Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Add a KB article to a Log Analytics alert

Add your own knowledge base (KB) article to an alert that was generated by Health Log Analytics. For example, you can provide additional information that might help to resolve the underlying issue. Health Log Analytics also uses your knowledge to enhance similar alerts.

Before you begin

This feature is supported in the Health Log Analytics application, Version 22.0.12 - December 2021 and later, and the Health Log Analytics Viewer application, Version 21.0.0 - December 2021 and later. These applications are available from the ServiceNow Store.

Role required: evt_mgmt_operator or evt_mgmt_admin

Procedure

  1. Open a Log Analytics alert.

    1. In the Service Operations Workspace, select the lists icon (
Image omitted: icon-lists-sow.png
Lists icon.\).
2.  Select the appropriate list in the Alerts sub-list and navigate to the desired alert.

    In the **All Alerts** list, alerts that were generated by Health Log Analytics have the value **Log Analytics** in the **Source** column.

3.  Select the alert number.
  1. Select the more actions icon (
Image omitted: icon-more-actions-sow.png
More Actions icon.\) at the top right of the **Details** tab and then choose **Create KB article for this issue** from the list.
  1. On the form, fill in the fields.
FieldDescription
Knowledge baseThe knowledge base where the new KB article is stored. By default, this value is the Health Log Analytics knowledge base.
Workflow\(Read-only\) The status of the KB article.When you publish the article, its status automatically changes from Draft to Published.
CategoryThe category of the component that caused the alert.
Short descriptionSummary of the KB article.
Article bodyContent of the KB article.
  1. Select Save.

  2. When the content of the article is final, select Publish.

Result

The KB article is added to the selected alert.