Create Ignore automation
Ignore automation streamlines the process of disregarding irrelevant or false-positive alerts from monitoring systems, efficiently managing alert fatigue by filtering out unnecessary notifications. This allows teams to focus on critical issues.
Before you begin
Role required: evt_mgmt_admin, evt_team_operator, or srm_responder
About this task
Ignore automations filter out alerts from source monitoring systems that match specific conditions. Separately, Event Management ignores alerts that have a duplicated message key field or where the severity is Clear.
For users familiar with the classic Event Management experience, ignore automations provide a simpler interface with enhanced team support for the event filter section of event rules.
Procedure
What to do next
You can transform raw events into an understandable format by creating Create Enrich automation.