> For the complete documentation index, see [llms.txt](https://oiadocs.cloudfabrix.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oiadocs.cloudfabrix.io/features-guide/alert-correlation/alert-correlation/untitled.md).

# Creating and Updating Correlation Policies

Follow the below steps to view and manage the Alert correlation policies.

![](/files/-M_vzVyH141HRofQmgoI)

![](/files/-M_w-U_7sYeV93UHCkuW)

![](/files/-M_w0ONNg8BIGdLf02Zs)

### **Correlate Burst policy:**

Follow the below steps to create a '**Correlate Burst**' policy.

Click on '**+**' buton to create a new Correlation policy and select the policy type as '**Correlate Burst**'

![](/files/-M_w1b6rPvl2aWq5xDOP)

As highlighted in the below screen, define the correlation burst policy settings appropriately.&#x20;

Set correlated alert group’s minimum severity. (**Note:** Incident’s severity is set to highest severity, if one of the grouped alert’s severity is higher than policy’s severit&#x79;**)**

**Raise Count:** Alert burst count (minimum)

**Raise Rate (seconds):** Rate of Alerts burst count within the defined time (seconds)

**Group Expiry (minutes):** Time window (for how long) to keep this policy active to group the burst of alerts

**Auto clear after last update (minutes):** Clear the Alert automatically after defined time (if there is ‘NO’ clear / recover message for the alert) (Note: when set to ‘0’, alert will be cleared automatically if there is a clear / recover message for the sam&#x65;**)**

![](/files/-M_w2PTuMnj-oJCpDAFf)

As shown in the below screen, Limit the Correlation burst policy scope to specific alert source (Nagios, vROps etc..) or it’s attributes (Site / application name etc.. )

**Group by** '**Attributes**' helps to correlate and group the alerts based on Alert attribute (one or more) selection.&#x20;

![](/files/-M_w4aUMt6GSFZ5h_Ka5)

Once the correlation policy is selected, make sure the policy's **Enabled** status is set to '**Yes**'.&#x20;

![](/files/-M_w66tGD_QjmdirrV5s)

### **Correlate Group policy:**

Follow the below steps to create a '**Correlate Group**' policy.

Click on '**+**' buton to create a new Correlation policy and select the policy type as '**Correlate Group**'

![](/files/-M_w79re3aJiMFqXOm-V)

As highlighted in the below screen, define the correlation group policy settings appropriately.&#x20;

Set correlated alert group’s minimum severity. (**Note:** Incident’s severity is set to highest severity, if one of the grouped alert’s severity is higher than policy’s severit&#x79;**)**

**Group Expiry (minutes):** Time window (for how long) to keep this policy active to group the burst of alerts

**Auto clear after last update (minutes):** Clear the Alert automatically after defined time (if there is ‘NO’ clear / recover message for the alert) (Note: when set to ‘0’, alert will be cleared automatically if there is a clear / recover message for the sam&#x65;**)**

![](/files/-M_w7ht-xAYck3YdAVJB)

As shown in the below screen, Limit the Correlation burst policy scope to specific alert source (Nagios, vROps etc..) or it’s attributes (Site / application name etc.. )

**Group by** '**Attributes**' helps to correlate and group the alerts based on Alert attribute (one or more) selection.&#x20;

Click on '**Save**' to create the correlation policy.

![](/files/-M_w4aUMt6GSFZ5h_Ka5)

Once the correlation policy is selected, make sure the policy's **Enabled** status is set to '**Yes**'.&#x20;

![](/files/-M_wFCUiZ-p4KwFo_bYL)

##
