Event Management - CMDB Based Alert Correlation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-15-2024 09:46 AM
Hi Team,
I have the following queries regarding the implementation of CMDB-based alert correlation:
- Is there any way to exclude specific nodes, severities, or alert types from CMDB-based alert correlation?
- Is it possible to define a timeframe window for CMDB-based alert correlation?
- What is the order of correlation execution? Considering that I have enabled the Alert correlation rule, Automated Alert correlation, and Tag-based alert correlation, which one takes precedence?
- Labels:
-
Event Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-15-2024 09:59 AM
This blog might be helpful
Mark it Helpful and Accept Solution!! If this helps you to understand.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-15-2024 10:09 AM
Thanks @SK Chand Basha
The link that you have shared above is related to the Alert Correlation Rule. I need to know about the CMDB based alert correlation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-15-2024 10:22 AM
Hello Satya, you need to create an automatic group filter. It's a fairly straightforward solution. Just select your alert group type and apply the filter.
LIKN: Configure filters for automatic alert groups (servicenow.com)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎05-15-2024 10:25 AM
Point 2: No, you cannot change it. It is set to 10 minutes by default. by default.
Link; Configure the time window for alert grouping - Support and Troubleshooting (servicenow.com)
point 3. Groping order:
- Log Analytics
- Rule-based and Tag Cluster
- Manual
- Automated
- CMDB
- Text
Link: Alert group types (servicenow.com)