Shared impacted services alert grouping
Summarize
Summary of Shared impacted services alert grouping
The Shared impacted services alert grouping feature in ServiceNow Event Management consolidates multiple related alerts under the single business service they affect. This provides your IT team with a focused, organized view of issues, enabling faster identification and resolution of service disruptions.
Show less
How Grouping Works
Each alert is associated with a Configuration Item (CI), such as a server or network device. ServiceNow traces the CI upward through the service hierarchy—from the CI to the application it supports, then to the overarching Business Service. The highest priority Business Service, called the Top Service, is identified based on business criticality. All alerts linked to the same Top Service are automatically grouped together, regardless of the physical or logical distance between their underlying CIs.
This approach differs from traditional CMDB-based alert grouping, which groups alerts only if CIs are within a limited number of topology hops (typically up to four). Shared impacted services alert grouping removes this limitation and groups alerts even when CIs are deep within complex service topologies.
When to Use Shared Impacted Services Alert Grouping
- Shallow service topologies: Both CMDB-based and Shared Impacted Services grouping are effective when CIs supporting a service are close in the topology (within about four hops).
- Deep or complex service topologies: Use Shared Impacted Services grouping when your service hierarchy includes many layers, such as applications, middleware, databases, and infrastructure components spanning multiple levels. This ensures all related alerts tied to the same Top Service are grouped, even if their CIs are far apart in the topology.
This feature helps prevent alert overload and provides a comprehensive view of the impact on critical business services, improving incident detection and response efficiency.
The Shared impacted services alert grouping automatically gathers related alerts under the business service they affect. When your IT environment generates multiple alerts at once, instead of facing a flood of disconnected notifications, your team gets one focused, organized view — making it faster to spot what is broken and act.
The Shared impacted services alert grouping feature solves this by automatically gathering related alerts into one place. It looks at each alert, figures out which business service is ultimately affected — for example, Online Payments or HR Portal — and groups all alerts that point to the same service together.
For details on creating a group automation, see Create Group automation.