Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run a remediation workflow on an alert

As an Event Management operator, you can also run a workflow on your ServiceNow instance that helps remediate the alert. For example, you might run a workflow that automatically restarts a server on your network, which might resolve an alert about CPU usage.

Before you begin

Note: The Operator Workspace interface is available only to customers who have upgraded from a release prior to the Utah release. New customers as of the Utah release can use the Service Operations Workspace for ITOM, which offers an enhanced UI for managing alerts.

Phase 1
Image omitted: progress-complete2.png
Analyze alert icon
Analyze and acknowledge an alert
Phase 2
Image omitted: progress-wip.png
Triage alert icon
Triage alerts
Phase 3
Image omitted: progress-not-started.png
Close alert icon
Close an alert

Note: You can run a remediation workflow if your administrator already set up workflows for you to choose from. You should be familiar with your organization’s policies regarding triaging of alerts.

Role required: evt_mgmt_operator

Procedure

  1. From the Service Operations Workspace dashboard, open the alert that you acknowledged in Phase 1: Analyze and acknowledge an alert.

  2. On the Alert form, click Quick Response.

Image omitted: quick-response.png
Quick response
  1. In the Quick Response window, click the name of the remediation under Run Remediation.
Image omitted: run-remediation.png
Running a remediation

What to do next

There are also other tasks you can take as part of the triage stage:

If you do not need to perform any other triage actions, proceed to Phase 3: Close an alert.

Parent Topic:Operator phase 2: Triage an alert