Content Based Alert Grouping

Content Based Alert Grouping is a feature that allows service administrators to configure grouping based on their preferred, user-defined field. Accounts working with predictable, homogenous alert data can now customize how alerts are grouped without having to train the algorithm on their specific data. With Content Based Alert Grouping, alerts that share an exact match on the selected field will be grouped together into the most recent open incident. If an incident remains open for 24-hours, grouping stops and any future alerts will trigger a new incident. Similar to other alert grouping mechanisms, Content Based Alert Grouping will only group alerts on the same service.

📘

Note

This feature is available as part of the Event Intelligence package or on Digital Operations plans. If you would like to sign up for a trial of Intelligent Alert Grouping and other Event Intelligence features, please contact our Sales team.

Configure Content Based Alert Grouping

🚧

Required User Permissions

User, Admin, Manager, Global Admin or Account Owner roles can configure Content Based Alert Grouping.

If you're not sure what role you have, or if you need your permissions adjusted, visit our sections on Checking Your User Role or Changing User Roles.

📘

Important Notes

  • Grouping can only be set up to one Common Event Format (PD-CEF) field.
  • Content Based Alert Grouping requires data to be formatted in PD-CEF.
  • Alerts will only be grouped on exact matches for the entire selected field.
  1. Select Configuration Services and click the name of the service where you would like to use Content Based Alert Grouping.
  2. Select the Response tab and click Edit under the Alert Grouping section.

Configure Content Based Alert Grouping

  1. Under How should alerts be grouped into incidents on this service?, select Based on the content of the alert and select your preferred PagerDuty Alert Field from the dropdown:
  • Class
  • Component
  • Group
  • Severity
  • Source
  • Summary
  • Custom Details: To use Custom Details field as your grouping criteria, select Custom Details from the drop-down menu, and enter your custom field name. Be sure that your spelling and capitalization exactly match the alert field which you would like to use for grouping. To use a nested Custom Details field, use dot-notation to specify the field name.

Select Content Based Alert Grouping and PagerDuty Alert Field

Alert Field Option: Custom Details

  1. Click Save Alert Grouping Settings to complete configuration.

Updated 8 days ago

Content Based Alert Grouping


Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.