*Version: 1.0 | Last Updated: 2025-05-12* ## Overview - **Feature Name:** GROUP BY - **Audience:** Administrators, Support team - **Prerequisites:** Understanding of MoovingON AI --- ## Table of Contents 1. [[#Introduction]] 2. [[#Getting Started]] 3. [[#Usage Instructions]] 4. [[#Usage Examples]] 5. [[#Related Links]] --- ## Introduction The "**Group By**" option for incidents allows users to receive a new incident for each service or host whenever conditions match the defined rules. By default, the "**Group By**" function is set to "**None**," meaning it is disabled. - **What is this feature?** - **Incident Creation Based on Grouping**. - How Incidents are Triggered: - When alerts meet the rule conditions and the required threshold, incidents will be created. - The system generates separate incidents for each host or service, depending on the chosen “**Group By**” option. Example: If grouping is set to Host, each unique host that meets the criteria will trigger a separate incident. - **Handle incidents**. - Manage Separate Incidents: - Each generated incident is handled individually. - Users must review and resolve each incident separately based on its specific details and alerts. --- ## Getting Started ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfYwOe_N998uuLprkrHu-GOkOrkAfcbuSEdrFXf8V-SzRkzcs8xq5uGzLAz1pWRb8tnr6nf2KpejPFED4pXvCdKQQek-5uC-gL56g9gY8lG1OpxAOalq8dI3VpcV3x8InhZhlhWRw?key=fGirOmmwKPn4MoEVOpftmPwT) - **Why is it useful?** - **Incident Rules**: - Incident rules define the conditions under which an incident is triggered. - These rules evaluate incoming alerts based on predefined criteria. - The system checks if an alert matches the specified conditions and whether it meets the required threshold before creating an incident. - **Logic Inside Rules**: - Check, Condition and String will define the alerts added to the incident. - "**Threshold**" in the top right corner determines the number of alerts that will trigger the incident - The "**plus**" symbol in the top left corner will add a condition to the rule. ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfvuiIinTNTcIMSi1SV0Ye-Azz8doPEUcZgqk5VPDo7u9ZG_hsVtd3TVJ7mks-ljeBJPJfPmY7fffY-5UeppvzFH00m6NAtzln8Hu8_oict-MZOdOvwDEkjpBuCkki_0Xz3_QX9zg?key=KBEKAuRqwRONFDBsNTxVIo1q) Additionally, the incident rules can be configured using these filters: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdxawl-MzAj-bC0Cy7FBoHjclZ3xZsNwLs3rFckEBSC7s4sWNL5pZrYG2b9ifrC_Ca3XDCvK-_t2nplA_j8V0pYOs81zMqW5ZU0bttFF4Vw7FOZ6HP5LANQGBM5pqYNojKS9jVeLg?key=KBEKAuRqwRONFDBsNTxVIo1q) In the "**Check**" value, we select the criteria that determine whether alerts are included in this manual incident. If the chosen "**Check**" value contains the inserted value, it will be assigned to the incident. Explanation regarding each option: - **Host**: Alert's host - **Service**: Alert's service - **Group**: To which group does the alert relate - **Template**: The template used to parse the alert. - **Flapping**: Indicates that the alert was triggered and recovered repeatedly within a short period of time. - **Alert Age**: The lifespan of the alert. - **Value**: Alert's value - **Custom Tag**: All custom fields that were added through the templates. - **Logic Between Rules**: - The rules operate using logical conditions (AND/OR) to determine if an alert qualifies for an incident. - If multiple conditions exist, they must be met by the rule’s logic settings. ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfld5H0q5ZPS44L0uvuiRf9Nju3K3DDx6JeRQi3IQGThzJxrvMwVWi0OFQY8vl4YlRUlDD2Nj0OtH3BMlG1fdcusg788k7YpC7wbA3sXTE67BeV4QnQYUWS8AoPr46ItHrDJS0Afg?key=fGirOmmwKPn4MoEVOpftmPwT) - **Group By**: This feature identifies the grouping of the created incident/s. The options we have, is for the incident to be grouped by: **Host**, **Service** or **None** (Not defined) - Configure the "**Group By**" Option. - Select a Field for Grouping: - Choose a field to group incidents by using the “**Group By**” option. - Available options: Service or Host. - Selecting None disables grouping, meaning all matching alerts will be handled under a single incident. ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXd-Dt2Edc9o8sgpWcJwXiQ7Q6w2CVF3W9AVXYvO68NNPyJ-u40OXBNIpiBofp_6OovyAJxTEqBYtXMFRc7sXXRHpmfxct5IQFRQXwLvQJUkxF_P2TJWzuZrw62vJTQl4N2_wqlm?key=fGirOmmwKPn4MoEVOpftmPwT) - **Incident Recovery Settings**: The handling of incidents can be configured with the following options: **Related Alert Recovery** or **Manual Close (no recovery)**. - **Automatic (Recover Incident)**: The incident is automatically recovered when the related alert is resolved. - **Manual (Close Incident Manually)**: The incident must be closed manually, regardless of the status of related alerts. **![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdVgXJb8IStBKnXn78exr1nFAcsUndVd5u2cWMdCTX3dvMDVX5T8KPh9QKJ7EFyq6KJK-zHxtL-UI4926Rv3ZS_hhVKIGtMVTgQGicz5htO3NzEuSu81m7MhXMqP3YTov1NWMxj?key=KBEKAuRqwRONFDBsNTxVIo1q)** - **Incident Settings**: Incident General settings for the incident: - **Host**: The host value used in the incident - **Service**: The service value used in the incident - **Guidelines**: - **Warning Guideline**: Runbook assigned in case of **Warning** status - **Critical Guideline**: Runbook assigned in case of **Critical** status - **Planned downtime Guideline**: Runbook assigned in case of **Planned downtime** - **Dashboards**: The dashboard which the incident relates to **![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfpqzUeIRsKcf4_QqoLTCqyc64PZ9z9UGhOZldqJ5DKzF2T7GEt8etPFXla4M1liaarlxpPsIxG5DPrR1c1VWavuvD_u90MARBRytmF_o3HA3UUM3Dk8d4qNHf6FNRhm_FRtg-GOg?key=KBEKAuRqwRONFDBsNTxVIo1q)** - **Override Runbook**: Turning this option **ON**, disables the initial runbook of the alert, and runs through the designated runbook of the incident **![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeJrNgghgLnhOzK4RooHDURhEDD9O9TjJ8R-Vyrepe_9SHdgeZpT_ryW1gGf5M2Qc2hdYYeUcYZbpXUJAk68o91VSJE1eEi1oSORFn6u5Rnu5em9FIIDpUnl4frEg7ezixX5BrU7w?key=KBEKAuRqwRONFDBsNTxVIo1q)** --- ## Usage Instructions **How to Use the Feature:** 1. First Option: To create or update, follow these steps: 1. Navigate to the relevant section Operations → Incidents→ Configuration. ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdQTdl7G-rzxWg7lVi_oaZQh_sMtne4GFUj8fMndOItQx_vvr9wwmAmJZa1jQX6WxXubPt9L1dQ4xIJWEo1nnnn4wBC8KmjWhc2cpWK8nz9_KSc7q7a0Kh5nRxi9IZfPrQVqr3bpQ?key=fGirOmmwKPn4MoEVOpftmPwT) 2. Click on the "+" ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeAVO513MQ_PKpBfGT72dDTGOruD6wARpfRrgORxWx6l45DFZqIWWInUO8fzVc0fB0sykx3x9DMs2USlUnJrGkwBTTkM6vbXQxVPSjCHQPjZi41LIE61jflKe6jt-nEBUeLfGxqZA?key=fGirOmmwKPn4MoEVOpftmPwT) 3. Fill in or modify the necessary details. 4. Save or submit the changes once you're done. 2. Second Option: **Manual Incident** 1. Begin by filtering your search to locate the desired host ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfwYnBxDySVEPsk1UVY5_93CXhDPFJH3WRJrMAnh_DaNXfo-1LAamU0xyR0o6ZyS0SbVhQd6Nh5-PqmXucrmKBB4qRYwZGC7xXMu-c0UyrQRBAexQhx1qXsfHljeZCuYHwyyFcu?key=fGirOmmwKPn4MoEVOpftmPwT) 2. After clicking on ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdplZb4Sy8oovU8oW2FVSMd2xGMhiv9qtjj40Tu-zWkzLzYv5gRMyjVHAnv4-h_vye1TEyNF3-FGmjCYKAGeZi6mWcOzBcoM_5JompPfkuDPjVet6jd0Yol97VjHpPWbLtaTtfZ?key=fGirOmmwKPn4MoEVOpftmPwT) ensure that you provide the correct information ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdOseBnLhWFrAgYtipLfMRoVewZGhaWSF3uIMcbvb7N5UO18wpT8sJrEcqQaPkwC8VLbSZd3tQQWOEuynq4kZILz1zb2nEdqJV5f8upDPWijGZcHBNqQ4ab35V9LpDkgK5Z5eWjSw?key=fGirOmmwKPn4MoEVOpftmPwT) 3. Create an incident: We will receive all alerts related to the host app under the manual incident. ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdIBB38L6PwsnhWPollA0y4LbZUzF-2HH0bUhe3BrJvyG8DD6VHoD8cGH14JDEoyU6ZJydiT1MwVevr96hNjWpDWxXVrnkuUw2ju590lUIdm_zEUPBcV_RbxOQvuk9TN_iWDUrt?key=fGirOmmwKPn4MoEVOpftmPwT) The incident will appear as follows: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeCMX1lSEbvMcGPaLFgHuBRosx7OVwhAK8yfaXvcqluTOdOvEAuUN-hokwVt2ap4QR-HWdTuy0T5xVYMHobwAffl1qPfDJhvT1NcWGO5HKKH50Nzxm1lBdPMnyXPQaIzCIz2dkm6g?key=fGirOmmwKPn4MoEVOpftmPwT) --- ## Usage Examples 1. Group by Service: In this scenario, all hosts containing the desired string will be grouped by the Service as seen in the screenshot Incident settings: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXea9Hm_vaLqHkGoOee4CzADUMyWd9rsvbMLtdZ3u8ywE48Eo1QWAwF0yzA-TMm5dnvouF_K3OX2A1nd7UxQc_bMIj5zmu-inTVnhSa48gjJJZ5FKEhmbFwxYkBjUBQ5-tCOFQmZ?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) Alerts related to the incident: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfEDqtNAjF-eaA1MEPEaY0oOmWWgLpzN0TMtiw67HBfoXKLyyJy5vyEKsOO1s_avyKFE23155-kT66nRFsJSUC8VBgthWHRga1dwT7bakFHCOuYIAURXvpn1NW_aPYG1hLGcLdsyw?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) Triggered Incidents: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeYSruVehPLNoJATELBTxNICLpvVm22kzAQOEbrivNrHEtNS5L6buCrbLJRBSJp7EXH2Jo_kXHdaFq2YHfWyCiMZdYQunPKoeOmi614JRRF5eddKsWOH9ytKl0SJgzhba_7u1gvdA?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) We can see which service the Incident triggered in the details: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcwREotxBjMoYqFw78d0n3aTPWvJ1y8oMmhp8LTFZHnX7elb3d2I3DY20VCXZwse-B4uuylpnjQFOACRkJEohafsQ8K2y5FGFDw0W9pAlUoe3xDF1mX_2pZCZSPp7ZTdL8E2CFBkw?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) 2. Group by **host**: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfkWH4T8V9BalH9Keqx2Z4K4IeT4cmjPnmXsEoPjpZ4xJKdUwVNueeEE3TIugquX3nY1qGhE_DIWh0mRKn6bU-jT32vDrpG7uilCORfREqQdQyIBGL7WC2gOP6thPiXwnMy-HYJ9Q?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) Alerts that related to the Incident: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdfH_kKcOPD-ZDQjXL4KXzNWzg-AILG3gAilGYX6qtlEPqIlpqKS71PdD4b2O7eEb5FkecgXNVAhYX8cDxBGzn02fpHOL0xzgrDw4jj9Wr5Mj82JU9iAvp6ZMGE7khM2U8tzFaAXA?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) 2 hosts meet the Incident’s conditions and the “Group by host” option was chosen, so 2 Incidents will be created: ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXe6DRcSmVBzJS9RnrLn0TOuYnpAC8tX7irfTAaoOpduBa6sEfDrC2OtR_AG6HrW5pDf_K_5I89lZw47KmL3JdVpUNcdTwC-8YbzasbmRV-aJnfw5_zZYJW7eLTgFfs6uFdB7X0zDQ?key=Lzt04Q8-yQ8LjtGG1cZ6grsh) --- ## Related Links - **Internal Links:** [[02.04 Filtering]]