Insights

What QUARK surfaces, and how to read and act on findings.

The Insights view is QUARK's home page: a ranked list of findings about your environment, ordered by impact.

Types of findings

TypeExample
Anomaly"Interface utilization on core-sw-01 is 3× its seasonal baseline"
Correlated incident"Slow logins across branch offices correlate with saturated WAN link"
Capacity forecast"Datastore DS-PROD will reach 90% capacity in ~11 days"
Silent degradation"Backup job durations have grown 40% over 3 weeks"
Flapping / noise"Trigger X has fired and resolved 22 times today — consider tuning"

Anatomy of a finding

Every finding contains:

  • Summary — one sentence stating what is happening and where.
  • Impact — the hosts, services, and (where mapped) business services affected.
  • Evidence — the charts and events QUARK used, annotated with the anomaly window. Every claim links back to raw NetOPS data.
  • Probable cause — when QUARK has enough signal, a ranked list of causes with confidence levels. See Root cause analysis.
  • Recommended actions — concrete next steps. See Remediation.

Working with findings

  • Acknowledge a finding to show your team it's being handled.
  • Snooze recurring findings you've decided to accept (for example, a known-noisy dev host) — snoozed findings stay out of the ranked list but remain searchable.
  • Escalate to create a ticket in the ticketing system with the finding's evidence attached.

Asking QUARK directly

The Ask QUARK box accepts natural-language questions about your environment:

"Which hosts had memory pressure during last night's batch window?"

"What changed on the network before the 09:40 outage?"

Answers cite the underlying metrics and events, so you can verify everything QUARK tells you.

Notifications

Findings above a severity threshold can be pushed to email or Microsoft Teams. Configure thresholds and quiet hours under Settings → Notifications — QUARK batches related findings so a single incident produces a single notification.

On this page