Tag Based Alert Clustering Engine release notes
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of Tag Based Alert Clustering Engine release notes
The Tag Based Alert Clustering Engine is a zero-code ServiceNow application designed to simplify alert grouping and correlation using tags, bypassing the need for CMDB dependencies, model training, or fine-tuning. It operates alongside existing alert correlation methods and allows immediate activation to enhance alert management efficiency.
Show less
Key Features
- AI-Driven Grouping Recommendations: Monthly generated, actionable suggestions for smart alert grouping automation accessible via the Alert Automation > Group page, with easy activation using Now Assist.
- Advanced Grouping Criteria: Inclusion of new grouping options such as Related Log Properties (HLA), Impacted Service Instance, and combined CI relationships with tags for more precise alert grouping reflecting organizational structures.
- Group Formation Controls: Advanced options like Minimum Threshold and Seed Alert filters enable customers to create meaningful and concise alert groups by setting prerequisites for group creation.
- Simulation and Testing: Tag-Based Alert Clustering Simulation allows users to test and evaluate grouping configurations within the Service Operations Workspace before deployment.
- Predefined Clustering Definitions: Availability of out-of-the-box clustering definitions that customers can utilize or customize, with periodic updates to maintain relevance.
- Improved Virtual Alert Aggregation: Clustered alerts are grouped under virtual alerts rather than individual real alerts, enhancing clarity in alert presentation.
- Team-Based Rule Execution: Support for team-level alert grouping rules executed only for assigned alerts to improve operational alignment.
Key Outcomes
- Enables ServiceNow customers to automate and optimize alert grouping based on tags and relationships, reducing alert noise and improving incident response efficiency.
- Provides flexible and scalable alert clustering options that align with organizational structures and service impact, enhancing situational awareness.
- Facilitates easy implementation and testing of grouping rules with simulation tools and AI-driven recommendations, minimizing configuration errors and administrative overhead.
- Ensures ongoing improvements and fixes through regular updates, addressing performance, scalability, and usability to maintain a robust alert clustering experience.
Version history for the Tag Based Alert Clustering Engine on the ServiceNow Store.
Important:
For details on system requirements and family compatibility, view the application
listing on the ServiceNow Store
website.
Version history
- Version 18.24.4 - July 2026
- Fix query_range SA on sn_em_tbac_sim_session_alerts.*
- Version 18.24.0 - June 2026
- New: Poactive grouping recommendations are now accessible on the Alert Automation > Group page.Our advanced AI-driven data science model generates these insightful recommendations each month, analyzing alerts to suggest smart grouping automation based on tags. Transforming each recommendation into a rule is a breeze—just a single click with Now Assist lets you review, test, and activate them effortlessly. Dive in and explore this game-changing feature today!
- Version 18.22.0 - May 2026
- Fixed: Fixed performance and scalability issue
- Version 18.20.2 - March 2026
- New:
- Two additional grouping criteria have been added to the "Mixed Group" options:
- Related Log Properties (HLA): This allows you to create grouping automations that combine HLA and Event Management alerts within a single group.
- Impacted Service Instance: This enables you to adjust the grouping based on your organizational structure.
- Additionally, a new "Advanced Options" section has been introduced, allowing you to set prerequisite rules for group creation:
- Minimum Threshold: This option lets you configure a specific number (two or more) of alerts that must match the rule before the group is formed, helping you create more concise and effective groups.
- Seed Alert: This feature lets you define a filter that requires at least one alert in the group to meet before the group is formed, resulting in more meaningful groupings.
- Two additional grouping criteria have been added to the "Mixed Group" options:
- New:
- Version 18.18.3 - December 2025
- New: We’ve upgraded the Mixed Groups option with new grouping capabilities. You can now group by Service Instance, Related Logs Entities (HLA), or both to create precise and effective alert grouping rules.
- Version 18.17.1 - August 2025
- New: You can now create grouping definitions that combine CI relationships and tags, allowing more flexible and accurate alert grouping.
- Version 18.14.0 - May 2025
- No updates.
- Version 18.12.3 - February 2025
- Two minor fixes.
- Version 18.12.1 - November 2024
-
- Changed: Group simulation order is now executed in an ascending order
- Fixed:
- Fixed time window settings for Tag Based groups
- Removing unnecessary error message when saving a new Tag Clustering definition
- Version 18.11.2 - October 2024
- Fixed: Groups are not being properly updated when new tags are added to an existing definition.
- Version 18.10.2 - August 2024
-
- New: Enable group simulation using the Alert Automation in Service Operations Workspace.
- Fixed:
- Fixed upgrade of tag-based clustering definition.
- Fixed the population of the Assignment Group field.
- Version 18.8.0 - July 2024
-
- Fixed:
- Pattern match happens when source type is one of: additional_info, alert_tags, and cmdb_key_value.
- Group criteria is working only for alerts with non empty value.
- ACL for the assignment group field.
- If a field is selected for group criteria, only alerts with not empty field value are grouped.
- Fixed:
- Version 18.7.2 - June 2024
-
- New:
- Tag-Based Alert Clustering Simulation: Helps users test and assess their implementation using simulation mode.
- Team-Based Rules: Adds the option for team-level rules that are executed only for assigned alerts.
- Out-of-the-Box Alert Clustering Definitions.
- New:
- Version 18.6.0 - March 2024
-
- New: 12 new out-of-the-box Tag-based Alert Clustering definitions created.
- Removed: 4 existing out-of-the-boxTag-based Alert Clustering definitions removed for new customers.
- Version 18.5.3 - August 2023
- Fixed: Fixing issues related to the custom description of Tag-Based groups.
- Version 18.4.8 - May 2023
-
New: Clustered alerts are aggregated under a virtual alert rather than one of the real alerts (available starting Vancouver).
- Version 18.3.3 - November 2022
-
- New: Supporting alert tags field for alert clustering
- Fixed:
- Fixed the link in the blue box message
- Fixed localization issues
- Version 18.2.10 - April 2022
- Fixed: Fixing tags and clustering definitions in a domain separated instance
- Version 18.1.4 - November 2021
-
- New:
- Support tags on CI keys from cmdb_key_value table
- Support platform patterns on tags to extract values
- Exclude list property for alert fields
- Fixed: Bug fixes
- New:
- Version 18.0.6 - August 2021
- New: The Tag Based Alert Clustering Engine app is a zero-code method that simplifies alert grouping and performs alert correlation without the need for CMDB, model training, or fine-tuning. The tag-based clustering capability enables alert clustering immediately from activation and works in parallel with existing ServiceNow alert correlation algorithms.