Content Based Alert Grouping

Content Based Alert Grouping enables services with predictable, homogenous alert data to have customized alert grouping without training an algorithm. With Content Based Alert Grouping, alerts that share an exact match on a set of chosen fields will be grouped together into the most recent open incident. If an incident remains open for 24 hours, grouping stops and any future alerts will trigger a new incident. Similar to other alert grouping mechanisms, Content Based Alert Grouping will only group alerts on the same service.



This feature is available as part of the Event Intelligence package or on Digital Operations plans. If you would like to sign up for a trial of Intelligent Alert Grouping and other Event Intelligence features, please contact our Sales team.

Configure Content Based Alert Grouping


Required User Permissions

User, Admin, Manager, Global Admin or Account Owner roles can configure Content Based Alert Grouping.

If you're not sure what role you have, or if you need your permissions adjusted, visit our sections on Checking Your User Role or Changing User Roles.


Important Notes

  • Content Based Alert Grouping requires data to be formatted in Common Event Format (PD-CEF).
  • Alerts will only be grouped on exact matches for the entire selected fields.
  1. Select Services Service Directory and click the name of the service where you would like to use Content Based Alert Grouping.
  2. Select the Settings tab and click Edit under the Reduce Noise section.
  3. Select the Content-Based radio button, then click Create Grouping.
  4. Select whether you want alerts to be grouped if All or Any specified fields match. If All is selected, an exact match on every specified field name must occur for alerts to be grouped. If Any is selected, alerts will be grouped when there is an exact match on at least one of the specified fields.
  1. There are two methods for specifying alert grouping fields:
  • On the right side of the screen, select a recently received alert to see the data payload off that specific alert. Directly click on the fields you want to group on and they will be added to your configuration. OR:
  • Select your preferred PagerDuty Alert Fields from the dropdown:
    • Class
    • Component
    • Group
    • Severity
    • Source
    • Summary
    • Custom Details: To use Custom Details field as your grouping criteria, select Custom Details from the drop-down menu, and enter your custom field name. Be sure that your spelling and capitalization exactly match the alert field which you would like to use for grouping. To use a nested Custom Details field, use dot-notation to specify the field name. Note: Dot-notation will only work if your field is nested within an object (not a string).
  1. Click Save Alert Grouping Settings to complete configuration.


How long will alerts group into an incident?

Until the incident is resolved, or up to 24 hours. After this time a new incident will be created.

If I have selected β€˜Any’ for field matching criteria and the following occurs: Alert A has an exact match on one specified field with Alert B; Alert B has an exact match on a different field with Alert C; Alert C has no matching fields with Alert A. How are alerts grouped?

Alert A and B would be grouped into one incident. A new incident would be created for Alert C. Content based alert grouping does not chain fields with subsequent alerts and alerts are grouped into the most recent incident where there is an exact match.

How do I use a nested Custom Details field as part of my Content Based Alert Grouping configuration?

Use dot-notation to specify nested Custom Details fields, such as field_name.nested_field1. Note: Dot-notation will only work if your field is nested within an object (not a string). For example, if your Custom Details looks like {"field_name": "nested_field1 = value, nested_field2 = value"} , entering field_name.nested_field1 will not allow you to group on the nested field. If you want to group on a value from a string, first extract it using Event Rules.

Can I manipulate or merge content of different fields to use as alert grouping criteria?

Yes, with Dynamic Field Enrichment & Extraction.

Updated about a month ago

Content Based Alert Grouping

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.