You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
we're currently using PagerDuty but I've started to look over the fence on Opsgenie.
It looks feature rich but I can't find any resources on time based alert grouping.
It's a very useful feature in PagerDuty which will group alerts that come in during a predefined time-window into one incident assuming that alerts that are triggered within the same time-window most lightly originate from the same problem.
This works well for us since we've got quite a lot of monitoring going on in our Fibre Network and the time-based alert grouping will reduce the noise during bigger events.
Is there a way to achieve the same outcome with Opsgenie?
Opsgenie does have alert correlation that acts in a similar fashion:
Essentially if you have an ongoing service disruption (with your Fibre Network), alerts can be associated to an incident during the window its open - and group to the 'same problem' as you mentioned:
Additionally - the incident updates, timeline, post-mortem and reports can be created/exported to incorporate all the data tied to the service disruption:
I know that's a lot of information and doc. sharing so please let us know if you have any additional follow up questions.
Thanks for your reply Nick,
I did see that there's an alert correlation feature but I'm not sure that it works in the same way as the PagerDuty time based grouping feature.
There are no matching rules going on when alerts are grouped together in an incident, the only common denominator is that they appear in the same time window, hence most lightly originating from the same event.
Has anyone implemented this behavior in Opsgenie?
I'm personally not familiar with PD's time-based grouping feature, but within an Opsgenie service's incident rule - multiple matching rules (and/or conditions) can be defined to associate alerts into one incident.
This does not have time-based functionality since it's all dependent on an ongoing incident, so the filter does need to be defined to match the alerts in order to associate them:
if I understand correctly the OG feature group multiple alerts into one Incident but we need to Group various Alerts into one , so it is not flooding our on-call staff with notifications. For example if we have a Fibre break , there are various alerst trigerred (OSPF, BGP, Interface, ....) which are obviously caused by same reason , which is the Fibre break.
So we are looking to configure Opsgenie in a way that if there are more than for eample 3 alerts generated within 5 minutes, Opsgenei Group them into ONE SINGLE ALERT NOTIFICATION, and notify our engineer. Then the negineer can open that one notification and see all other alerts which are grouped.
is it something currently built in, or you are planning to add as a feature?