Apply Event iQ Detect to an aggregation policy
Event iQ Detect in IT Service Intelligence (ITSI) uses machine learning to correlate notable events into episodes, reducing alert noise. Use Event iQ Detect to facilitate notable event aggregation policy configuration.
- From the ITSI main menu, select Configuration then Event Management then Notable Event Aggregation Policies.
- Select an existing policy to apply Event iQ. Otherwise, select Create policy to create a new event aggregation policy.
- Generate the suggested group by fields in the Filtering Criteria and Instructions section. Specify a field name and value for the episode policy to detect. Any notable events that match the filtering criteria and apply to the policy will be selected by the policy. Use an AND clause to add additional rules to the rule block, or add an OR clause to start a new rule block.
- Activate the Event iQ toggle. Set the analysis window that the algorithm will use to generate the suggested grouping fields based on a historical analysis of your alert data. Choose an analysis window that generates enough data for the algorithm to analyze.
- Select the Run analysis button to display aggregation fields generated by the Event iQ algorithm. After receiving recommendations, selectAdvanced settings to view the specific fields.
- (Optional) Select Advanced settings to change the matching method between exact match, normalized exact match, and fuzzy match. You can enable cross field matching if you choose exact or normalized matching methods.
- (Optional) After configuring a rule, select Preview results to preview the alerts that will be generated by the conditions you set.
- (Optional) After the grouping fields are generated, set advanced settings to update the ranking of the fields by level of importance. The Event iQ algorithm will generate an initial ranking of fields, but you can make changes to that initial ranking.
- Set criteria for when to create a new episode in the Break episode section. When the breaking criteria are met, the current episode can no longer have any events added to it, and a new episode starts with the next notable event. For example, you might enter, Break episode if the following event occurs: message matches *status Normal. This rule breaks an episode once it receives a normal notable event, indicating the problem is resolved.
- Set how you want information about each episode to display in the Episode information section. Select settings for details such as the episode's severity, event type, status, and other criteria that will display on the Episode Review dashboard.