ECM sits between your monitoring tools and your team. It collects every event, correlates it with everything else happening across your infrastructure, shows your team exactly what matters, and can act on it automatically — all without replacing a single tool you already run.
Every event that reaches your team has already passed through all four stages — automatically, in real time.
Connectors poll, subscribe to, or receive webhooks from every monitoring and ITSM tool you run, and normalise events into a common format.
Deduplication, suppression, and grouping rules — aware of your topology — turn thousands of raw events into a handful of incidents.
The Alert Console, Entity Graph, Historical Trends, and Alert Heatmap give every audience the view they need.
Automation workflows, bidirectional ITSM sync, mobile alerts, and AI-generated summaries close the loop without manual work.
A closer look at how events move through ECM from the moment they're generated.
Each of ECM's 50+ connectors knows how to talk to its source natively — polling SNMP traps from Nagios, subscribing to SolarWinds' alert stream, reading CloudWatch events, or receiving webhooks from ServiceNow. Every event is normalised into a common schema the moment it arrives, so the correlation engine works from a consistent view regardless of where an event came from.
Same alert, same entity, repeated within 5 minutes → keep one, increment the counter.
Downstream alerts during a known upstream outage → suppress until the parent clears.
All alerts tagged "Database Incidents" within a 10-minute window → one incident, multiple events.
Alerts from entities inside an active maintenance window → suppressed automatically.
This is where the noise reduction happens. ECM applies your correlation rules — deduplication, suppression, grouping, and maintenance-window awareness — to the normalised event stream. Rules are built in a visual editor and can reference entity relationships from the topology graph, so a switch outage doesn't generate forty separate "downstream unreachable" incidents.
Correlated incidents land in the Alert Console, grouped and searchable. From there, the Entity Graph shows how the affected systems relate to everything else, Historical Trends shows whether this is a one-off or a pattern, and the Alert Heatmap shows where to look first across your whole estate. Same data, four ways to look at it.
An incident doesn't just sit in a console waiting for someone to notice. ECM can open, route, acknowledge, and close tickets in ServiceNow, Jira, or BMC automatically as the underlying alerts change. Automation workflows can trigger remediation scripts directly. On-call engineers get pushed to their phones. And the AI Incident Narrator turns the raw correlation into a plain-language summary for whoever's reading it.
Both deployment options run the same correlation engine and connectors. Pick based on where your data needs to live.
Sign up, point ECM's connectors at your monitoring tools, and alerts start flowing within minutes. No infrastructure to provision or patch. Best for teams who want to be correlating events today.
Run ECM inside your own infrastructure when alert data, topology, or compliance requirements mean it can't go to the cloud. Same connectors, same correlation engine, same console — deployed where you control it.
Hybrid estate? Deploy dedicated ECM nodes across Microsoft Azure, Amazon AWS, and Google Cloud alongside your on-prem data centers — all correlated in the same single pane of glass.
If you don't see your question here, ask us directly — we typically reply within a day.
For cloud, most teams have their first connector live and alerts flowing within hours of signing up. On-prem typically takes a day for initial installation and connector setup, then iterative tuning of correlation rules over the following days as you see real traffic.
No. ECM sits above SolarWinds, Nagios, Zabbix, Zenoss, Dynatrace, Datadog, and 50+ other tools via native connectors. Your team keeps using the tools they know for monitoring — ECM is where the correlated, cross-tool view lives.
Yes. During onboarding, we help map existing suppression and deduplication logic — whether that's rules in another tool or scripts your team maintains — into ECM's visual rule builder, so you're not starting from zero.
Your choice. Cloud deployments run in managed regions with standard data protection practices; on-prem deployments keep all data inside your own infrastructure. Both run the same platform.
No. Correlation rules, dashboards, and automation workflows are all configured visually. A REST API is available if your team wants to build custom integrations on top.
You can keep growing on transparent, predictable pricing — no per-event licensing surprises, since your event volume typically drops as correlation kicks in. Talk to us for a quote based on your entity count.
Yes. ECM 6.4 added an Elasticsearch Cloud export for real-time anomaly detection — tracking shifts in alert severity and priority and breaking down alerts by source — plus a multilingual Alert Console available in English, French, and Japanese, with more languages planned.
Free for up to 100 managed entities. No credit card needed. Cloud or on-prem, up and running in minutes.