# How to Use Interactive Alert Input for OpenSRE Investigations

> Simplify OpenSRE investigations by using interactive alert input. Paste alert JSON payloads directly into your terminal with opensre investigate --interactive for faster analysis.

- Repository: [Tracer/opensre](https://github.com/Tracer-Cloud/opensre)
- Tags: how-to-guide
- Published: 2026-04-18

---

**Run `opensre investigate --interactive` to paste alert JSON payloads directly into your terminal, bypassing file-based or inline string input requirements.**

OpenSRE provides an **interactive mode** that streamlines incident response by letting you paste raw alert JSON directly into the terminal. This eliminates the need to save alerts to temporary files or manually escape complex JSON strings for command-line arguments. According to the Tracer-Cloud/opensre source code, the interactive workflow reads from standard input, validates the payload, and passes it directly to the investigation pipeline orchestrated by LangGraph.

## How Interactive Alert Input Works

The interactive mode follows a five-stage pipeline through the OpenSRE CLI architecture:

**1. CLI Command Parsing**

The `investigate` command defined in [`app/cli/commands/general.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/commands/general.py) receives the `--interactive` flag and forwards it to the core runner. Lines 36-38 handle the flag parsing and argv construction for the investigation.

**2. Payload Dispatch**

In [`app/cli/payload.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/payload.py), the `load_payload` function (lines 71-80) acts as a central dispatcher. When `interactive=True`, it delegates to `load_interactive()` instead of file-based or JSON string loaders.

**3. Interactive Prompt**

The `load_interactive()` function (lines 62-68) writes the instruction `"Paste the alert JSON payload, then press Ctrl-D when finished."` to `stderr`. This ensures the prompt does not corrupt the JSON output stream on `stdout`. It then reads all data from `stdin` until EOF (Ctrl-D).

**4. Investigation Execution**

The parsed dictionary passes to `run_investigation_cli` in [`app/cli/investigate.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/investigate.py) (lines 51-63). This function normalizes alert metadata, resolves pipeline configurations, and invokes the LangGraph-based investigation runner.

**5. Result Output**

After pipeline completion, the CLI prints a JSON result containing the Slack-compatible report, root cause analysis, and noise classification to `stdout`.

## Using Interactive Mode from the CLI

Start an interactive investigation session by running:

```bash
opensre investigate --interactive

```

The terminal will display the prompt on `stderr` and wait for your input:

```

Paste the alert JSON payload, then press Ctrl-D when finished.
{
  "alert_name": "High CPU",
  "pipeline_name": "prod-services",
  "severity": "critical",
  "raw_alert": { "cpu": 98, "instance": "i-0123abc" }
}
^D

```

After pressing **Ctrl-D** (EOF), OpenSRE validates the JSON and executes the investigation. The final JSON report appears on `stdout`:

```json
{"report":"…slack message…","problem_md":"…","root_cause":"…","is_noise":false}

```

Because the prompt writes to `stderr`, you can safely pipe the JSON output to other tools or files using `--output`.

## Programmatic Usage with Python

You can embed the same interactive behavior in custom scripts by importing the payload loader directly from [`app/cli/payload.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/payload.py):

```python
from app.cli.payload import load_interactive
from app.cli.investigate import run_investigation_cli

# Blocks execution, prints prompt to stderr, and reads from stdin

payload = load_interactive()

# Execute investigation with parsed payload

result = run_investigation_cli(raw_alert=payload)

print(result["report"])

```

The `load_interactive()` function raises `SystemExit` on empty input, mirroring the CLI behavior exactly. This ensures consistent error handling whether you use the command line or a Python wrapper.

## Testing Interactive Input

The OpenSRE test suite demonstrates how to simulate interactive input by patching `sys.stdin` with a `StringIO` buffer. This approach is implemented in [`tests/test_main.py`](https://github.com/Tracer-Cloud/opensre/blob/main/tests/test_main.py):

```python
import io
import sys
from app.cli.payload import load_payload

# Simulate user pasting JSON

sample = '{"alert_name":"High CPU","severity":"warning"}\n'
sys.stdin = io.StringIO(sample)

# Load as interactive payload

payload = load_payload(input_path=None, input_json=None, interactive=True)

assert payload["alert_name"] == "High CPU"

```

This technique allows you to test interactive workflows in CI/CD pipelines without requiring an actual TTY.

## Summary

- **Entry Point**: The `--interactive` flag in [`app/cli/commands/general.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/commands/general.py) triggers the interactive workflow.
- **Core Logic**: `load_interactive()` in [`app/cli/payload.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/payload.py) handles stdin reading and JSON validation.
- **Output Isolation**: Prompts write to `stderr` to keep `stdout` clean for machine-readable JSON results.
- **Integration**: Use `run_investigation_cli` from [`app/cli/investigate.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/investigate.py) for programmatic access.
- **Validation**: Interactive mode bypasses TTY checks and reads until EOF, making it suitable for both manual and automated usage.

## Frequently Asked Questions

### What happens if I provide malformed JSON in interactive mode?

The `load_interactive()` function in [`app/cli/payload.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/payload.py) attempts to parse the stdin content with `json.loads()`. If the JSON is invalid, it raises a `json.JSONDecodeError` and exits with a non-zero status code, displaying the parsing error to `stderr` without corrupting the output stream.

### Can I pipe JSON into an interactive investigation?

No. The interactive mode specifically bypasses the TTY check that `load_stdin()` would normally enforce. If you need to pipe JSON, omit the `--interactive` flag and use standard input redirection (`cat alert.json | opensre investigate`), which triggers `load_stdin()` rather than `load_interactive()`. The interactive flag is designed for scenarios where you want visual confirmation and manual pasting.

### Where is the interactive prompt text defined?

The prompt string `"Paste the alert JSON payload, then press Ctrl-D when finished."` is hardcoded in [`app/cli/payload.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/cli/payload.py) within the `load_interactive()` function (lines 62-68). The function uses `sys.stderr.write()` to ensure the instruction appears immediately and does not buffer with the JSON output.

### How does OpenSRE handle empty input in interactive mode?

If you press Ctrl-D without entering any content, `load_interactive()` detects the empty string and raises `SystemExit` with an appropriate error message. This behavior mirrors standard UNIX tooling and ensures the investigation pipeline does not execute with null payloads.