Configure priority for aggregation policies in ITSI

Add a priority level to a notable event aggregation policy (NEAP) in ITSI to process your incoming alerts from highest to lowest priority.

By assigning priority levels to policies, administrators can control how incoming alerts are processed, ensuring they are mapped to the most relevant episode. This reduces alert noise, prevents duplicate incident creation, and streamlines investigation workflows across teams.
Note: Default Episodes by Alert Group is the out-of-the-box ITSI aggregation policy that groups notable events into episodes based on their alert group field. It helps reduce alert noise by automatically combining related alerts with the same alert group into a single episode.
How this process works:
  • Assign priority levels ranging from 0 to 999 to these policies, with 0 being the highest priority and 999 the lowest.

  • Once an incoming alert matches an aggregation policy, the alert is grouped into an episode for the highest ranking policy only, and prevents duplicate episodes. If multiple notable event aggregation policies share the same priority value, the alert is grouped under all applicable policies.

  • All new, imported, and existing notable event aggregation policies have a default priority of 0.

    NEAP events workflow

After setting your priorities, you can sort the policies on the Notable Event Aggregation Policy page by priority to quickly filter your list from high to low priority policies.

For more information on filtering criteria and action rules, see Overview of aggregation policies in ITSI.

Set up priority for an aggregation policy

You can edit an aggregation policy priority directly from the Notable Event Aggregation Policies page.
  1. Navigate to Configuration > Event Management > Notable Event Aggregation Policies.

  2. Select an existing policy to edit, or select Create New to define a new policy.

  3. Edit the priority in the Priority field when updating an individual notable event aggregation policy.

  4. Enter a numeric value between P0 and P999. 0 is the highest priority.
    Note: If no value is specified, the policy defaults to a priority of zero.
  5. Save your changes.

Note: The priority for the default aggregation policy for ITSI cannot be edited.
NEAP listNEAP priority

Once configured, the system will automatically route notable events to the policy with the highest priority match. You can verify the routing behavior and event volume processed by your policies using the Event Analytics dashboard.

Bulk edit priority for multiple aggregation policies

To update the priority for multiple aggregation policies at once, complete these steps.
  1. From the ITSI menu, select Configuration then Event Management then Notable Event Aggregation Policies.
  2. Select the checkboxes next to the notable event aggregation policies you want to modify.
  3. From the bulk actions menu, select Edit Priority.

  4. Enter the new priority value for the selected policies.

  5. Save your changes.

Create or import a prioritized notable event aggregation policy

When you create a new policy or import an existing one, the default priority is automatically set to 0.