---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Tag cluster alert grouping

# Tag cluster alert grouping {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Tag cluster alert grouping

Tag cluster alert grouping is a no-code alert correlation method that helps ServiceNow customers efficiently group similar alerts without relying on CMDB data or machine learning model training.
This feature reduces alert noise by clustering related alerts based on tags, making alert management simpler and more effective.
Show full answer Show less  
This capability is enabled immediately after activating the Tag-Based Alert Clustering Engine application, available from the ServiceNow Store. Alert grouping is applied according to a configurable correlation logic order, and supports multiple tags linked to grouping definitions on a many-to-many basis. Groups formed through this method are identified as the Tag Cluster group type.

Tag cluster alert grouping supports domain separation, enabling different domains within your organization to maintain independent alert grouping configurations and correlation logic.

## Key Features

* **Tag creation and matching:** Define alert grouping criteria by creating tags that require exact matches, approximate (fuzzy) matches, or pattern matches.
* **Predefined tags and definitions:** Use out-of-the-box tags and alert clustering definitions to accelerate setup. Predefined tags map from alert fields, tags, or additional info, and may populate missing Configuration Item data from the CMDB.
* **Alert clustering definitions:** Attach one or more tags to a definition that specifies alert correlation conditions. Both custom and predefined definitions are supported; predefined ones must be activated before use.
* **Timeframe-based grouping:** Alerts are grouped if their tag values match and their occurrence times fall within a configured timeframe relative to the initial alert.

## Practical Application

After setting up tags and attaching them to clustering definitions, the system automatically collects alerts and groups those with matching tags according to the defined timeframe. This dynamic grouping helps teams focus on consolidated alert groups rather than individual alerts, improving operational efficiency.

## Next Steps

* Create and configure alert clustering tags based on your alert data and grouping needs.
* Create or activate alert clustering definitions, including predefined definitions for faster deployment.
* Attach tags to alert clustering definitions to specify correlation criteria.
* Configure event rules as needed to customize alert content for better tagging and grouping.  
Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar
alerts reduces the overall noise of a large quantity of alerts.

Tag cluster alert grouping is enabled immediately after the activation of the Tag-Based Alert Clustering Engine application, available in the ServiceNow Store. This grouping is applied according to the correlation logic order specified in the [Configure alert correlation logic order](https://servicenow-prod.fluidtopics.net/oC3RGIQrOnC~9K7eeV5eog "Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response efficiency."). Alert grouping tags are attached to definitions on a many-to-many (M2M) basis. Multiple tags can be linked to a single definition, and a tag can be part of multiple
definitions. Groups formed from tag cluster alert grouping definitions are classified as the Tag Cluster group type.

Tag cluster alert grouping supports domain separation, allowing different domains to have their own distinct alert grouping configurations and logic.

First, create alert grouping tags to define the criteria for grouping alerts. You can set the tags to require an exact match, an approximate ('fuzzy') match, or a character pattern match.

You can also use preconfigured tags to speed up alert clustering. These predefined tags are mapped from alerts and are based on information from sources such as the Alert field, Alert tags, or Alert additional info. If the required
data is missing and the selected tag source is Alert CI or Alert CI key, the tag is populated using the Configuration Item (CI) value from the Configuration Management Database (CMDB). Predefined tags are easily identified by their description, which includes out of the box.

You can attach one or more tags to an alert clustering definition, which specifies the conditions for alert correlation. You can either create your own alert clustering definition or use a predefined one provided by the
application. Predefined definitions come with associated tags.  
Important:  
Make sure to activate predefined definitions before use. In new systems, several definitions are active by default. The remaining ones must be activated. For more information, see [Activate a predefined alert clustering definition](https://servicenow-prod.fluidtopics.net/RMUO63zMC91gr1kf9p4vgg "Activate the predefined alert clustering definitions provided with the Tag-Based Alert Clustering Engine application before use. Utilizing these preconfigured definitions minimizes setup time and ensures a more efficient configuration process, allowing for quicker implementation and streamlined alert management.").

Once one or more alert clustering tags are attached to a definition, the system collects alerts and checks if their tags match all the tag values specified in the definition. Alerts with matching or similar tag values are grouped
together. New incoming alerts join an existing group if their tags match the tags in the definition used to create the group.

For tag-cluster grouping, alerts are added to a group based on the timeframe defined in the alert clustering settings. The time between the initial alert (virtual alert) and subsequent alerts is evaluated. If two new alerts are
received, and their time difference falls within the defined timeframe, they are added to the group. The initial event's generation time is used to determine the relevance of the timeframe.
**Related concepts**   

* [Alert tags](https://servicenow-prod.fluidtopics.net/a86ahFC0rNNz9M43s~Lj0g "Alert tags allow consolidation for all normalized fields and improve the admin experience to transform and normalize alert fields (key/value)​ enabling reuse of normalized fields across different sources.​ This improves alert quality for correlation and provides more out-of-the-box TBAC (Tag Based Automatic Correlation) definitions​.")  
**Related tasks**   

* [Create alert clustering tags](https://servicenow-prod.fluidtopics.net/yzl7a6tf9lvnfQ~6K5i5zQ "Create streamlined alert correlations with alert clustering tags by grouping alerts that share identical or similar tags based on your configured match method. This reduces noise, enhances incident prioritization, and improves operational efficiency, enabling faster issue resolution and response times.")
* [Create an alert clustering definition](https://servicenow-prod.fluidtopics.net/VteWdlAQpjSnqQ8c5Bn7Jg "Define alert clustering conditions to trigger one or more alert clustering tags, which help create alert groups from fewer alerts. Creating alert groups from fewer alerts reduces noise, making it easier to identify critical incidents, prioritize responses, and manage issues effectively.")
* [Activate a predefined alert clustering definition](https://servicenow-prod.fluidtopics.net/RMUO63zMC91gr1kf9p4vgg "Activate the predefined alert clustering definitions provided with the Tag-Based Alert Clustering Engine application before use. Utilizing these preconfigured definitions minimizes setup time and ensures a more efficient configuration process, allowing for quicker implementation and streamlined alert management.")
* [Attach a predefined tag to a tag-based alert clustering definition](https://servicenow-prod.fluidtopics.net/jkx_OU1zfmT5o5nDRvUYbg "Get started faster with alert clustering by attaching a predefined alert clustering tag to a tag-based alert clustering definition in Event Management. By associating a predefined tag, you ensure that alerts meeting the specified criteria are grouped effectively, facilitating quicker identification and response to related incidents.")
* [Configure an event rule to customize alert content](https://servicenow-prod.fluidtopics.net/y3wetDYMwXph7QgT~DFEhg "You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert.")

