---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add a KB article to an alert

# Add a KB article to a Log Analytics alert {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Add your own knowledge base (KB) article to an alert that was generated by Health Log Analytics. For example, you can provide additional information that might help to resolve the underlying issue.

## Before you begin

This feature is supported in the Health Log Analytics application, Version 22.0.12 - December 2021 and later, and the Health Log Analytics Viewer application, Version 21.0.0 - December 2021 and later. These applications are available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home).

Role required: evt_mgmt_operator or evt_mgmt_admin

## Procedure

1. Open a Log Analytics alert.
   1. In the Service Operations Workspace, select the lists icon (![Lists icon.]()).
   2. Select the appropriate list in the Alerts sub-list and navigate to the desired alert.  
      In the All Alerts list, alerts that were generated by Health Log Analytics have the value Log Analytics in the Source column.
   3. Select the alert number.
   {#hla-op-alert-add-kb-sow__substeps_usb_xcj_gtb}
2. Select the more actions icon (![More Actions icon.]()) at the top right of the Details tab and then choose Create KB article for this issue from the list.
3. On the form, fill in the fields.  
   {#hla-op-alert-add-kb-sow__table_r25_ntb_gtb__entry__2}

   | Field | Description |
   |-|-|
   | Knowledge base | The knowledge base where the new KB article is stored. By default, this value is the Health Log Analytics knowledge base. |
   | Workflow | (Read-only) The status of the KB article. When you publish the article, its status automatically changes from Draft to Published. |
   | Category | The category of the component that caused the alert. |
   | Short description | Summary of the KB article. |
   | Article body | Content of the KB article. |
   [Table 1. Create Knowledge form]

   {#hla-op-alert-add-kb-sow__table_r25_ntb_gtb}
4. Select Save.
5. When the content of the article is final, select Publish.
{#hla-op-alert-add-kb-sow__steps_zfj_ggx_stb}

## Result

The KB article is added to the selected alert.

