---
title: Triage and Notify
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Event Management > Correlation > Triage and Notify
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Triage and Notify

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

{% image
   source="https://docs.dd-static.net/images/events/correlation/triage/triage.8b26a42dd1f53fe5b24bdf022eea9e98.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/events/correlation/triage/triage.8b26a42dd1f53fe5b24bdf022eea9e98.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="Case detail page with an event side panel. Investigate correlated events from a case and analyze related metrics" /%}

Event Management correlates related events and automatically consolidates them into a single work item. Bring in all the context of related logs, related metrics, and alerting monitors to triage and troubleshoot issues in one place.

From the [Correlation](https://app.datadoghq.com/event/correlation) page, find the pattern you want to analyze and click Triage Work Items at the end of the same row. You can also click Work Management at the top of the page to view all work items with correlated events in [Work Management](https://app.datadoghq.com/work?query=status%3AOPEN%20creation_source%3AEVENT_MANAGEMENT&page=1&page-size=25&sort=created_at). Datadog pulls in related metrics and logs so you can troubleshoot issues with all the related data in one place.

## Event Management Work Item{% #event-management-work-item %}

| Feature         | Description                                                                                                                                                                                                                                    |
| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Priority        | highest priority of correlated alerts                                                                                                                                                                                                          |
| Attribute       | tags from correlated events. user updates won't get overriden by the engine                                                                                                                                                                    |
| Status          | automatically managed by system, user updates will get overriden by system. Work items will auto resolve when all of the underline alerts recover and automatically reopen when any alert is re-triggered during the maximum alive time window |
| Deletion        | select the checkbox on the alert to delete any irrelevant alerts, deleted alerts won't get correlated again                                                                                                                                    |
| Enriched Alerts | some work items will get automatically enriched with intelligent alerts that Datadog thinks are related based on your infrastructure. Enriched alert do not impact work item attribute, priority, and status                                   |

For more information on Work Management operations, see the [Work Management documentation](https://docs.datadoghq.com/incident_response/work_management/view_and_manage.md).

### Investigation{% #investigation %}

1. From the work item Overview, click Investigation
1. Under the Correlations section, you can see a list of alerts and events
1. Click into any of the alerts or events to view all related metrics and logs in context of the alert
1. (Optional) Select any alerts or events you want to remove that are not related to the work item
1. Under the Related Metrics section, compare all related metrics or group by tags

## Create a notification or ticket{% #create-a-notification-or-ticket %}

With correlated events, you can configure one notification for a group. So, instead of having 20 notifications and 20 potential issues to investigate, you have one single work item and one notification. Combine all your alerts in the Work Management Projects page. There are a few ways to group notifications in Work Management:

### Ticketing{% #ticketing %}

On the Project Settings page, configure the Integrations you want your projects to send notifications to. Datadog supports the following integrations with manual and automatic ticket creation, and bi-directional syncing:

- ServiceNow
- Jira

For setup instructions, see the [Work Management Settings](https://docs.datadoghq.com/incident_response/work_management/settings.md#set-up-integrations) documentation.

## Notifications{% #notifications %}

In work management, *views* group work items based on a configured query. You can set up a notification when a work item matching this query is created. Datadog supports Pagerduty, Email, Webhook, Microsoft Teams, and Slack. To learn how to create a view, see the [Work Management Views](https://docs.datadoghq.com/incident_response/work_management/view_and_manage.md#create-a-view) documentation.

**Note**: You need to reconfigure underlying monitors to remove multiple notifications. Grouping monitor events does not mute individual notifications.
