Associated Events Email Notifications
Focus
Focus
Strata Cloud Manager

Associated Events Email Notifications

Table of Contents

Associated Events Email Notifications

Learn about the associated events in notification profiles.
Where Can I Use This?What Do I Need?
Associate events are informational signals to get all updates related to an incident excluding the initial trigger and resolution. To reduce unnecessary noise while preserving visibility into incident lifecycle transitions (such as creation, update, and resolution), Strata Cloud Manager suppresses associated event email notifications by default for all notification profiles.
When configuring your notification preferences, you must distinguish between the following event types:
  • Incident State Change events—Represent transitions in the lifecycle of an incident (for example, when an incident is created, escalated, or resolved). These events generate email notifications to drive independent remediation or triage decisions.
  • Associated events—Indicate a new alert has been correlated with an existing incident. While useful for tracking the scope of an incident, these correlation updates are high-frequency and rarely require immediate action.
The notification profile is the primary configuration object that governs how and when you receive email notifications. Each notification profile includes a preference that controls whether Associated events generate email notifications. This preference is disabled by default for both existing and newly created profiles. When you edit or create a notification profile, enabling this option resumes delivery of Associated event emails for that specific profile, though the platform displays a contextual message warning that enabling this setting might increase notification volume.
If your security operations workflow depends on real-time awareness of every alert associated with an active incident, you can enable Associated event email delivery on the relevant notification profiles. If your team primarily acts on incident state transitions and investigates correlated alerts through the web interface, leaving the default suppressed behavior reduces inbox volume without affecting your ability to manage incidents effectively. For Webhooks and ServiceNow, associated events continue to be sent by default. You can disable it based on your requirements.