{"product_id":"slack-devops-incident-triage-with-gpt-4-1-prometheus-jira","title":"Slack DevOps Incident Triage with GPT-4.1, Prometheus \u0026 Jira","description":"\u003ch3\u003eTurn Slack incident reports into Jira (or GitHub) tickets—with GPT-4.1, Prometheus, Loki, and human approval\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow automates DevOps incident triage by listening to Slack alerts, using a GPT-4.1 agent to investigate via Prometheus metrics and Loki logs (plus RAG from past incidents), saving the analysis to PostgreSQL, and—only after explicit approval—creating a Jira or GitHub issue and triggering Terraform remediation.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eDetects new incidents in Slack\u003c\/strong\u003e by triggering when a message is posted in your configured Slack incident-response channel.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eNormalizes the incident context\u003c\/strong\u003e (message text, channel, thread timestamp, reporter) and creates a \u003cem\u003esession ID\u003c\/em\u003e for thread-based memory.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003ePerforms AI-assisted investigation\u003c\/strong\u003e using a GPT-4.1 agent with tool-calling to query:\n    \u003cul\u003e\n      \u003cli\u003e\n\u003cstrong\u003ePrometheus\u003c\/strong\u003e for metrics evidence\u003c\/li\u003e\n      \u003cli\u003e\n\u003cstrong\u003eLoki\u003c\/strong\u003e for relevant log findings\u003c\/li\u003e\n      \u003cli\u003e\n\u003cstrong\u003ea vector-store RAG knowledge base\u003c\/strong\u003e for past incident patterns\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eGenerates a structured RCA (JSON)\u003c\/strong\u003e including root cause, confidence, evidence, remediation, risk level, and service.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eSaves the incident analysis\u003c\/strong\u003e to a PostgreSQL \u003ccode\u003eincidents\u003c\/code\u003e table.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRequests approval when remediation is proposed\u003c\/strong\u003e: if no concrete remediation is found, it posts an investigation update to Slack and stops; otherwise it posts an approval request and waits for a reviewer decision via a resume webhook.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eCloses the loop after approval\u003c\/strong\u003e: creates a ticket in \u003cstrong\u003eJira or GitHub Issues\u003c\/strong\u003e, triggers a \u003cstrong\u003eTerraform Cloud\u003c\/strong\u003e run, re-queries \u003cstrong\u003ePrometheus\u003c\/strong\u003e, adds a \u003cstrong\u003eGrafana annotation\u003c\/strong\u003e, and posts a resolution summary back to the original Slack thread.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eHandles rejection safely\u003c\/strong\u003e by posting a rejection notice to Slack and stopping.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eSaaS teams that triage incidents from Slack and want consistent, evidence-based RCAs.\u003c\/li\u003e\n  \u003cli\u003eAutomation engineers needing an n8n workflow that ties Slack → AI investigation → PostgreSQL → Jira\/GitHub → Terraform → Grafana.\u003c\/li\u003e\n  \u003cli\u003eDevOps incident response where changes must be approved by a human before remediation.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTrigger:\u003c\/strong\u003e Slack new message (incident-response channel)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eNodes \/ integrations: \u003c\/strong\u003e \u003ccode\u003eif\u003c\/code\u003e, \u003ccode\u003eset\u003c\/code\u003e, \u003ccode\u003eslack\u003c\/code\u003e, \u003ccode\u003ewait\u003c\/code\u003e, \u003ccode\u003ejira\u003c\/code\u003e, \u003ccode\u003egithub\u003c\/code\u003e\n\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eAI:\u003c\/strong\u003e OpenAI GPT-4.1 agent with session memory and tool-calling\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eObservability:\u003c\/strong\u003e Prometheus, Loki, Grafana annotation\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eData storage:\u003c\/strong\u003e PostgreSQL (\u003ccode\u003eincidents\u003c\/code\u003e table)\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eRemediation:\u003c\/strong\u003e Terraform Cloud run (post-approval)\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45950030774451,"sku":"N8N-19171","price":41.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/DGdU4JMp8CJKo8GWqxN7_Cn5jvHHw.png?v=1788512974","url":"https:\/\/buyflowscripts.com\/products\/slack-devops-incident-triage-with-gpt-4-1-prometheus-jira","provider":"N8N Commerce","version":"1.0","type":"link"}