Use System Fields in Runbook Actions
Reference built-in incident and alert data in runbook actions.
System fields provide access to incident and alert data in your runbook actions. These fields are automatically available based on your runbook context and can be referenced using Mustache templates or CEL expressions.
Incident fields
These fields are automatically available when your runbook has incident context:
{{incident.id}}- Unique incident identifier{{incident.short_id}}- Human-readable ID (e.g., "INC-123"){{incident.title}}- Incident title{{incident.severity}}- Severity level (SEV0, SEV1, SEV2, SEV3, SEV4){{incident.status}}- Current status (detected, investigating, mitigating, resolved){{incident.created_at}}- Creation timestamp{{incident.updated_at}}- Last update timestamp{{incident.service}}- Affected service name{{incident.environment}}- Environment (production, staging, development){{incident.owner}}- Current owner/responder{{incident.url}}- Link to incident in AI SRE UI
Activity fields (enhanced incident data)
The Activity namespace provides access to Harness-specific incident data, including full service objects with IDs:
{{Activity.id}}- Activity identifier{{Activity.title}}- Activity title{{Activity.severity}}- Severity object{{Activity.severity.id}}- Severity ID (numeric){{Activity.status}}- Current status{{Activity.summary}}- Activity summary{{Activity.impacted_services}}- Array of Harness service objects with.idand.nameproperties{{Activity.url}}- Link to activity in AI SRE UI
Get Harness service IDs with CEL:
Alert fields
These fields are available when your runbook has alert context:
{{alert.id}}- Unique alert identifier{{alert.title}}- Alert title{{alert.priority}}- Priority level (p1_critical, p2_error, p3_warning, p4_info){{alert.service}}- Service associated with the alert{{alert.source}}- Alert source (Datadog, New Relic, Prometheus, etc.){{alert.timestamp}}- When the alert was received{{alert.fingerprint}}- Deduplication fingerprint{{alert.url}}- Link to alert source (if available)
Severity field usage
The severity field contains string values representing severity levels. When referencing severity in runbook actions:
{{incident.severity}} returns "0"
SEV0:Critical
System-wide outage
{{incident.severity}} returns "1"
SEV1:Major
Significant service degradation
{{incident.severity}} returns "2"
SEV2:Moderate
Partial service impact
{{incident.severity}} returns "3"
SEV3:Minor
Minor issue with workaround
{{incident.severity}} returns "4"
SEV4:Cosmetic
Cosmetic issue, no functional impact
Example Slack message using severity:
Go to Create runbook triggers to learn how to configure severity-based trigger conditions.
CEL expression alternative:
Custom fields
Custom fields defined on incident types or alert types are also available via Mustache syntax:
{{incident.custom_field_name}}- Any custom field added to an incident type{{alert.custom_field_name}}- Any custom field added to an alert type
Example: If your "Service Incident" type has a custom field called error_rate, reference it as:
Next steps
Go to Use Mustache templates in runbook actions to reference incident data with Mustache templates.
Go to Use CEL in runbook actions to implement dynamic logic with CEL expressions.
Go to Best practices to review field usage guidelines.
Last updated
Was this helpful?