Alert Correlation Rules and Grouping Mechanism to Reduce Noise

แชร์
ฝัง
  • เผยแพร่เมื่อ 24 ก.ย. 2024
  • I have created a community article on the same named as Event Management : Leverage Alert Correlation and Grouping for Noise Reduction : community.serv...

ความคิดเห็น • 30

  • @NghiNguyen-ug8ur
    @NghiNguyen-ug8ur ปีที่แล้ว +3

    Your content is much much better than the nowlearning on-demand course! Keep doing this, Thanks!!

    • @AshutoshMunot
      @AshutoshMunot  ปีที่แล้ว

      Glad you think so!

    • @rupalirasal6846
      @rupalirasal6846 หลายเดือนก่อน

      Hello, do you have any other documentation on alert management?

  • @ravigaur583
    @ravigaur583 หลายเดือนก่อน

    Best explanation, Thanks

  • @dtonomy8635
    @dtonomy8635 3 ปีที่แล้ว +2

    This is very useful!
    Same amount of noises do exist in security detections alerts. Grouping alerts not only reduce noise but also provide valuable context for security analysts to quickly identify true positives and false positives. In our product we have designed a module called pattern discovery. It automatically pulls all detections using the detections API so our Pattern Discovery Engine can automatically cross-correlate all the detections into a much smaller number of Cases. Since cross-correlating could be time consuming when done manually, we've automated that step in our product…
    Anyways, Good demo, Ashutosh!

    • @AshutoshMunot
      @AshutoshMunot  3 ปีที่แล้ว

      Thanks for your inputs @DTonomy

  • @amysrisai
    @amysrisai 2 ปีที่แล้ว +1

    Thank you for explaining the Alert correlation & grouping using Rule and OOTB methods so well. I would also be interested in how Learned Patterns are created and managed. If you could add a video on this, that would be greatly appreciated.

  • @aakuSBhan
    @aakuSBhan 4 ปีที่แล้ว +1

    nice video..Very Helpfull.

  • @oswaldoperalta
    @oswaldoperalta 2 ปีที่แล้ว +1

    Awesome tutorial man. Thank you!

  • @vaasant10
    @vaasant10 3 ปีที่แล้ว +1

    Nice Video ..Bro

  • @SudiptaGoswami2
    @SudiptaGoswami2 3 ปีที่แล้ว +1

    👍👍👍

  • @sharathkumar7938
    @sharathkumar7938 ปีที่แล้ว

    Can we disable auto alert grouping for some type of alerts???

  • @TaleleMilind
    @TaleleMilind 4 ปีที่แล้ว +1

    Thank you Ashutosh for this nice video. I want to replicate similar incident/ parent child incident mechanism in program. please can you help, what rule need to be consider while doing ML

    • @AshutoshMunot
      @AshutoshMunot  4 ปีที่แล้ว

      Sure. When you say parent child incident means you want to create incident for all secondary alerts as well and make them child of primary alert incident?

    • @TaleleMilind
      @TaleleMilind 4 ปีที่แล้ว

      Yes, Primary incident( lets say Diskspace issue) and child are rest of jobs failed due to primary issue. Can you guide on some ML algorithms that can be use outside serviceNow.

    • @AshutoshMunot
      @AshutoshMunot  4 ปีที่แล้ว

      @@TaleleMilind You can make use of patterns here. You can create rule based correlation as well. How you know they are child? Based on CI relationship? If yes then they are automatically handled by ServiceNow if you have proper relationship in cmdb.

    • @TaleleMilind
      @TaleleMilind 4 ปีที่แล้ว

      @@AshutoshMunot Not on CI relation. I need to create some relation. Does any ML will tell me that they are related?

    • @AshutoshMunot
      @AshutoshMunot  4 ปีที่แล้ว

      @@TaleleMilind we can have Manual correlation and that correlation will be recorded and next time automatically ServiceNow will use it when new alert is created

  • @Avdacademy
    @Avdacademy ปีที่แล้ว

    Hello Ashutosh l,
    I created four events with the same source with the same CI and different message keys. Even they are grouping automatically. Could you confirm me on this . How the automatic rule works.

  • @jacoba8851
    @jacoba8851 3 ปีที่แล้ว

    Hello does this require to purchase any separate module from service now?

  • @evaa_121
    @evaa_121 3 ปีที่แล้ว

    if we do manual grouping, you mentioned that next time alert aggregation runs, then servicenow will automatically does the grouping next time right. In that case, will it show the grouping as 'Automated'?

    • @AshutoshMunot
      @AshutoshMunot  3 ปีที่แล้ว +1

      Yes

    • @evaa_121
      @evaa_121 3 ปีที่แล้ว

      @@AshutoshMunot thanks for replying. is there a way to revert that. (in case when the person wrongly does the manual grouping)