---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create an alert correlation rule

# Create an alert correlation rule {#ariaid-title1}

Release version: Zurich  
Updated July 31, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Create an alert correlation rule to designate primary and secondary alerts. The primary alert is identified as the root cause of the alert group and the secondary alerts are grouped under the primary alert.

## Before you begin

Role required: evt_mgmt_admin

## About this task

Grouping automation helps you manage alerts more effectively by collecting similar alerts together. This makes it easier to see patterns, quickly identify issues, and respond efficiently. For more information on how to group
alerts easily, see [Create Group automation](https://www.servicenow.com/docs/w9MxnVFbX1z6~2jywYZoLQ "Grouping automation helps you manage alerts more effectively by collecting similar alerts together. This makes it easier to see patterns, quickly identify issues, and respond efficiently. By organizing alerts in this way, you can reduce alert noise, identify root causes, and assign them to the appropriate teams.").

## Procedure

1. Navigate to AllEvent ManagementRulesAlert Correlation Rules.  
   You can also [Create Enrich automation](https://www.servicenow.com/docs/O8D7CDGzMzYnqrxh_yFF0A "Alert enrichment involves transforming raw events from monitoring tools into a standard format, aiding automated grouping and response. This includes extracting fields from lengthy alert payloads or composing them into a standardized format. Additionally, you can create tags, which are metadata added to alerts for easier filtering and grouping.")
2. Select New.
3. On the form, fill in the fields.  
   For information on the fields, see [Alert correlation rule form](https://www.servicenow.com/docs/hQ43pifv9HQkev~Y_ZepoQ "Manage the fields that define how alerts are correlated and grouped.").
4. Select Submit.

## Result

A rule-based alert group is created when a new alert is generated or when an existing alert status changes from Closed or Flapping to Open or Reopened. The filter criteria must be matched.

*[\>]: and then


