Find your people. Pick a challenge. Ship something real. The CreatorCon Hackathon is coming to the Community Pavilion for one epic night. Every skill level, every role welcome. Join us on May 5th and learn more here.

Source changes on group alert

Henrik Jutterst
Kilo Sage

In Event Management we have multiple sources that send events to our ServiceNow instance. Our NOC/SOC-team have a list in Agent Workspace where they have alerts for each source, but they recently found out that when an Alert is grouped into primary and secondary alert, the source name changes into "Group Alert", and the filter then does not find the Alerts.

 

So, my question is: What's the best way around this? And WHY is the source changing when it's a grouped alert?
I would think that it's quite common to have more than one event source, and also that you might want to filter by source...

 

 

HenrikJutterst_0-1666362374851.png

 

1 ACCEPTED SOLUTION

Henrik Jutterst
Kilo Sage

Can't be fixed OOB 😞

View solution in original post

1 REPLY 1

Henrik Jutterst
Kilo Sage

Can't be fixed OOB 😞