Text-based alert grouping
In text-based alert grouping, the EM Alert Clustering Solution forms clusters based on the Description, Metric name, and Configuration item.Class fields. Using this solution, text-based groups are created. When a new alert arrives, the ML Predictor determines which cluster it belongs to, and alerts in the same cluster form a group.
The ML Predictor job is asynchronous and assigns real-time alerts to clusters. There may be slight delays in receiving the predictor's results, causing the creation of text-based groups to be delayed by several minutes, as the alert grouping job runs once per minute. If the prediction results are not ready during the current run, it will recheck during the next run of the grouping job.
- Cluster quality threshold: sa_analytics.alert_grouping_tb_cluster_quality_threshold, default is 70.
- Alert rank threshold: sa_analytics.alert_grouping_tb_alert_rank_threshold, default is 0.3 (smaller values are better).
The EM Alert Clustering Solution definition is located in the ml_capability_definition_clustering table. To access it, navigate to .