---
title: Pattern-based Correlation
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: Docs > Event Management > Correlation > Pattern-based Correlation
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Pattern-based Correlation

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Overview{% #overview %}

Pattern-based correlation allows you to control how the events are correlated. Datadog also uses machine learning to automatically enrich your pattern with related Datadog Monitor events, using underlying telemetry gathered within Datadog and other heuristics.

To get you started, Datadog automatically suggests [pattern-based correlations](https://app.datadoghq.com/event/correlation) according to your environment. Click any of the recommendations to open the configuration for the recommended pattern. Configuration fields are pre-populated.

## Create a pattern{% #create-a-pattern %}

To create a pattern:

1. Navigate to [Correlation](https://app.datadoghq.com/event/correlation).
1. Click + Add a Pattern, at the top of the Pattern table. This opens a pattern configuration page that displays out-of-the-box suggested patterns on the left side, and a pattern output preview on the right side.
1. You can adjust a suggested pattern by clicking + Continue With Pattern. This takes you to the pre-populated configuration page for additional tuning. Or, you can choose to create your own pattern by clicking + Personalize From Scratch

First, events are deduplicated to alert based on event aggregation key. Then, alerts are correlated to a work item based on configuration.

{% video
   url="https://docs.dd-static.net/images/events/correlation/correlation_helper.mp4" /%}
For more information on how to sends events with aggregation key, see [send events to datadog](https://docs.datadoghq.com/events/ingest.md). Events without an aggregation key are deduped to one single alert within the timeframe.


### Suggested patterns{% #suggested-patterns %}

Suggested patterns are recommended based on your commonly used service and environment tags to help you get started with event correlation quickly.

### Configuration{% #configuration %}

From the [correlation configuration page](https://app.datadoghq.com/event/correlation/rule/new)

1. Select the event source you want to group on from the dropdown.
1. To exclude any events from the source defined above, add an event query in Filter by these events or tags to filter them out.
1. Add related events to associate changes or other supplementary events to support work item investigation. Related events will be appended to a work item but will not create new work items.
1. Define the grouping tags. Grouping tags are event facets. See the advanced settings section below if you don't see the tag from the dropdown. **Note**: you can create facets on both event attribute and tag. To learn more, see the [facets](https://docs.datadoghq.com/events/explorer/facets.md) documentation.

### Advanced settings (optional){% #advanced-settings-optional %}

1. Click Show Advanced Settings.

1. You can add grouping tags to correlate events and customize work item title.

   {% dl %}
   
   {% dt %}
Add grouping tags
   {% /dt %}

   {% dd %}
   to add new grouping tags, this is same as adding [new event facet](https://docs.datadoghq.com/events/explorer/facets.md#create-a-facet).
      {% /dd %}

   {% dt %}
Customize work item title
   {% /dt %}

   {% dd %}
to create a template to replace the automatically generated work item title. You can reference tag template variables using handlebars syntax, for example "{{tag.service}}", to include a comma-separated list of tag values.
   {% /dd %}

      {% /dl %}

1. Under Correlator Logic, configure when to create a work item and how long to correlate alerts and deduplicate events:

   {% image
      source="https://docs.dd-static.net/images/events/correlation/pattern/correlator_logic_advanced_settings.195b78b7fc384227a8e9eeaa6830c53c.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/events/correlation/pattern/correlator_logic_advanced_settings.195b78b7fc384227a8e9eeaa6830c53c.png?auto=format&fit=max&w=850&dpr=2 2x"
      alt="Correlator Logic tab in Advanced Settings showing the minimum alert count, correlation duration, auto-closure, event deduplication, and extended deduplication options" /%}

   {% dl %}
   
   {% dt %}
Minimum alert count
   {% /dt %}

   {% dd %}
The minimum number of correlated alerts required to create a work item. If the minimum is one, the first correlated alert creates the work item.
   {% /dd %}

   {% dt %}
Correlation window
   {% /dt %}

   {% dd %}
The maximum duration during which new alerts can be added to the same work item. This window begins when the first alert is correlated.
   {% /dd %}

   {% dt %}
Create a new work item after auto-closure
   {% /dt %}

   {% dd %}
When enabled, a matching alert creates a new work item after the previous work item closes automatically.
   {% /dd %}

   {% dt %}
Deduplication window
   {% /dt %}

   {% dd %}
The duration during which additional events from an alert already in the work item are associated with that alert. This window begins when the first alert is correlated.
   {% /dd %}

   {% dt %}
Extend dedupe window until all alerts resolve
   {% /dt %}

   {% dd %}
When enabled, unresolved alerts already in the work item can continue to receive events after the deduplication window expires, for up to 30 days. This setting does not extend the correlation window for adding new alerts.
   {% /dd %}

      {% /dl %}

For example, consider a pattern with a minimum alert count of one, a 48-hour correlation window, and a 48-hour deduplication window:

   - Alert A is correlated at 9:00 AM on Monday. It creates a work item, and both windows begin.
   - Alert B is correlated at 10:00 AM on Monday and is added to the same work item. Additional events from Alert A or Alert B during the deduplication window are associated with their existing alerts.
   - Both configured windows expire at 9:00 AM on Wednesday.
   - Alert C is correlated at 10:00 AM on Wednesday. Because the correlation window has ended, it cannot join the existing work item and creates a new work item, regardless of the **Create a new work item after auto-closure** setting.

If **Extend dedupe window until all alerts resolve** is enabled, events from unresolved Alert A or Alert B can continue to update the existing correlation after 9:00 AM on Wednesday, for up to 30 days. Alert C still cannot join the existing work item because it is a new alert.

A work item closes automatically only when all of its alerts resolve. If deduplication ends while alerts are still unresolved, correlation stops and the work item stays open unless it is closed manually.

A work item can contain up to 500 alerts, and each alert can retain up to 100 events. After an alert reaches 100 events, the correlator drops all subsequent events for that alert, including its recovery event. The alert cannot resolve, so the work item stays open unless it is closed manually.

When a work item stops processing before its alerts resolve, it displays an Ended incomplete badge. Hover over the badge to see why processing stopped.

The work item can display more than 100 matching events because its event list retrieves matching events independently. The displayed event count might differ from the number of events retained and processed by the correlator.

## Preview pattern output{% #preview-pattern-output %}

Preview the possible patterns and work items your configuration would potentially create. The preview panel displays

- the total number of ingested events (limited to the first 1000 events).
- the number of alerts that would be deduped from events.
- the number of work items that would be created based on the configuration.

Use this data to preview the impact of your correlations and understand the expected output of a pattern.

**Notes**: the default title in the preview work item is the first alert in correlation. After you save a pattern, the event management work item title is intelligently generated.

## Select a Work Management destination{% #select-a-work-management-destination %}

1. From the Project dropdown menu, select from an existing work item to send your grouped events to.
1. (Optional) Add a tag to resulting work items.
1. Click Save and Activate to activate this pattern and group events into work items.

## Update existing pattern{% #update-existing-pattern %}

After you update an existing pattern, all live work items will stop processing. New events that match the pattern will create a new work item.

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Learn about triaging and notifying on work items](https://docs.datadoghq.com/events/correlation/triage_and_notify.md)
