Incident Correlation
12 min
role and roles platform saas only minimum version 2025 2 feature eligibility ivanti's capabilities are available to customers who have subscribed to premium or enterprise premium license to know your eligibility, reach out to your ivanti account manager ivanti neurons for leverages ai to streamline incident management through intelligent grouping of incidents into clusters the incident correlation capability identifies patterns among new, incoming incidents, helping organizations detect major it service issues quickly the incident correlation dashboard empowers incident managers to build a dashboard, view cluster severity, and manage incident clusters efficiently users can make a dashboard to monitor correlated incidents, link incidents or unlink incidents, and assign parent incidents this advanced dashboard service enhances visibility and control, making my dashboard a central hub for proactive incident resolution the incident correlation dashboard is available out of the box for all new customers however, existing customers upgrading to version 2025 2 should set it up enable incident correlation log in to as an go to the configuration console, scroll to ai configuration hub and select it set incident correlation to active using the toggle button customize the incident correlation capability click the configure option beside the toggle button the incident correlation page is displayed optionally, enable the enable boundaries option using the toggle button this option allows you to define the criteria for grouping incoming incidents into clusters by default, this option is disabled, and the system clusters incidents only based on the similarity of the summary fields from the boundary field dropdown, select the incident record fields that you prefer to form a cluster you can select up to six options from the dropdown by default, the system also considers the summary field together with the other fields you select optionally, enable the enable whitelist filtering option this feature allows you to exclude incidents containing a specific keyword from forming clusters this is especially useful for skipping less important incidents for example, in a large organization, employees might frequently raise password reset incidents considering the minor priority of the incidents, administrators might not want these to form a cluster or appear in the incident correlation dashboard by using the "password reset" keyword, the administrators can exclude related incidents from forming clusters and can be addressed separately enter the keyword in the whitelist keywords field the system excludes incidents containing this keyword from forming clusters use to add additional fields use to delete a field you can create maximum up to 10 keywords the keywords are not case sensitive under correlation mappings , configure the field mappings to map the source or user created field to the target field used by the machine learning service to cluster the incidents click save to save the settings configure incident correlation dashboard the incident correlation dashboard is available to new customers from version 2025 2 by default existing customers have to set to it up from the , select build > page layouts select the role you want to set it up for under roles and click add page layout adding the page layout select incident correlation , provide necessary information and save the incident correlation dashboard is setup and the workspace is now available in the service desk console working with incident correlation dashboard to access the incident correlation dashboard from the service desk console, click more > search for incident correlation dashboard and open it a list of clusters is displayed you can open any cluster to view more information and make changes incident correlation dashboard points to note can add incident correlation dashboard to any role such as or to do so, enable object level permissions for the incident cluster\[nrn incidentcluster] business object this ensures the dashboard displays and functions correctly also add the incident correlation tab in the incident page to view correlated incidents and to navigate to the dashboard refer to configuring correlated tab docid\ asx2 bqaxnadmni3akn40 dashboard the incident correlation dashboard has the following elements filter by use this option to narrow down the dashboard by avg priority, cluster status, or range cluster name clickable; opens the cluster details page where all the incidents in the cluster is displayed with options to link/unlink incidents and assign parent incident trends dynamic graph with a visual representation of incident flow over time it is updated every time the page is refreshed the following are the color definitions green when incidents reported are in downward trend, that is if the incidents reported in the last hour is less than the previous hour red when incidents reported are in a rising trend, that is if the incidents reported in the last hour exceeds the previous hour created on date the cluster is created avg priority average priority of incidents in the cluster, determined from the individual impact of correlated incidents in the cluster category category of the grouped incidents region geographical region reporting the incidents incidents reported total number of incidents in the cluster linked incidents clickable; opens the cluster details page for managing incidents parent incident(s) clickable; opens the cluster details page cluster status current status of the cluster, with the following states not started when the cluster created in progress when an action such as linking incidents or assigning parents is taken terminated when the cluster is auto closed as result of all parent incidents resolved or closed +add incident use this option to add incidents into a cluster this option is available in the cluster details page remove from cluster to remove an incident from a cluster, select the incident and click this option this option is available in the cluster details page once you remove an incident from a cluster, you cannot add it back cluster details page configuring the correlated incidents tab the correlated incidents tab is available in the incident view page it helps a view the related incidents for resolving incidents faster this tab is available for new customers from version 2025 2 by default however, existing customers have the configure it to configure the correlated incidents tab from the configuration console, select build > business object > incident > layouts open the layout used for the role you want configure the tab from the view in this layout section, select formview click add child panel with relation enter correlated incidents as the tab name select correlated incidents as the plugin select incidentclusterassocincident in the relationship column correlated incidents tab added in the formview page save the changes correlated incidents tab is now added to the incident view page for the selected role frequently asked questions why is incident id available in boundary selection if each incident id is unique and may prevent incidents from clustering? incident id is available in boundary selection because, when the boundary feature was introduced, all fields used in the correlation process were included as boundary options this allowed customers to choose which fields to prioritize for clustering however, because each incident id is unique, using it as a boundary field places each incident in a separate group and may prevent meaningful clustering why is description available in boundary selection if it is an html field that may contain extensive text and screenshots? description and other html fields are sanitized before the correlation process during clustering, only the text content in these fields is considered why is incident status available in boundary selection if incidents with different status values may not be clustered together and status values can change over time? when incident status is used as a boundary field, incidents with different status values may not be clustered together if an incident's status changes, it is re evaluated during the next correlation run and may move to a different cluster or no longer belong to its current cluster are boundary fields used as a similarity check? a boundary field is not a similarity check it acts as a scoping rule that limits clustering to incidents with the same boundary field value incidents with different boundary values are evaluated separately and cannot be grouped into the same cluster, regardless of content similarity
