Official agent skill

Alerting Irm

by grafana in grafana/skills

Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Alerting Irm

skills CLI
$ npx skills add grafana/skills --skill alerting-irm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills alerting-irm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-core/alerting-irm .claude/skills/alerting-irm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
alerting-irm
GitHub stars
281
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
344 words
Files
4 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

  • Works in 4 steps: Create contact points (where… → Add notification policies (which alerts… → Write the alert rule — pick the type → …
  • Configuring alerts
  • SKILL.md covers Common Workflows, Contact Points (YAML…, Notification policies and Silences, plus 4 more sections
  • Calls curl and jq; reaches hooks.slack.com

What it does

Alerting Irm is an agent skill from grafana/skills, published by the product's own GitHub organization. Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escalation chains, incident-management integrations, and SLOs with multi-window burn-rate alerts. Use when configuring alerts, debugging notification routing, setting up on-call rotations, declaring or managing incidents…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/alerting.md`, `references/irm.md` and `references/slo.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting, Incident response and Site reliability engineering. It works with Grafana, PagerDuty, Slack and Prometheus. The licence is Apache-2.0.

When your agent uses it

  • Configuring alerts
  • Debugging notification routing
  • Setting up on-call rotations
  • Managing incidents

Example prompts

  • “t firing — even when the user says”
  • “alert me when X happens”
  • “route this to the platform team”
  • “/alerting-irm”

Requirements

  • A credential in YOUR_PAGERDUTY_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Create contact points (where notifications go)
  2. Add notification policies (which alerts go where) — see § Notification policies below for the matchers pattern.
  3. Write the alert rule — pick the type
  4. Verify routing before going live

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • hooks.slack.com

    Also links to:

    • grafana.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Alerting Irm loads about 1.9k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 219 tokens; SKILL.md has 344 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~219
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 344 words, ~1,923 tokens.

Download SKILL.mdSave it as .claude/skills/alerting-irm/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
alerting-irm
description
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escalation chains, incident-management integrations, and SLOs with multi-window burn-rate alerts. Use when configuring alerts, debugging notification routing, setting up on-call rotations, declaring or managing incidents, defining SLOs, provisioning alerting via YAML or API, picking matchers for a notification policy, building a PagerDuty/Slack webhook receiver, or troubleshooting why an alert isn't firing — even when the user says "page me on errors", "alert me when X happens", "route this to the platform team", or "set up an SLO" without naming Alerting or IRM.
license
Apache-2.0

Grafana Alerting & IRM

Docs: https://grafana.com/docs/grafana/latest/alerting.md

Common Workflows

Provisioning a new alert end-to-end
  1. Create contact points (where notifications go):

    bash
    curl -X POST https://grafana.example.com/api/v1/provisioning/contact-points \
      -H 'Authorization: Bearer <token>' -H 'Content-Type: application/json' \
      -d @contact-points.json

    Verify:

    bash
    curl https://grafana.example.com/api/v1/provisioning/contact-points \
      -H 'Authorization: Bearer <token>' | jq '.[].name'
  2. Add notification policies (which alerts go where) — see § Notification policies below for the matchers pattern.

  3. Write the alert rule — pick the type:

  4. Verify routing before going live:

    bash
    # Force-fire a test alert from the rule's UI, then check Alertmanager's view
    curl https://grafana.example.com/api/alertmanager/grafana/api/v2/alerts \
      -H 'Authorization: Bearer <token>' | jq '.[] | {alertname: .labels.alertname, receiver: .receivers}'

    The expected receiver should appear. If the wrong receiver appears, re-check the policy's matchers.

Routing alerts to IRM / on-call
  1. In IRM, create an Integration of type "Grafana Alerting webhook" → copy the integration URL
  2. Add a webhook contact point in Grafana Alerting pointing at that URL (full YAML in references/irm.md § Routing)
  3. Add a notification policy matcher routing the right severity to the new contact point
  4. Verify: trigger a test alert; it should appear in IRM within ~30s. Full debug procedure in references/irm.md § Verifying the IRM integration.
Defining an SLO
  1. Create the SLO via UI or API → Grafana auto-generates recording rules, dashboards, and burn-rate alerts (the generated YAML is in references/slo.md)
  2. Use multi-window burn-rate alerts, not single-window — see references/slo.md § Multi-window burn-rate alerts for why single-window fires on noise
  3. Verify with the 4-step pattern in references/slo.md § Validating SLO config
Show full SKILL.md (130 more words)Show less

Contact Points (YAML provisioning)

yaml
# provisioning/alerting/contact_points.yaml
apiVersion: 1
contactPoints:
  - orgId: 1
    name: pagerduty-critical
    receivers:
      - uid: pd-receiver
        type: pagerduty
        settings:
          integrationKey: YOUR_PAGERDUTY_KEY
          severity: critical

  - orgId: 1
    name: slack-alerts
    receivers:
      - uid: slack-receiver
        type: slack
        settings:
          url: https://hooks.slack.com/services/YOUR/WEBHOOK/URL
          channel: '#alerts'

For email, webhook, Teams, Telegram, OnCall, and other receiver types, see references/alerting.md § Contact point receiver types.

Notification policies

Hierarchical routing tree with label matchers:

yaml
# provisioning/alerting/notification_policies.yaml
apiVersion: 1
policies:
  - orgId: 1
    receiver: default-receiver
    group_by: ['alertname', 'cluster', 'service']
    group_wait: 30s
    group_interval: 5m
    repeat_interval: 12h
    routes:
      # Critical alerts → PagerDuty
      - receiver: pagerduty-critical
        matchers:
          - severity = critical
        group_wait: 10s
        repeat_interval: 4h

      # Platform team → Slack, but page on critical
      - receiver: slack-alerts
        matchers:
          - team = platform
        routes:
          - receiver: pagerduty-critical
            matchers:
              - severity = critical

      # Everything else → email
      - receiver: email-alerts
        matchers:
          - severity =~ "warning|info"

Silences

Suppress notifications for matching alerts without stopping evaluation:

bash
curl -X POST https://grafana.example.com/api/alertmanager/grafana/api/v2/silences \
  -H 'Authorization: Bearer <token>' \
  -H 'Content-Type: application/json' \
  -d '{
    "matchers": [
      {"name": "alertname", "value": "HighErrorRate", "isRegex": false},
      {"name": "env", "value": "staging", "isRegex": false}
    ],
    "startsAt": "2024-01-01T00:00:00Z",
    "endsAt": "2024-01-01T02:00:00Z",
    "comment": "Maintenance window",
    "createdBy": "admin"
  }'

# Verify it was created
curl https://grafana.example.com/api/alertmanager/grafana/api/v2/silences \
  -H 'Authorization: Bearer <token>' | jq '.[] | select(.status.state == "active")'

Alert rule states

StateDescription
NormalCondition not met
PendingCondition met, waiting for for duration
FiringCondition met for full for duration
NoDataQuery returned no data
ErrorQuery/evaluation error
RecoveringWas firing, condition no longer met

Provisioning directory layout

provisioning/alerting/
├── alert_rules.yaml          # Alert and recording rules
├── contact_points.yaml       # Notification destinations
├── notification_policies.yaml  # Routing tree
├── templates.yaml            # Message templates
└── mute_timings.yaml         # Recurring mute windows

API provisioning (keeps UI editable)

Add X-Disable-Provenance: true to keep resources editable in the UI after API provisioning:

bash
curl -X PUT https://grafana.example.com/api/v1/provisioning/policies \
  -H 'Authorization: Bearer <token>' \
  -H 'X-Disable-Provenance: true' \
  -H 'Content-Type: application/json' \
  -d @policy.json

curl -X POST https://grafana.example.com/api/v1/provisioning/alert-rules \
  -H 'Authorization: Bearer <token>' \
  -H 'X-Disable-Provenance: true' \
  -H 'Content-Type: application/json' \
  -d @rule.json

References

  • references/alerting.md — full alert rule YAML (Grafana-managed / Prometheus / Loki) + notification templates
  • references/slo.md — generated SLO recording rules + multi-window burn-rate alert pattern + validation steps
  • references/irm.md — IRM capabilities, integration sources, Alerting → IRM routing + verification + common failure modes

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/grafana-core/alerting-irm of grafana/skills.

  • SKILL.md
  • references/alerting.md
  • references/irm.md
  • references/slo.md

Open the folder on GitHubat commit 1ccacf2

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in grafana/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Alerting Irm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Alerting Irm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Alerting Irm this skillgrafana/skills2811 repos~1.9kAutomated safety check: PassApache-2.0
Alerting OncallBagelHole/DevOps-Security-Agent-Skills1.1k—~3kAutomated safety check: PassMIT
Sentry Alert TunerLeoYeAI/openclaw-master-skills2.2k—~7.3kAutomated safety check: PassMIT
Monitoring Observabilityahmedasmar/devops-claude-skills203—~3.9kAutomated safety check: PassNone
Expert OpsReJeCtAll/ExpertTeam-Codex113—~625Automated safety check: PassMIT
SRE EngineerJeffallan/claude-skills12k—~1.7kAutomated safety check: PassMIT

Similar skills

  • Alerting Oncall

    BagelHole/DevOps-Security-Agent-Skills

    Set up alerting rules, configure on-call rotations, and manage incident response workflows.

    1.1k GitHub stars~3k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Sentry Alert Tuner

    LeoYeAI/openclaw-master-skills

    Reduce Sentry alert fatigue by surgically tuning issue grouping, fingerprint rules, severity mapping, sample rates, before-send filters, sourcemap pipelines, and release-health gates.

    2.2k GitHub stars~7.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Monitoring Observability

    ahmedasmar/devops-claude-skills

    Monitoring and observability strategy, implementation, and troubleshooting.

    203 GitHub stars~3.9k tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed
  • Expert Ops

    ReJeCtAll/ExpertTeam-Codex

    基础设施运维专家入口。用于 Codex CLI 的 $expert-ops 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~625 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Observability Monitoring

    AnastasiyaW/codex-claude-code-config

    Design, audit, and troubleshoot production monitoring and observability using user-impact checks, layered telemetry, USE/RED, SLI/SLO/SLA, error budgets, cardinality controls, actionable alerting…

    154 GitHub stars~4.1k tokensUpdated today
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    281 GitHub stars~678 tokensUpdated today
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    281 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    281 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    281 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    281 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    281 GitHub stars~1.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Alerting Irm

What does Alerting Irm do?

Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…. Alerting Irm is an agent skill from grafana/skills, published by the product's own GitHub organization. Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escalation chains, incident-management integrations, and SLOs with multi-window burn-rate alerts.

When should I use Alerting Irm?

Alerting Irm fits situations like: configuring alerts; debugging notification routing; setting up on-call rotations; managing incidents.

How do I install Alerting Irm in Claude Code?

Run `npx skills add grafana/skills --skill alerting-irm -a claude-code`. Or copy the skill folder (skills/grafana-core/alerting-irm in grafana/skills) into .claude/skills/alerting-irm in your project. Claude Code loads it when a task matches its description.

How do I install Alerting Irm in Codex?

Run `npx skills add grafana/skills --skill alerting-irm -a codex`. Or copy the skill folder (skills/grafana-core/alerting-irm in grafana/skills) into .agents/skills/alerting-irm in your project. Codex loads it when a task matches its description.

Can I use Alerting Irm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill alerting-irm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alerting-irm, .gemini/skills/alerting-irm, .github/skills/alerting-irm and .opencode/skills/alerting-irm in your project.

What does Alerting Irm need to run?

Going by SKILL.md and its folder, Alerting Irm needs the command-line tools its instructions call (curl and jq). Our summary lists: A credential in YOUR_PAGERDUTY_KEY.

Does Alerting Irm access the network?

SKILL.md names 2 domains. In commands or code: hooks.slack.com; the agent is likely to contact it when it follows the instructions. As links in the text: grafana.com. This is read from the text; nothing was executed.

Is Alerting Irm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Alerting Irm use?

Alerting Irm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Alerting Irm use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Alerting Irm?

Skills that share tags, products or a category with Alerting Irm: Alerting Oncall (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Sentry Alert Tuner (LeoYeAI/openclaw-master-skills, 2.2k stars), Monitoring Observability (ahmedasmar/devops-claude-skills, 203 stars) and Expert Ops (ReJeCtAll/ExpertTeam-Codex, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Alerting Irm?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 281 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.