For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/events/correlation/intelligent.md. A documentation index is available at /llms.txt.

Intelligent Correlation

This product is not supported for your selected Datadog site. ().

Overview

Intelligent Correlation automatically aggregates Monitor alerts into cases based on related infrastructure dependencies, underlying telemetry, and other heuristics. Intelligent Correlation relies on relationships identified within your infrastructure based on the underlying telemetry. It considers only alerts from monitors that notify a paging integration or are tagged high priority. If there isn’t enough telemetry to establish these relationships, or if your monitors don’t meet these criteria, you might not see any correlated cases.

Enable Intelligent Correlation

Enabling the Intelligent Correlator applies to your entire Datadog organization. After it’s enabled, it evaluates incoming monitor alerts, automatically grouping related ones into cases. You can return to the same page at any time to adjust the tag filters or disable the Correlator.

To get started:

  1. On the Settings page, under Projects, click Intelligent Correlation.

  2. On the Intelligent Correlator card, click Edit.

    Intelligent Correlation settings page showing the Intelligent Correlator card, currently off, with an Edit button
  3. Under Define Intelligent Correlator, optionally narrow the events the correlator evaluates:

    • Consider events with any of these tags: Only events matching one of these tags are correlated. To consider all monitor alerts, leave this field empty.
    • Exclude events with any of these tags: Events matching one of these tags are not correlated. This may be useful for filtering out noisy or non-production alerts.
    Define Intelligent Correlator form with fields to include and exclude events by tag, and a Save and Enable button
  4. Click Save & Enable.

Receiving your first case

Event Management - Intelligent Correlation

When you navigate to Event Correlations, find a project called Intelligent Correlation. From this project, you can see the cases created by Intelligent Correlation.

Intelligent Correlation generates cases automatically after it finds related alerts:

Case detail page of case created from intelligent correlation, showing related alerts in the Investigation tab

Further Reading

Additional helpful documentation, links, and articles: