Skip to main content

Groupping multiple alerts

  • June 16, 2025
  • 3 replies
  • 13 views

yasinmnk
Forum|alt.badge.img+7

Hi,

Is there a way to automatically group multiple alerts from the same user—especially when individual tickets already exist for similar alerts—so that new alerts can be referenced or linked to an existing Jira ticket instead of creating separate ones each time?

3 replies

kentphelps
Staff
Forum|alt.badge.img+11
  • Staff
  • June 16, 2025

Take a look at this thread to see if it helps:  Throttle Rule Alerts


Forum|alt.badge.img+4
  • Bronze 3
  • June 17, 2025

There is a config for grouping alerts in the SOAR. You can find the detailed information here: 
https://cloud.google.com/chronicle/docs/soar/investigate/working-with-alerts/alert-grouping-mechanism-admin

If you want to work with bundled alerts, you're going to want to do that in the SOAR side.  It will provide the capability, plus you could automate your tickets into Jira and have them already grouped. 


yasinmnk
Forum|alt.badge.img+7
  • Author
  • Bronze 3
  • June 18, 2025

Thanks guys both of you @Mustache @kentphelps