---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Mixed alert grouping

# Mixed alert grouping {#ariaid-title1}

* Release version: Zurich
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Mixed alert grouping combines multiple strategies---currently CMDB-based and tag-based grouping---to form a single, cohesive alert group. It reduces noise, bridges gaps when one method isn't enough, and delivers a clearer,
end-to-end view of incidents. This approach helps operators identify root causes faster and take informed action, even in complex or incomplete data environments.

To understand how Mixed grouping works in practice, it's important to look at the individual strategies it currently supports. At this stage, Mixed Grouping comprises two core methods: [CMDB based alert grouping](https://www.servicenow.com/docs/ss18Twptl0FqMp6sac9Esg "CMDB based alert grouping helps organizations manage alerts by organizing them according to their related configuration items (CIs) within the Configuration Management Database (CMDB). This method group alerts based on CI relations in applications or infrastructure components, allowing teams to better understand the impact of issues, respond more effectively to alerts, and maintain service availability."), which leverages service relationships defined in the CMDB, and [Tag cluster alert grouping](https://www.servicenow.com/docs/wo2B9OTDXZtqeoO2xcMqkQ "Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts."), which uses shared metadata across alerts. Each plays a distinct role in correlating related alerts effectively.

If you're looking to group alerts, see [Create Group automation](https://www.servicenow.com/docs/w9MxnVFbX1z6~2jywYZoLQ "Grouping automation helps you manage alerts more effectively by collecting similar alerts together. This makes it easier to see patterns, quickly identify issues, and respond efficiently. By organizing alerts in this way, you can reduce alert noise, identify root causes, and assign them to the appropriate teams.").

