Viewing links between alerts in log analytics-based alert groups

  • Rversion finale: Australia
  • Mis à jour 12 mars 2026
  • 1 minute de lecture
  • Use Link View in Express List to see why alerts in a log analytics-based alert group are correlated together through the visualization of shared attributes.

    Link View for log analytics-based alert groups shows the connections between component-based alerts. Each component-based alert may involve multiple host configuration items (CIs). A component represents a logical part of a service instance where the alert was detected. Components can consist of multiple CIs that perform the same function, such as multiple redundant hosts. For more information, see Types of Health Log Analytics alerts.

    The colored tags in the link view represent attributes of the alerts such as hosts, users, or correlation indicators extracted from the logs. The lines connect attributes that share the same alert. This visualization helps you understand the relationships between different alerts in the group using their shared attributes.

    Log analytics-based groups often contain multiple correlation attributes within a single group. Link View enables you to explore why anomalies detected on different components were correlated into one group. By manipulating the attribute display, you can better understand the relationships between alerts that share common attributes.

    In this sample Link View, a component attribute is shown for each child alert in the log analytics alert group. Other attributes show connections between the component alerts.

    The Link View legend lists the meaning of the symbols used to represent the attributes. You can toggle between hiding and showing attributes types to reduce noise. For a description of each attribute, see Attributes in Express List Link View.

    Sample log analytics-based Link View legend.