Insights
What QUARK surfaces, and how to read and act on findings.
The Insights view is QUARK's home page: a ranked list of findings about your environment, ordered by impact.
Types of findings
| Type | Example |
|---|---|
| Anomaly | "Interface utilization on core-sw-01 is 3× its seasonal baseline" |
| Correlated incident | "Slow logins across branch offices correlate with saturated WAN link" |
| Capacity forecast | "Datastore DS-PROD will reach 90% capacity in ~11 days" |
| Silent degradation | "Backup job durations have grown 40% over 3 weeks" |
| Flapping / noise | "Trigger X has fired and resolved 22 times today — consider tuning" |
Anatomy of a finding
Every finding contains:
- Summary — one sentence stating what is happening and where.
- Impact — the hosts, services, and (where mapped) business services affected.
- Evidence — the charts and events QUARK used, annotated with the anomaly window. Every claim links back to raw NetOPS data.
- Probable cause — when QUARK has enough signal, a ranked list of causes with confidence levels. See Root cause analysis.
- Recommended actions — concrete next steps. See Remediation.
Working with findings
- Acknowledge a finding to show your team it's being handled.
- Snooze recurring findings you've decided to accept (for example, a known-noisy dev host) — snoozed findings stay out of the ranked list but remain searchable.
- Escalate to create a ticket in the ticketing system with the finding's evidence attached.
Asking QUARK directly
The Ask QUARK box accepts natural-language questions about your environment:
"Which hosts had memory pressure during last night's batch window?"
"What changed on the network before the 09:40 outage?"
Answers cite the underlying metrics and events, so you can verify everything QUARK tells you.
Notifications
Findings above a severity threshold can be pushed to email or Microsoft Teams. Configure thresholds and quiet hours under Settings → Notifications — QUARK batches related findings so a single incident produces a single notification.