How can we exclude specific alerts from participating in alert grouping or correlation mechanisms?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 weeks ago
We have certain alerts that should remain standalone and not be considered in any type of correlation, including:
- Rule-Based Correlation
- Tag-Based Correlation
- CMDB-Based Correlation
- Automated Correlation
- Manual Correlation
Is there a recommended approach or configuration to ensure these alerts are completely bypassed from all correlation types?
- Labels:
-
Event Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 weeks ago
Create a custom Alert Correlation rule .
Refer:
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 weeks ago
I am trying to understand how this is going to help, can you tell me exactly how we need to achieve this
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi Deepak,
I’d like to know which attribute or unique identifier you want to use to exclude alerts from the alert group.
If you are using CMDB-Based Correlation or Automated Correlation, this requirement will need customization of the out‑of‑the‑box functionality.
If you are not using CMDB-Based Correlation or Automated Correlation, then exclusion can be achieved by adding conditions to other configurable rules.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 weeks ago
Hey @MushtaqMir , We are using the tag based correlation and apart from that the alert correlation properties are set to true for CMDB, Network Traffic, ML based automation correlation
Requirement is I want to do correlation for all except few, I understand that the requirement will need customization of the out‑of‑the‑box functionality.
I can use one field that is we have as customer name on the alert table to exclude those alerts from any type of correlation