Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

SRM Availability SLO – When does an Event Management Alert consume the Error Budget?

RaviT6544609655
Tera Contributor

Hi Everyone,

 

I’m working with ServiceNow Service Reliability Management (SRM) and would like to clarify the expected behavior of an Availability SLI/SLO based on Event Management Alerts.

I have the following configuration:

  • SLI Type: Availability
  • Measurement: Duration
  • SLO Objective: 99%
  • Compliance Period: Rolling 90 days
  • SLI Data Source: Alerts
  • Service: Splunk - MOD
  • SLI Alert Filter: Source contains splunk

An Event Management alert is generated with:

  • Source: Splunk-TA
  • State: Open
  • Severity: Warning
  • The alert is associated with the Splunk - MOD service.

However, the SLO continues to show:

  • Availability: 100%
  • Error Budget Remaining: 100%
  • error budget Rate: 0
  • Reliability: Stable

My questions are:

  1. For an Availability SLI using Alerts as the data source, does every alert matching the service and filter contribute to the SLO/error-budget calculation?
  2. What makes an Event Management alert a "qualified alert" for an Availability SLI?
  3. Does alert severity (for example, Warning vs Critical) affect whether it contributes to an availability breach?
  4. Does an Open alert automatically represent service unavailability, or are additional conditions required?
  5. How is the duration of an alert converted into availability loss and error-budget consumption?
  6. Is there any additional configuration required between Event Management alerts and the Availability SLI for the alert to contribute to the SLO?

I’m mainly looking to understand the standard SRM calculation and qualification logic, rather than troubleshoot a specific instance.

Any documentation or examples explaining this behavior would be appreciated.

Thanks!

0 REPLIES 0