.
  • dt-obs-problems — Querying, analyzing, and trending detected problems
  • dt-obs-predictive-analytics — Ad-hoc anomaly and novelty detection using MCP analyzer tools (not persistent alert configs)
  • dt-platform — Operational health of anomaly detectors (execution events, failure rates)
  • dt-platform-costs — Query costs generated by anomaly detector DQL
  • dt-sdlc-quality-gates — Site Reliability Guardian for deployment gate alerting
  • dt-dql-essentials — DQL syntax for writing detector queries and alert history queries

© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/dt-alerting of Dynatrace/dynatrace-for-ai.

  • SKILL.md
  • references/anomaly-detectors.md
  • references/davis-events.md
  • references/workflow-notifications.md

Open the folder on GitHubat commit 4f9aa71

Compare with similar skills

Dt Alerting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dt Alerting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dt Alerting this skillDynatrace/dynatrace-for-ai163—~3.3kAutomated safety check: PassApache-2.0
Code Design Rationale Investigatorcursor/plugins11k9 repos~2.6kAutomated safety check: PassNone
Channel Debug Corevercel-labs/vercel-openclaw-archived117—~2kAutomated safety check: NotesMIT
Kibana Connectorsaspectrr/deer405—~2kAutomated safety check: PassMIT
Chat SDKdatabuddy-analytics/Databuddy1.2k—~2.6kAutomated safety check: PassAGPL-3.0
Axiom SRE Investigatoropenclaw/clawhub9.5k—~7.1kAutomated safety check: PassMIT

Similar skills

  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    11k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Channel Debug Core

    vercel-labs/vercel-openclaw-archived

    Official

    Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.

    117 GitHub stars~2k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Kibana Connectors

    aspectrr/deer

    Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

    405 GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Chat SDK

    databuddy-analytics/Databuddy

    Build multi-platform chat bots with Chat SDK (chat npm package).

    1.2k GitHub stars~2.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Debug deployed Cloudflare Workers using the cfobservability MCP, Wrangler, D1/R2 state, repo evidence, and safe live reproduction.

    105 GitHub stars~1.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from Dynatrace/dynatrace-for-ai

All 33 skills in this repo
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    163 GitHub stars~3.9k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    163 GitHub stars~4.2k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Ext Monitors

    Dynatrace/dynatrace-for-ai

    3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).

    163 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Problems

    Dynatrace/dynatrace-for-ai

    DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.

    163 GitHub stars~4.6k tokensUpdated 9 days ago
    Auto-check passed
  • Dt Obs Services

    Dynatrace/dynatrace-for-ai

    Service performance monitoring with RED metrics (Rate, Errors, Duration) and runtime-specific telemetry for Java, .NET, Node.js, Python, PHP, and Go.

    163 GitHub stars~3.3k tokensUpdated 9 days ago
    Auto-check passed

Works with

Questions about Dt Alerting

What does Dt Alerting do?

End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…. Dt Alerting is an agent skill from Dynatrace/dynatrace-for-ai. End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and denoising by root cause analysis, and workflow-based notification routing (email, Slack, ServiceNow, webhook).

When should I use Dt Alerting?

Dt Alerting fits situations like: configuring alerting; choosing between detector types; querying alert event history; understanding why alerts merged into a problem.

How do I install Dt Alerting in Claude Code?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a claude-code`. Or copy the skill folder (skills/dt-alerting in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-alerting in your project. Claude Code loads it when a task matches its description.

How do I install Dt Alerting in Codex?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a codex`. Or copy the skill folder (skills/dt-alerting in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-alerting in your project. Codex loads it when a task matches its description.

Can I use Dt Alerting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-alerting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-alerting, .gemini/skills/dt-alerting, .github/skills/dt-alerting and .opencode/skills/dt-alerting in your project.

What does Dt Alerting need to run?

SKILL.md names no scripts, command-line tools or credentials: Dt Alerting is instructions for the agent only.

Does Dt Alerting access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dt Alerting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dt Alerting use?

Dt Alerting is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dt Alerting use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Dt Alerting?

Skills that share tags, products or a category with Dt Alerting: Code Design Rationale Investigator (cursor/plugins, 11k stars), Channel Debug Core (vercel-labs/vercel-openclaw-archived, 117 stars), Kibana Connectors (aspectrr/deer, 405 stars) and Chat SDK (databuddy-analytics/Databuddy, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dt Alerting?

Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 163 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.