slo-investigate

Correlate SLO definitions with metrics, alerts, and runbooks to diagnose breaches.

535|42|Updated Mar 23, 2026
One-click install
npx skills add https://github.com/grafana/gcx --skill slo-investigate
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: slo-investigate
Source: https://github.com/grafana/gcx/tree/main/claude-plugin/skills/slo-investigate
Command: npx skills add https://github.com/grafana/gcx --skill slo-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

SLO breaches often require quick, structured root-cause analysis. This skill helps operators understand why an SLO is breaching by performing dimensional breakdowns, correlating SLO definitions with metrics and alerts, and providing runbook access and related dashboards.

Core Features & Use Cases

  • Root-cause analysis for breaching SLOs with dimensional breakdowns by cluster, service, or other labels.
  • Correlates SLO definitions with current metrics and alert rules to surface actionable insights.
  • Provides direct access to relevant runbooks and dashboards for remediation and collaboration.

Quick Start

Ask gcx to investigate a breaching SLO and surface runbooks, dashboards, and alert-rule correlations.

Frequently Asked Questions about slo-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate an SLO breach to find the root cause?

To investigate an SLO breach, you correlate SLO definitions with current metrics and alerts, evaluate SLI and burn rate, and apply dimensional breakdowns by labels like cluster or service to isolate the root cause.

What is the best way to correlate alerts with SLO definitions during an incident?

Correlate alerts with SLO definitions by linking alert rules to the SLO's destination datasource, evaluating current burn rates, and surfacing actionable insights across relevant time windows.

How do I find runbooks and dashboards related to a breaching SLO?

Find runbooks and dashboards for a breaching SLO by querying the SLO's destination datasource to fetch associated remediation resources, providing direct access to collaboration and troubleshooting steps.

Does SLO root-cause analysis support dimensional breakdowns across multiple data sources?

Yes, SLO root-cause analysis supports dimensional breakdowns across multiple data sources by querying the SLO's destination datasource to correlate metrics, alerts, and runbooks across different time windows and labels.

Why do I need to evaluate the current SLI and burn rate when diagnosing SLO breaches?

Evaluating the current SLI and burn rate is necessary because it quantifies the severity and speed of the violation within a specific time window, enabling precise dimensional root-cause analysis and remediation.