How it works
1
Trigger
An automation runs on its schedule (e.g. 09:00 every morning) or when an alert matches its filter rules.
2
Investigate
Foggy runs the investigation using your connected data sources — querying metrics, logs, dashboards, and cluster state, just like a manual investigation.
3
Deliver
Results appear as a chat thread in the web interface and are delivered to Slack (if configured). Full chain-of-thought, sources, and follow-up suggestions included.
Alert-triggered automations
Configure automations that fire when alerts come in. Define filter rules to control which alerts trigger investigations.Filter rules
Filter rules match against alert labels. Multiple rules use AND logic — all must match for the automation to trigger. Common patterns:
Run now
Every automation — scheduled or alert-triggered — has a Run now button on its detail page. This executes the automation immediately against live data, independent of its schedule or filter rules. Useful for testing a new automation, or to re-run one after fixing a connector.Scheduled automations
Set up investigations that run on a recurring schedule — no alerts required.
All frequencies support multi-select times — e.g. run at both 09:00 and 17:00.

Next steps
Slack Bot
Investigate incidents and get automation results directly in Slack.
Knowledge Base
Add runbooks and context so Foggy gives more accurate answers.
Connect data sources
Add Grafana, Kubernetes, and more to power investigations.