---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Review alerts

# Review alerts {#ariaid-title1}

* Release version: Zurich
* 
* Updated December 19, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Access the Express List interface to review and manage alerts in your Event Management system.

## Before you begin

Verify you have installed the ITOM
AIOps and ServiceNow Otto for IT Operations Management (ITOM) plugins.

Ensure you are in the Configure IT Operations Management page.

Role required: evt_mgmt_admin or evt_team_operator

## About this task

When reviewing alerts, validate the following to ensure your event pipeline is healthy and alerts are actionable:

* Check CI binding. Alerts should populate the cmdb_ci field. If there is no CI, your binding rules need tuning.
* Verify severity spread. If everything lands as Critical or Info, your mapping needs work.
* Confirm that clear events close alerts. Trigger a condition, then resolve it at the source. The alert should auto-close.
* Spot-check key fields. Ensure node, source, resource, and message_key are meaningfully populated (not blank or generic).
* Review Error events. Check em_event status = Error for parsing or mapping issues.
* Check the alert count. Make sure it matches in both your source system and in ServiceNow.

## Procedure

1. Navigate to Configuration SummaryEvent ManagementAlert response.
2. Expand Alert response.
3. Select Review alerts.
4. Select Review alerts in Express List.  
   Express List opens with a list of active alerts.  
   Note:  
   To get more information on alerts so you can more efficiently monitor systems and services, resolve alerts, evaluate the alert impact, track issues, and report incidents, see [Express List in the Service Operations Workspace for ITOM](https://www.servicenow.com/docs/0r9myCAA9IXZvqQB2ChATA "The ServiceNow Event Management Express List feature helps you identify health issues across the datacenter on the Service Operations Workspace. It provides a list of quick information on alerts so you can more efficiently monitor systems and services,​ resolve alerts, evaluate the alert impact,​ track issues, and report incidents.").
5. To complete the setup, select Mark as configured.
{#review-alerts__steps_ipn_t1y_1jc}

*[\>]: and then


