|docs
Start Trial

AI & Automation

Time-Based Alert Grouping

Automatically group incoming alerts into open incidents based on the time they are generated

View as Markdown

Time-Based Alert Grouping automatically adds alerts to an open incident for a predetermined period. This feature is helpful for services that generate many alerts. Grouped alerts mean fewer incidents and interruptions for responders, richer context for triggered incidents, and lower resolution times.

AIOps / Signal Intelligence Feature

This feature is included with the PagerDuty AIOps add-on, or included as Signal Intelligence in PD Reliability Platform plans.

If you would like to sign up for a trial of PagerDuty AIOps features, please read PagerDuty AIOps Trials.

AIOps Service Configuration

Your service configuration must have AIOps enabled in order to use this feature. AIOps Service Configuration is in Limited General Availability. Please refer to Configurable Service Settings for more information and enablement steps.

Legacy Availability

This feature is also available with Legacy Event Intelligence.

Required User Permission

You can edit a service's alert grouping settings if you have one of the following roles:

  • Account Owner
  • Admin and Global Admin
  • User
  • Manager base role and team roles
    • Manager team roles can only manage services associated with their team.

Enable Time-Based Alert Grouping

  1. In the web app, navigate to Services Service Directory and click your preferred service's name.
  2. Select the Settings tab and click New Grouping or Edit in the Reduce Noise section.
  3. Select Time only and select a duration from the dropdown.
The PagerDuty web app showing how to enable Time-Based Alert Grouping
Enable Time-Based Alert Grouping
  1. Click Save.

Disable Time-Based Alert Grouping

  1. In the web app, navigate to Services Service Directory and click the name of your desired service.
  2. Select the Settings tab and click Edit in the Reduce Noise section.
  3. In the bottom-left, click Delete. In the confirmation modal, click Delete again.
    • Note: This action cannot be undone.

Time-Based Alert Grouping Behavior

When you enable Time-Based Alert Grouping on a service, the first alert creates a new incident. Subsequent alerts add to that incident for the specified time period while the incident remains open (that is, triggered or acknowledged). If the incident resolves within the selected time period, the timer stops, and subsequent alerts do not group into that incident.

The timer restarts when the next alert on that service arrives and triggers a new incident. If the incident does not resolve within the selected time period, the incident remains open and the next alert triggers a new incident. Subsequent alerts group into the most recent incident.

If you select until incident is resolved for the duration of the timer, the first alert on the service triggers an incident and all subsequent alerts group into that incident until it resolves, regardless of how much time passes.

Time-Based Alert Grouping Example

This example uses a Shopping Cart service with a one-hour time-based alert grouping window.

TimeExample 1: Incident resolves within 45 minutesExample 2: Incident does not resolve within one hour
10:00 a.m.TRIGGER: An alert triggers and creates Incident 1. The one-hour timer begins, set to group all new alerts on the Shopping Cart service into Incident 1 until 11:00 a.m.TRIGGER: An alert triggers and creates Incident 1. The one-hour timer begins, set to group all new alerts on the Shopping Cart service into Incident 1 until 11:00 a.m.
10:07 a.m.ACKNOWLEDGE: Responder acknowledges Incident 1.ACKNOWLEDGE: Responder acknowledges Incident 1.
10:15 a.m.Five more alerts come in on Shopping Cart. Incident 1 now has six alerts, all triggered.Five more alerts come in on Shopping Cart. Incident 1 now has six alerts, all triggered.
10:45 a.m.RESOLVE: The responder resolves Incident 1. New alerts on the Shopping Cart service no longer group into Incident 1.Incident 1 remains in the acknowledged state and groups alerts.
10:55 a.m.TRIGGER: An alert comes in on the Shopping Cart service and creates Incident 2. A new one-hour timer begins, set to group all new alerts on the Shopping Cart service into Incident 2 until 11:55 a.m.An alert comes in on Shopping Cart and groups into Incident 1. Incident 1 now has seven alerts: three resolved, four triggered.
11:00 a.m.Incident 1 is resolved, Incident 2 is triggered with one alert.Incident 1 remains acknowledged, the timer expires, and PagerDuty no longer actively groups new alerts into Incident 1. Incident 1 is acknowledged with seven alerts.
11:10 a.m.An alert comes in and groups into Incident 2. Incident 2 now has two alerts.TRIGGER: An alert comes in and creates Incident 2. The one-hour timer begins, set to group all new alerts on the Shopping Cart service into Incident 2 until 12:10 a.m.

FAQ