---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Reduce noise with advanced log alert filters

# Reducing noise by adding advanced log alert filters in Health Log Analytics {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use advanced log alert filters to determine whether to allow an alert or to drop it. These filters reduce noise by dropping alerts that don't indicate a
significant issue.
You can add advanced log alert filters to scan alerts for your defined conditions. For example, you can define a filter that drops alerts coming from specific log sources, or alerts for anomalies that do not cross the specified
threshold.  
Some examples of the actions that advanced filters can enable:

* Alert only on anomalies that are shared across multiple hosts.
* Do not alert on anomalies that happen outside of working hours.
* Do not alert if the anomaly does not cross the specified threshold.
* Alert only on anomalies that are part of a correlation.
{#hla-op-adv-alert-filtering__ul_as1_15c_gnb}  
You can manage advanced log alert filters as follows:

* [Create advanced log alert filters](https://www.servicenow.com/docs/1LAy8ahH4mxt2jJEdJ3IfQ "Add advanced log alert filters to scan alerts for conditions that you specify. The filters reduce noise by dropping alerts that do not indicate a significant issue. While developing a filter, you can test, update, publish, or activate the filter at any time.")

  Add advanced log alert filters to scan alerts for conditions that you specify. The filters reduce noise by dropping alerts that do not indicate a significant issue. While developing a filter, you can test, update,
  publish, or activate the filter at any time.
* Continue modifying the filter by reopening the filter record from the [filters list](https://www.servicenow.com/docs/EfIvw5TWHaNaqJxf9X_ANA "Define, save, and share searches of log data to help determine the causes of Log Analytics alerts."). You can then edit, test, publish, and activate the filter.
{#hla-op-adv-alert-filtering__ul_vw5_nbf_32c}

For more technical information on log alert filters, see the [Advanced Log Alert Filtering \[KB0863538\]](https://support.servicenow.com/kb_view.do?sysparm_article=KB0863538) article in the Now Support Knowledge Base.

