---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Configure alert correlation logic order

# Configure alert correlation logic order {#ariaid-title1}

* Release version: Yokohama
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response
efficiency.

## Before you begin

Role required: admin

## Procedure

1. Navigate to AllSystem PropertiesAll Properties.
2. Search for the property sa_analytics.agg.query.group_logic_order.  
   Default value is "CMDB,NETWORK_TRAFFIC,TAG_BASED,PATTERN,TEXTBASE". This is a comma separated list of the grouping types in the order of their execution.  
   Note:  
   If one of the grouping types is not specified in the property, it needs to be added manually. Alert correlation rules are trigger-based and applied immediately when an alert is created or updated, before other grouping algorithms.  
   * CMDB: CMDB grouping
   * NETWORK_TRAFFIC: Network traffic grouping
   * TAG_BASED: Tag cluster grouping
   * PATTERN: Automated CI-based patterns grouping
   * TEXTBASE: Text-based grouping
   {#configure-alert-correlation-logic-order__ul_asp_hhl_xbc}
3. Use the property sa_analytics.agg.query.group_logic_order to define or modify the order of correlation methods based on your preferences.
**Related concepts**   

* [Alert grouping and use cases](https://servicenow-prod.fluidtopics.net/uR0fwbMTSu3Dxk8LkwyZqA "Alert grouping methods range from user-defined approaches, like Manual, Rule-based, and Tag-cluster, to advanced, fine-tunable algorithms, including Automatic, CMDB, Text-based, Log Analytics, and Network Traffic-based grouping.")

*[\>]: and then


