Configure scheduled job-based alert grouping

  • Release version: Zurich
  • Updated July 31, 2025
  • 1 minute to read
  • Set up rules and parameters to group related alerts automatically, streamlining alert management and reducing alert noise.

    Before you begin

    Role required: evt_mgmt_admin

    About this task

    The scheduled job Service Analytics: Group Alerts Using RCA/Alert Aggregation helps in grouping alerts.

    Procedure

    1. Navigate to All > Event Management > Administration > Alert Correlation Properties.
    2. On the Alert Correlation Properties page, enable the relevant properties.
      • Enable CMDB correlation (sa_analytics.agg.query_cmdb_correlation_enabled).
      • Enable Network Traffic correlation (sa_analytics.agg.query_network_traffic_correlation_enabled).
      • Enable ML based Automation correlation (sa_analytics.specific_patterns_enabled).
      • Enable Text based correlation (sa_analytics.text_based_group_enabled).
      • “Group by” property, with comma-separated list of field names that need to have matching values across alerts to allow alerts to be grouped together. The property can contain alert field names (such as assignment_group), CI field names (such as alert_cmdb_ci.location), alert additional info field names (such as additional_info.state) or alert tags (such as t_data_center). When the specified field values match each other between alerts, those alerts can be grouped together (sa_analytics.agg.group_alert_with_same_group_by_fields).
      • Max number of relations between CIs in a topology which form a CMDB group (sa_analytics.agg.query_cmdb_graph_walk_nodes).
      • Use all CMDB relations for CMDB group correlation (evt_mgmt.related_cis_get_all_relation_types).
    3. Select Save.

      To group alerts without a CI as Text-based or ML based groups, set sa_analytics.enable_no_ci_grouping to true. Ensure the Feature Identifier includes both the node and metric name. For details on configuring the feature identifier, see Specify and manage pattern identifier attributes for alert grouping.

    4. Optional: Set evt_mgmt.alert_groups_reasoning.enable_worknotes to none to prevent group reasoning work note display.

      By default, a work note appears in the Activities tab when a group is created or updated, showing the grouping reason.