Associate a knowledge base article with an alert
As an Event Management operator, you can associate a knowledge base (KB) article with the alert to capture additional information about the alert. This might include a procedure that someone has to follow to resolve the underlying issue on your network, or a best practice to prevent the issue from reoccurring.
Before you begin
Note: The Operator Workspace interface is available only to customers who have upgraded from a release prior to the Utah release. New customers as of the Utah release can use the Service Operations Workspace for ITOM, which offers an enhanced UI for managing alerts.
| Phase 1 | Image omitted: progress-complete2.png Analyze icon | Analyze and acknowledge an alert |
| Phase 2 | Image omitted: progress-wip.png Operator icon | Triage alerts |
| Phase 3 | Image omitted: progress-not-started.png Operator do icon | Close an alert |
This task assumes that your organization uses the Knowledge Base application in your ServiceNow instance.
Role required: evt_mgmt_operator
Procedure
From the Service Operations Workspace dashboard, open the alert that you acknowledged in Phase 1: Analyze and acknowledge an alert.
On the Alert form, click the lookup icon (
Lookup icon\) next to the **Knowledge article** field.
Filter the list of existing KB articles by first selecting a field, such as Short Description, and then entering related text into the search text field.
You can use the
contains(*) operator to search for articles that contain keywords. For example, entering*oraclein the short description filters the KB articles that contain the wordoraclesomewhere in the short description.
Search the KB
If you cannot find any related KB articles, you can click New, create a new one, and then click Submit.
The KB article number appears in the Knowledge article field on the Alert form.
KB number
- Click Update on the Alert form to save the information.
What to do next
There are also other tasks you can take as part of the triage stage:
- Run a remediation workflow on an alert if your Event Management administrator already set up a workflow in your ServiceNow instance and your policies allow you to trigger it from the alert.
- Launch a web application from an alert to open a website or an event monitoring tool that provides more information about the alert.
- Put an alert into maintenance to temporarily hide it from the Service Operations Workspace dashboard if the alert does not require action at this time.
If you do not need to perform any other triage actions, proceed to Phase 3: Close an alert.
Parent Topic:Operator phase 2: Triage an alert