<h2>Tag cluster alert grouping</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2025" /><meta name="DC.rights.owner" content="(C) Copyright 2025" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="concept" /><meta name="DC.title" content="Tag cluster alert grouping" /><meta name="abstract" content="Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts." /><meta name="description" content="Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts." /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/concept/Alert-Groups.html" /><meta name="DC.relation" scheme="URI" content="../../../product/it-operations-management/reference/r_ITOMApplications.html" /><meta name="DC.relation" scheme="URI" content="../../../product/it-operations-management/reference/itom-health-landing-page.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/concept/c_EM.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/concept/using-event-management.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/concept/c_ServiceAnalyticsOverview.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/task/alert-clustering-tags.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/task/alert-clustering-definitions.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/task/alert-clustering-cis.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/task/alert-clustering-predefined-definition.html" /><meta name="DC.relation" scheme="URI" content="../../../product/event-management/task/alert-clustering-predefined-tag.html" /><meta name="DC.relation" scheme="URI" content="../task/alert-clustering-tags.html" /><meta name="DC.relation" scheme="URI" content="../task/alert-clustering-definitions.html" /><meta name="DC.relation" scheme="URI" content="../task/alert-clustering-predefined-definition.html" /><meta name="DC.relation" scheme="URI" content="../task/alert-clustering-predefined-tag.html" /><meta name="DC.relation" scheme="URI" content="../task/t_EMComposeOuput.html" /><meta name="DC.relation" scheme="URI" content="alert-tags.html" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2024-08-01" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="alert-clustering-tag-definitions-concept" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Tag cluster alert grouping</title></head><body id="alert-clustering-tag-definitions-concept"> <div class="breadcrumb"><a class="link" href="../../../product/it-operations-management/reference/r_ITOMApplications.html" title="Get better visibility into your infrastructure and services, prevent service outages, and expand your organization's operational agility with ServiceNow IT Operations Management.">IT Operations Management</a> > <a class="link" href="../../../product/it-operations-management/reference/itom-health-landing-page.html" title="The ServiceNow ITOM Health product includes the ServiceNow Event Management and ServiceNow Metric Intelligence applications, which help you track and maintain the health of services in your organization.">ITOM Health</a> > <a class="link" href="../../../product/event-management/concept/c_EM.html" title="The ServiceNow Event Management application helps you to identify health issues across the datacenter on a single management console. It provides alert aggregation and root cause analysis (RCA) for discovered services, application services, and automated alert groups. Event Management is available as a separate subscription from the rest of the ServiceNow platform.">Event Management</a> > <a class="link" href="../../../product/event-management/concept/using-event-management.html" title="Event Management administrators administer events, manage and monitor alerts, aggregate alerts, and work review and monitor services' status with the Operator Workspace service monitor.">Configuring Event Management</a> > <a class="link" href="../../../product/event-management/concept/c_ServiceAnalyticsOverview.html" title="Alert grouping is the process of organizing and consolidating related alerts into sets based on common characteristics or criteria. This helps in simplifying alert management by reducing noise, making it easier to prioritize, track, and address issues efficiently. Grouped alerts provide a clearer overview of related incidents, facilitating quicker root cause analysis and remediation.">Alert grouping</a> > </div> <h1 class="title topictitle1" id="ariaid-title1">Tag cluster alert grouping</h1> <div class="body conbody"><p class="shortdesc">Tag cluster alert grouping enables you to easily create groups of alerts. It is a non-code method of alert grouping that correlates alerts without having to use CMDB or model training. This simpler way of grouping similar alerts reduces the overall noise of a large quantity of alerts.</p> <p class="p">Tag cluster alert grouping is enabled immediately after the activation of the Tag-Based Alert Clustering Engine application, available in the <span class="ph">ServiceNow Store</span>. This grouping is applied according to the correlation logic order specified in the <a class="xref" href="../task/configure-alert-correlation-logic-order.html" title="Improve alert management by enabling users to customize correlation logic order. This feature empowers you to fine-tune correlation methods to their specific needs, enhancing alert prioritization and response efficiency.">Configure alert correlation logic order</a>. Alert grouping tags are attached to definitions on a many-to-many (M2M) basis. Multiple tags can be linked to a single definition, and a tag can be part of multiple definitions. Groups formed from tag cluster alert grouping definitions are classified as the Tag Cluster group type.</p> <p class="p">Tag cluster alert grouping supports domain separation, allowing different domains to have their own distinct alert grouping configurations and logic.</p> <p class="p">First, create alert grouping tags to define the criteria for grouping alerts. You can set the tags to require an exact match, an approximate ('fuzzy') match, or a character pattern match.</p> <p class="p">You can also use preconfigured tags to speed up alert clustering. These predefined tags are mapped from alerts and are based on information from sources such as the Alert field, Alert tags, or Alert additional info. If the required data is missing and the selected tag source is Alert CI or Alert CI key, the tag is populated using the Configuration Item (CI) value from the <span class="ph">Configuration Management Database (CMDB)</span>. Predefined tags are easily identified by their description, which includes 'out of the box.'</p> <p class="p">You can attach one or more tags to an alert clustering definition, which specifies the conditions for alert correlation. You can either create your own alert clustering definition or use a predefined one provided by the application. Predefined definitions come with associated tags.</p> <div class="p"> <div class="note important"><span class="importanttitle">Important:</span> Make sure to activate predefined definitions before use. In new systems, several definitions are active by default. The remaining ones must be activated. For more information, see <a class="xref" href="../task/alert-clustering-predefined-definition.html" title="Activate predefined alert clustering definitions provided with the Tag Based Alert Clustering Engine application before use. Using these preconfigured definitions minimizes setup time.">Activate a predefined alert clustering definition</a>.</div> </div> <p class="p">Once one or more alert clustering tags are attached to a definition, the system collects alerts and checks if their tags match all the tag values specified in the definition. Alerts with matching or similar tag values are grouped together. New incoming alerts join an existing group if their tags match the tags in the definition used to create the group.</p> <p class="p">For tag-cluster grouping, alerts are added to a group based on the timeframe defined in the alert clustering settings. The time between the initial alert (virtual alert) and subsequent alerts is evaluated. If two new alerts are received, and their time difference falls within the defined timeframe, they are added to the group. The initial event's generation time is used to determine the relevance of the timeframe.</p> </div> <div class="related-links"> <ol class="olchildlinks"><li class="link olchildlink"><a href="../../../product/event-management/task/alert-clustering-tags.html">Create alert clustering tags</a><br /> Alert clustering tags represent an improved way to correlate alerts. Alerts with identical or similar tags (depending on the configured match method) are joined together to form a group.</li><li class="link olchildlink"><a href="../../../product/event-management/task/alert-clustering-definitions.html">Create an alert clustering definition</a><br /> An alert clustering definition determines the conditions that must be met for invoking one or more alert clustering tags. Alert clustering tags enable you to create an alert group from fewer alerts.</li><li class="link olchildlink"><a href="../../../product/event-management/task/alert-clustering-cis.html">Create key values to cluster alerts</a><br /> Create key values to cluster CIs, using the Key Values table. Key values create an additional way to determine commonality between alerts and to combine them into groups. For example, you may want to group alerts on CIs that share the same supplier or location.</li><li class="link olchildlink"><a href="../../../product/event-management/task/alert-clustering-predefined-definition.html">Activate a predefined alert clustering definition</a><br /> Activate predefined alert clustering definitions provided with the Tag Based Alert Clustering Engine application before use. Using these preconfigured definitions minimizes setup time.</li><li class="link olchildlink"><a href="../../../product/event-management/task/alert-clustering-predefined-tag.html">Attach a predefined tag to a tag-based alert clustering definition</a><br /> Get started faster with alert clustering by attaching a predefined alert clustering tag to a tag-based alert clustering definition in <span class="ph">Event Management</span>.</li></ol> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="../../../product/event-management/concept/Alert-Groups.html" title="Alerts are grouped into various types to streamline problem identification and management. An alert can belong to only one alert group at a time.">Alert grouping types</a></div> </div> <div class="linklist relinfo relconcepts"><strong>Related concepts</strong><br /> <ul class="linklist"><li class="linklist"><a class="link" href="alert-tags.html" title="Alert tags allow consolidation for all normalized fields and improve the admin experience to transform and normalize alert fields (key/value) enabling reuse of normalized fields across different sources. This improves alert quality for correlation and provides more out-of-the-box TBAC (Tag Based Automatic Correlation) definitions.">Alert tags</a></li></ul></div> <div class="linklist relinfo reltasks"><strong>Related tasks</strong><br /> <ul class="linklist"><li class="linklist"><a class="link" href="../task/alert-clustering-tags.html" title="Alert clustering tags represent an improved way to correlate alerts. Alerts with identical or similar tags (depending on the configured match method) are joined together to form a group.">Create alert clustering tags</a></li><li class="linklist"><a class="link" href="../task/alert-clustering-definitions.html" title="An alert clustering definition determines the conditions that must be met for invoking one or more alert clustering tags. Alert clustering tags enable you to create an alert group from fewer alerts.">Create an alert clustering definition</a></li><li class="linklist"><a class="link" href="../task/alert-clustering-predefined-definition.html" title="Activate predefined alert clustering definitions provided with the Tag Based Alert Clustering Engine application before use. Using these preconfigured definitions minimizes setup time.">Activate a predefined alert clustering definition</a></li><li class="linklist"><a class="link" href="../task/alert-clustering-predefined-tag.html" title="Get started faster with alert clustering by attaching a predefined alert clustering tag to a tag-based alert clustering definition in Event Management.">Attach a predefined tag to a tag-based alert clustering definition</a></li><li class="linklist"><a class="link" href="../task/t_EMComposeOuput.html" title="You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert.">Configure an event rule to customize alert content</a></li></ul></div> </div> </body></html></div>