Skip to main content
Alert sources can fire many alerts for the same underlying issue. Alert grouping groups those related alerts into a single alert group, so you can triage, escalate and attach them to an incident once — instead of handling each alert on its own.
We’re currently migrating organisations onto our new alert grouping. While your organisation is being migrated, you may not yet be able to configure grouping outside of incidents. Once you’re fully migrated, you’ll have access to the full experience as described in this help doc. To read more about the migration, see here

How it works

When grouping is enabled on an alert route, each incoming alert is matched to a group using the attributes you’ve chosen to group by, such as service or region. Alerts that share a key join the same group, as long as they arrive within the group’s time window. Windows can be configured in two ways:
  • Fixed window — the group stays open for a set time after it’s created.
  • Extending window — the window resets each time a new alert joins, so the group stays open while related alerts keep arriving.
An alert group is a bucket of alerts and it takes its title and description from the first alert to join.
An alert group for a PodCrashLooping alert, showing five grouped alerts in the left pane and, on the right, the
group's related incidents, related escalations, and a timeline recording that the group was created by grouping on
Alert Title within an extending 30-minute window

Setting up grouping

Grouping can be configured per alert route:
  1. Open the alert route you want to group alerts on.
  2. Enable grouping and choose the attributes to group by.
  3. Choose a fixed or extending window. a. A fixed window means the alert group will close at the set time after the first alert has arrived. b. An extending window will close the alert group at the set time after the most recent alert has arrived.
The Group alerts configuration on an alert route, with grouping turned on, a 30-minute window set to Extending, and
alerts grouped by Alert Title
You can then choose to create an incident from grouped alerts, and whether alerts should also create escalations. When they do, you control how a group pages as new alerts join:
  • On every new alert — page each time an alert joins the group.
  • On priority increase — only page when an alert with a higher priority joins the group.
  • After a grace period — wait a set number of minutes before paging, giving you time to action the alert first.
The escalation options for an alert group, with choices for On every new alert, On priority increase, and After a
grace period, and a grace period set to 5 minutes

Attaching groups to incidents

If incident creation is enabled on the route, alert groups are attached to incidents automatically. You can also attach a group to a new or existing incident yourself.

Managing alerts in a group

Sometimes an alert doesn’t belong in the group it’s landed in. Take one or more alerts out of a group by clicking Ungroup, either for a single alert from its own page, or for several at once from the bulk actions bar. From the dashboard, Slack, or Microsoft Teams, this shows you what the alert route would do with the ungrouped alerts, pre-filled and editable, so you can review and confirm rather than guess:
  • Do you want to create an incident?: create a new incident (pre-filled with the title, severity, type, and any custom fields the alert route would have set, and fully editable), merge into an existing incident, or don’t create one.
  • Do you want to escalate to anyone?: escalate to the people or escalation path the alert route would have paged (also editable), or don’t escalate.
Choosing not to create an incident and not to escalate simply removes the alerts from the group and does nothing else.

Private alerts

If you’ve created a private alert route then you’ll be able to group those alerts and create private alert groups. The visibility of private alert groups is inherited from the visibility of the constituent alerts.

Alert group limit

We have a limit of 1,000 alerts joining an alert group. Once that limit has been reached, we’ll create a new alert group for subsequent alerts to group into. If this is an issue for your organisation, then please get in touch.

Alert grouping migration

Whether you move across all at once or gradually depends on whether your organization has at least one alert route that currently groups alerts into incidents. If you don’t, there’s nothing to switch over, so we’ll migrate you fully from the start. You’ll be able to configure alert grouping straight away from your alert route configuration. If you do, we’ll start migrating you gradually. We do this to prevent both the old and new flows each creating incidents or escalations. During this period, some alerts will still group into incidents using the old flow while others start forming alert groups using the new one. Here’s how the handover works for a given attribute that you’re grouping by (e.g. Alert title)
  • While alerts keep arriving within the grouping window, we continue grouping them into incidents using the old flow.
  • Once the grouping window closes, new alerts for that attribute will start forming an alert group using the new flow. Depending on how your alert route is configured, it’ll then create an incident and escalation.
  • Because the old flow’s window always extends, alerts will only begin to be grouped into alert groups once there’s a gap between alerts arriving that is longer than the grouping window duration.
  • An alert will only be processed by the old or new flow; never both.
While you’re migrating, you’ll get the core new experience — alerts group automatically and you can ungroup any that don’t belong — but the extra configuration options listed above are unavailable until the migration finishes. The migration finishes when across all of your alert routes with grouping configured, there aren’t any open incidents that an alert could group into.

What’s changing

Old behavior
  • We’d only allow you to group alerts into an incident.
    • If you used Suggested alert grouping, we didn’t group alerts automatically — we’d ask whether you want to relate each alert to the incident.
    • If you used Automatic grouping, we’d create and then cancel escalations for each alert being grouped.
  • The grouping window always extended — i.e. if a new alert arrived, the window would extend again.
New behavior
  • Once you’re fully migrated, you have more control:
    • Choose whether the grouping window is extending or fixed.
    • Fine-grained control over how alerts joining a group then escalate.
    • Group alerts without creating an incident.
  • We attach alerts to the relevant alert group for you automatically, and you can ungroup any that don’t belong.
  • We don’t automatically cancel any escalations made from alerts in a group, as we did if you had previously configured Automatic grouping in the old flow.

FAQs

Not yet — a group’s title and description come from the first alert to join it, and aren’t editable.
No. Groups close automatically when their window expires, or when all attached incidents are resolved. You can resolve a group’s alerts, but there’s no manual close.
As part of the alert routing configuration, you can choose a Slack or Teams channel to post messages when alerts go through the route. These messages don’t currently contain information about the alert group.
The grouping window is configurable per alert route, up to a maximum of 48 hours — we preselect 30 minutes when you first enable grouping, but you can choose any duration in that range, as either a fixed or extending window. If a new alert arrives after the window has expired, it starts a new alert group (and, if the route creates incidents, a new incident).