---
sourceDocument: Xanadu IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/it-operations-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Alert grouping types

# Alert grouping types {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Alerts are grouped into various types to streamline problem identification and management. An alert can belong to only one alert group at a time.
Watch this brief video to learn about alert grouping and how it organizes alerts into clusters based on specific criteria.

<br />

You can view all alert groups by navigating to Event ManagementAll Alerts, where the icon in the Group column denotes the alert group type. Alerts not associated with any group will not have an entry in the Group column. Double-click the
Group column for an alert group to open the Grouped Alerts dialog box, where you can display all alerts in the group and manually add or remove alerts.  
Note:  
The filter that defines alert groups must not be on fields that do not appear in the \[em_alert_history\] table because impact calculation is not a calculated property. This situation occurs because fields like Event Count, Priority, and Priority Group are not copied to the \[em_alert_history\] table for impact calculation.  
{#Alert-Groups__table_ajd_qwj_ww__entry__5}

| Type | Icon | Description | Creation method | Additional information |
|-|-|-|-|-|
| Log Analytics | L | Log Analytics groups are formed when the system identifies multiple related Log Analytics alerts, grouping them based on their significant connections. | Created as part of log analytics event processing. | [Kinds of Health Log Analytics alerts](https://www.servicenow.com/docs/d~tmO0MmkgntF50WCv3pgQ "Health Log Analytics generates several types of alerts.") |
| Rule-based | R | Rule-based groups consist of related alerts that are organized based on compliance with alert correlation rules, which determine how alerts are grouped according to their relationships. | Created via business rule (Calculate correlation rule) on em_alert table when alert is created or updated. | [Create an alert correlation rule](https://www.servicenow.com/docs/uOJ8J7EFkJdP7AfxzzpmwQ "Create an alert correlation rule to designate primary and secondary alerts. The primary alert is identified as the root cause of the alert group and the secondary alerts are grouped under the primary alert.") |
| Automated | A | Automated groups are formed by alert aggregation and include a virtual alert as the primary alert of the group. An Aggregated automated group is created when two or more alerts share the same CI type and metric name. | Created via scheduled job. | [Automated alert grouping](https://www.servicenow.com/docs/HauD4Au9yoRCO9RnKWZWig "Event Management alert aggregation aggregates alerts into automated alert groups based on historical alert data. Automated alert groups are displayed in the Express List in the Service Operations Workspace.") |
| CMDB-based | C | CMDB-based groups are formed based on CI relationships in the CMDB, specifically for CIs that are not included in rule-based or automated groups. | Created via scheduled job. | [CMDB based alert grouping](https://www.servicenow.com/docs/XB9ALlOeJi_Zh~6MVIfSpA "CMDB based alert grouping helps organizations manage alerts by organizing them according to their related configuration items (CIs) within the Configuration Management Database (CMDB). This method group alerts based on CI relations in applications or infrastructure components, allowing teams to better understand the impact of issues, respond more effectively to alerts, and maintain service availability.") |
| Text-based | T | Text-based groups are formed by grouping alerts based on similar text from frequently used words in following fields. * Description * Metric Name * CI Class {#Alert-Groups__ul_xq4_wlz_mlb} | Created via scheduled job. | N/A |
| Tag cluster | Tag | Tag cluster groups are formed by grouping alerts according to user-defined tag-based alert clustering definitions. | Created via scheduled job. | [Tag cluster alert grouping](https://www.servicenow.com/docs/IOMrsBQ1yGPRQpcY0cEMuA "Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts.") |
| Manual | M | Alerts grouped manually by users to organize related issues. | Created manually by the user. | [Create alert group manually](https://www.servicenow.com/docs/9qNtQEZiIgLtjMYfreHkUA "Manually create an alert group to organize and manage related alerts when not using scheduled jobs. This provides flexibility to group alerts on-demand for effective resolution.") |
[Table 1. Alert grouping types]

{#Alert-Groups__table_ajd_qwj_ww}

For information on scheduled jobs and parameters, refer to [Scheduled jobs and parameters for alert grouping](https://www.servicenow.com/docs/fOii1BTvlvoRZMNP2pxADw "Automate alert organization by configuring jobs to group alerts based on predefined criteria and parameters."). For detailed information on configuring alert correlation logic order, see [Configure alert correlation logic order](https://www.servicenow.com/docs/Tz3PuvykLoBh0OSmQU1R4Q "Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response efficiency.").

*[\>]: and then


