Detection & alerting · 6 min read

Set up topology-aware alert correlation

Correlation groups related symptoms into one incident instead of paging on each one. Here's how to make sure it understands your topology correctly.

What you'll need

  • Auto-discovery or an imported topology map
  • At least two sensors if your network spans multiple sites
1

Confirm your topology map is current

Correlation relies on knowing which devices sit downstream of which. Review Topology > Map and confirm auto-discovered links match reality, especially after any recent network change.

2

Set correlation windows

The default 90-second correlation window groups symptoms that appear close together in time. Widen it for networks with slower convergence protocols, or narrow it for fast, flat networks where you want faster incident creation.

3

Test with a planned change

The next time you reboot a core switch during a maintenance window, check whether the resulting downstream alerts grouped into one incident. If they didn't, the topology map likely needs a manual link added.