---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Alert grouping

# Alert grouping {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Alert grouping is the process of organizing and consolidating related alerts into sets based on common characteristics or criteria. This helps in simplifying alert management by reducing noise, making it easier to prioritize,
track, and address issues efficiently. Grouped alerts provide a clearer overview of related incidents, facilitating quicker root cause analysis and remediation.

## How alert grouping works {#c_ServiceAnalyticsOverview__section_fbq_kc1_hdc}

Alert grouping enhances operational efficiency and optimizes alert management by categorizing alerts. Here's how it works:

1. Event consolidation: Event Management collects alerts from multiple sources, providing a centralized view of notifications and alerts. This consolidation enables teams to manage alerts more efficiently and recognize critical issues more easily.
2. Contextual Enrichment: Alerts are enriched with data from the Configuration Management Database (CMDB), which contains detailed information about applications and infrastructure components. This context allows teams to better understand the significance of alerts and prioritize responses based on their impact.
3. Intelligent Correlation: Event Management utilizes different types of machine learning algorithms to automatically group related alerts. This intelligent grouping reduces alert noise by combining similar alerts, allowing teams to concentrate on significant issues rather than being inundated with multiple notifications.
{#c_ServiceAnalyticsOverview__ol_ogp_lc1_hdc}

## Benefits of alert grouping {#c_ServiceAnalyticsOverview__section_pmx_hz5_hcc}

* Creating [automated alert groups](https://servicenow-prod.fluidtopics.net/FHrJ9kDr_Pm28csw30pnmw "Automated alert grouping is a process that uses historical data to automatically organize similar alerts into groups. These alerts could be system issues, like server errors or network outages. By grouping related alerts together, it helps teams quickly identify patterns, manage recurring problems, and reduce the noise from too many individual alerts.") by aggregating alerts based on predefined patterns.
* Correlating alerts using timestamps and CI identification to form automated alert groups.
* Forming [CMDB based alert grouping](https://servicenow-prod.fluidtopics.net/G3z31fQVC3q~AUNJa2cCfg "CMDB based alert grouping helps organizations manage alerts by organizing them according to their related configuration items (CIs) within the Configuration Management Database (CMDB). This method group alerts based on CI relations in applications or infrastructure components, allowing teams to better understand the impact of issues, respond more effectively to alerts, and maintain service availability.") by correlating alerts based on CI relationships in the CMDB.
* Correlating alerts based on text similarity of alerts using NLP (Natural Language Processing).
{#c_ServiceAnalyticsOverview__ul_qmx_hz5_hcc}
**Related tasks**   

* [Synchronizing alert response with automated alert grouping](https://servicenow-prod.fluidtopics.net/RADurNLimnDj8MXyIpc6VA "Synchronize alert response with grouping by ensuring alert management jobs runs after alert grouping jobs—this prevents duplicate actions like incident creation on secondary alerts.")

