Aggregation policies support splitting rules that determine how events are grouped. You can split by entity, by service, by custom field, or by time window. Splitting by entity gives each server its own Notable Event stream.
The filtering step determines which events enter the policy. You can filter by severity, service name, entity type, or custom field values. Combining smart filtering with appropriate splitting rules is the key to effective noise reduction.