Your content is much much better than the nowlearning on-demand course! Keep doing this, Thanks!!
@AshutoshMunot Жыл бұрын
Glad you think so!
@rupalirasal68464 ай бұрын
Hello, do you have any other documentation on alert management?
@dtonomy86353 жыл бұрын
This is very useful! Same amount of noises do exist in security detections alerts. Grouping alerts not only reduce noise but also provide valuable context for security analysts to quickly identify true positives and false positives. In our product we have designed a module called pattern discovery. It automatically pulls all detections using the detections API so our Pattern Discovery Engine can automatically cross-correlate all the detections into a much smaller number of Cases. Since cross-correlating could be time consuming when done manually, we've automated that step in our product… Anyways, Good demo, Ashutosh!
@AshutoshMunot3 жыл бұрын
Thanks for your inputs @DTonomy
@amysrisai3 жыл бұрын
Thank you for explaining the Alert correlation & grouping using Rule and OOTB methods so well. I would also be interested in how Learned Patterns are created and managed. If you could add a video on this, that would be greatly appreciated.
@AshutoshMunot3 жыл бұрын
Great suggestion!
@ravigaur5833 ай бұрын
Best explanation, Thanks
@oswaldoperalta2 жыл бұрын
Awesome tutorial man. Thank you!
@AshutoshMunot2 жыл бұрын
Glad it was helpful!
@Avdacademy2 жыл бұрын
Hello Ashutosh l, I created four events with the same source with the same CI and different message keys. Even they are grouping automatically. Could you confirm me on this . How the automatic rule works.
@aakuSBhan4 жыл бұрын
nice video..Very Helpfull.
@AshutoshMunot4 жыл бұрын
Many many thanks
@sharathkumar7938 Жыл бұрын
Can we disable auto alert grouping for some type of alerts???
@vaasant103 жыл бұрын
Nice Video ..Bro
@AshutoshMunot3 жыл бұрын
Thanks
@TaleleMilind4 жыл бұрын
Thank you Ashutosh for this nice video. I want to replicate similar incident/ parent child incident mechanism in program. please can you help, what rule need to be consider while doing ML
@AshutoshMunot4 жыл бұрын
Sure. When you say parent child incident means you want to create incident for all secondary alerts as well and make them child of primary alert incident?
@TaleleMilind4 жыл бұрын
Yes, Primary incident( lets say Diskspace issue) and child are rest of jobs failed due to primary issue. Can you guide on some ML algorithms that can be use outside serviceNow.
@AshutoshMunot4 жыл бұрын
@@TaleleMilind You can make use of patterns here. You can create rule based correlation as well. How you know they are child? Based on CI relationship? If yes then they are automatically handled by ServiceNow if you have proper relationship in cmdb.
@TaleleMilind4 жыл бұрын
@@AshutoshMunot Not on CI relation. I need to create some relation. Does any ML will tell me that they are related?
@AshutoshMunot4 жыл бұрын
@@TaleleMilind we can have Manual correlation and that correlation will be recorded and next time automatically ServiceNow will use it when new alert is created
@SudiptaGoswami23 жыл бұрын
👍👍👍
@evaa_1214 жыл бұрын
if we do manual grouping, you mentioned that next time alert aggregation runs, then servicenow will automatically does the grouping next time right. In that case, will it show the grouping as 'Automated'?
@AshutoshMunot4 жыл бұрын
Yes
@evaa_1214 жыл бұрын
@@AshutoshMunot thanks for replying. is there a way to revert that. (in case when the person wrongly does the manual grouping)
@jacoba88513 жыл бұрын
Hello does this require to purchase any separate module from service now?