Hi
try this search code in to group these two alerts in one alert
sourcetype = test host="host1" OR host="host2" "condition"
| eval name=substr(source,16,8)
| eval portal=case((host=="host1" AND name== "name01") , "title1" , (host=="host1" AND name== "name02") , "title2" , (host=="host1" AND name== "name03") , "title3" , (host=="host2" AND name== "name01"), "title4",(host=="host2" AND name== "name02"), "title5",(host=="host2" AND name== "name03"), "title6")
| stats first(portal) as Portal count(name) as Name by name
... View more