# Group alerts into incidents

Tell whether a new alert belongs to an open incident. `find` picks the incident, or none. `decide` confirms the match.

*find picks INC-1 for the card failure, and decide confirms the match with true.*

```
alert="Card charges fail with 500 at checkout"
covers="Which incident covers: $alert"
same="Is this the same failure as: $alert"

incident=$(
cat <<'EOF' |
INC-1 checkout returns 500 at payment
INC-2 search results load slowly
INC-3 nightly export ran late
EOF
thinkthen find "$covers" --none
)

if [ -n "$incident" ]; then
  printf '%s\n' "$incident" |
  thinkthen decide "$same"
fi

test "$incident" = "INC-1 checkout returns 500 at payment"
```

*Output*

```
true
```

*exit 0*

*No open incident covers a full disk. find prints nothing, and decide never runs.*

```
alert="Disk is full on the backup server"
covers="Which incident covers: $alert"
same="Is this the same failure as: $alert"

incident=$(
cat <<'EOF' |
INC-1 checkout returns 500 at payment
INC-2 search results load slowly
INC-3 nightly export ran late
EOF
thinkthen find "$covers" --none
)

if [ -n "$incident" ]; then
  printf '%s\n' "$incident" |
  thinkthen decide "$same"
fi

test -z "$incident"
```

*No output. exit 0*

## The functions it uses

- [find](/functions/find/): Pick the one line that best answers a question.

- [decide](/functions/decide/): Answer one yes or no question about the evidence.

On GitHub: [github.com/botassembly/thinkthen](https://github.com/botassembly/thinkthen)
