---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Influencing anomaly detection with lexical keywords

# Influencing anomaly detection with lexical keywords {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Influence how Health Log Analytics finds anomalies by managing keywords it looks for in your log data. When text in log data for a source matches a lexical keyword that exceeds a specified count threshold, the system identifies an
anomaly and generates an alert.
Health Log Analytics scans your logs for words that can indicate important issues. Lexical keywords such as 'crashed' or 'failed' signal conditions that may require attention. The application sets a threshold
for each lexical keyword based on its normal occurrence pattern and frequency in your logs.

When Health Log Analytics scans your logs, it identifies all occurrences of the keyword. If the frequency of a lexical keyword in the log data for a source exceeds the specified threshold, the system identifies an
anomaly and generates an alert.  
Health Log Analytics comes with many default global keywords. You can add, edit, and delete these global keywords or phrases, which apply to all source types.  
Note:  
To add a specified keyword associated with a specific source type, see [Configure source type capabilities](https://www.servicenow.com/docs/XJbufIhIjrYtw5IoNifuDQ "Health Log Analytics extracts source types automatically in the mapping process. You can add timestamp formats and specify, delete, or exclude keywords for individual source types.").

You can manage lexical keywords as follows:  
* [Add, edit, or delete Health Log Analytics lexical keywords](https://www.servicenow.com/docs/JWUKsaJPYBAPesmZ38K0Hw "Manage the keywords that Health Log Analytics looks for in your log data.")

  Add, edit, and delete global keywords or phrases.
* [View the lexical keywords that generate alerts](https://www.servicenow.com/docs/hIWBHI1~1ZI2h~J~AzMccw "View the list of lexical keywords that can indicate important issues in log entries.")

  View the list of lexical keywords that can indicate important issues in log entries. By default, the table lists only global keywords.
{#hla-log-anomaly-detection__ul_a3d_ky2_32c}
* **[Add, edit, or delete Health Log Analytics lexical keywords](https://www.servicenow.com/docs/JWUKsaJPYBAPesmZ38K0Hw)**   
  Manage the keywords that Health Log Analytics looks for in your log data.
* **[View the lexical keywords that generate alerts](https://www.servicenow.com/docs/hIWBHI1~1ZI2h~J~AzMccw)**   
  View the list of lexical keywords that can indicate important issues in log entries.

