---
sourceDocument: Xanadu IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/it-operations-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create an alert correlation rule

# Create an alert correlation rule {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an alert correlation rule to designate primary and secondary alerts. The primary alert is identified as the root cause of the alert group and the secondary alerts are grouped under the primary alert.

## Before you begin

Role required: evt_mgmt_admin

## Procedure

1. Navigate to AllEvent ManagementRulesAlert Correlation Rules.
2. Click New.
3. On the form, fill in the fields.  
   For information on the fields, see [Alert correlation rule form](https://www.servicenow.com/docs/ETHqK0wLj36exYr~_2jeOw "Manage the fields that define how alerts are correlated and grouped.").
4. Select Submit.

## Result

A rule-based alert group is created when a new alert is generated or when the status of an existing alert changes from Closed or Flapping to Open or Reopened, provided the filter criteria are matched.

*[\>]: and then


