When to use this pattern
Use this pattern when several monitoring rules page for overlapping failures.
Investigation flow
- Deduplicate repeats of the same alert using a stable key.
- Compare service, environment, dependency, and onset time across distinct alerts.
- Group alerts that merit one coordinated response and preserve links to their original evidence.
- Split the incident if new evidence reveals unrelated failures or different response ownership.
Required fields
| Field or dimension | Purpose |
|---|---|
| alert ID and deduplication key | Distinguish repeated notifications from distinct conditions. |
| service and dependency | Supply operational relationships that support grouping. |
| trigger time and incident ID | Retain a timeline and an auditable association. |
Worked example: Keep a shared dependency outage actionable
Three services page on database errors. Dependency evidence supports a shared database incident. A simultaneous third-party payment timeout remains a separate investigation when its traces show no database involvement. Grouping reduces interruptions while preserving that distinction.
| Evidence | Observation |
|---|---|
| Repeated alert | The same rule and resource keep the same deduplication identity. |
| Related alerts | Different services show failure at the shared database boundary. |
| Independent alert | Payment-provider failures follow a different path. |
Limitations and false matches
- Matching alert text is weaker evidence than shared affected resources.
- Large time windows can merge independent incidents.
- Automated grouping availability and behavior depend on product configuration and subscription.
Verification checklist
- Send duplicate test events and confirm one alert identity is preserved.
- Send distinct but related test alerts and inspect the incident association.
- Check that an unrelated test condition remains independently visible.
Supported by
Documented examples, not an exhaustive compatibility list. Features require suitable instrumentation and configuration; availability can depend on the runtime, backend, and subscription.
- PagerDuty — Configured alert grouping associates related notifications with incidents.
- PagerDuty — Alert records remain associated with incidents and can be moved when grouping needs correction.
Related signals
Related concepts
Related patterns
Related guides
FAQ
Should incident grouping suppress the original evidence?
No. Keep the source alert, its trigger condition, and its chart or query links available to responders.