When to use this pattern

Use this pattern when several monitoring rules page for overlapping failures.

Investigation flow

  1. Deduplicate repeats of the same alert using a stable key.
  2. Compare service, environment, dependency, and onset time across distinct alerts.
  3. Group alerts that merit one coordinated response and preserve links to their original evidence.
  4. Split the incident if new evidence reveals unrelated failures or different response ownership.

Required fields

Fields that make the connection possible
Field or dimensionPurpose
alert ID and deduplication keyDistinguish repeated notifications from distinct conditions.
service and dependencySupply operational relationships that support grouping.
trigger time and incident IDRetain a timeline and an auditable association.

Worked example: Keep a shared dependency outage actionable

Illustrative scenario

Three services page on database errors. Dependency evidence supports a shared database incident. A simultaneous third-party payment timeout remains a separate investigation when its traces show no database involvement. Grouping reduces interruptions while preserving that distinction.

Example observations and the next comparison
EvidenceObservation
Repeated alertThe same rule and resource keep the same deduplication identity.
Related alertsDifferent services show failure at the shared database boundary.
Independent alertPayment-provider failures follow a different path.

Limitations and false matches

  • Matching alert text is weaker evidence than shared affected resources.
  • Large time windows can merge independent incidents.
  • Automated grouping availability and behavior depend on product configuration and subscription.

Verification checklist

  • Send duplicate test events and confirm one alert identity is preserved.
  • Send distinct but related test alerts and inspect the incident association.
  • Check that an unrelated test condition remains independently visible.

Supported by

Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.

  • PagerDuty — Configured alert grouping associates related notifications with incidents.
  • PagerDuty — Alert records remain associated with incidents and can be moved when grouping needs correction.

Related signals

Related concepts

Related patterns

Related guides

FAQ

Should incident grouping suppress the original evidence?

No. Keep the source alert, its trigger condition, and its chart or query links available to responders.