Washington DC |
- Address alerts more effectively with alert simplifications created by Now Assist using generative AI
- Use alert simplifications in Service Operations Workspace and Express List to help triage and investigate alerts more effectively, which can lead to reduced resolution time.
- Save time by using preconfigured alert clustering tags and definitions
- Get started faster with alert clustering in Event Management by using predefined tags mapped from alerts and based on the information contained in tag sources. You can attach one or more tags to an alert clustering definition. Either create your own
definition or select a predefined definition provided with the application.
- Create a predefined Express List view for users and user groups
- Configure an Express List view for users to make sure that they focus on specific services, priorities, or alerts. You can set the filters, column order, and filter attributes for this view in Event Management and assign it to individual users or user groups.
- Enhanced system properties
- Monitor the behavior of the Agent Client Collector with enhanced Policy Calculation and Framework Configuration system properties, including enhancements to agent Discovery, automatic MID Server selection, and error message logging.
- Configuration data files added to checks
- Provide enhanced data collection in the Agent Client Collector by communicating the instance data with the agent. The configuration data files are also sent to the agent’s associated MID Server.
- Continuously discovering resources in your Kubernetes clusters
- Continuously discover the resources in the Kubernetes clusters deployed in on-premises and cloud environments in near real-time without the need to enter any credentials in your ServiceNow instance. You can ensure that the changes in the resources are promptly reported to the instance and updated in the Configuration Management Database (CMDB).
- Scaling Health Log Analytics to support increased log ingestion
- Stream log data in a scalable, more stable way by using the advanced ServiceNow infrastructure. The Health Log Analytics AI engine has been enhanced to scale dynamically in response to increased log ingestion by your organization.
|
Xanadu |
- Load the allow list only from the configuration file
- Enhance your security by loading the allow list from the configuration file and ignoring the allow-list parameters.
- Configure the agent log level from the instance
- Configure the agent log level directly from the ServiceNow® instance without needing to access the acc.yml configuration file.
- Ensure secure agent connections
- Ensure that your agent connections are secure by adding a self-signed certificate to your operating system's truststore. Adding a certificate to the truststore verifies that the certificate is
authentic.
- Use the new application Service Reliability Management
- Use the Service Reliability Management application to respond, collaborate, track, and self-remediate when working on alerts and incidents.
- Configure the Dynatrace connector instance
- Starting in version 3.6.3, Event Management supports collecting raw metric data collection using the Dynatrace metric connector.
- Enable expanded processing for the MID server on Network Interface Controllers (NICs) during keepalive operation
- Starting in version 3.6.3, benefit from enhanced stability when running a keepalive operation. You can use the enhanced MID Server capability to configure the number of Network Interface Controllers (NICs) that can be monitored by a keepalive operation.
- Stream log data from the System Log table in Glide to the Health Log Analytics AI engine
- Use the Glide Syslog data input to stream log messages from the System Log table (Glide Syslog) in Glide to the Health Log Analytics AI engine (Occultus).
Note: Only a single Glide Syslog data input can exist in the system. This data input doesn't run on a MID Server.
- Enrich automation
- Map current alert fields values to specified new values through the Change alert values option, in the "If these conditions are met, don't add an alert in ServiceNow" section.
- Group automation
- Track and optimize alert grouping efficiency through a new header displaying key details from the Test Automation section, including total alerts, alert groups, ungrouped alerts, and compression.
- View data on configuration items on the preview panel in Express List
- View additional details about configuration items (CIs) that are bound to alerts on the Express List preview panel.
- Speed up alert resolution with a Now Assist analysis of past related incidents
- Enhance efficiency and reduce downtime with a Now Assist analysis of past incidents related to the current alert. Now Assist investigates historical data to identify past incidents related to the current alert and reports their frequency and criticality levels. It also provides a summary of effective strategies used to
resolve them. In addition, Now Assist offers contact information for individuals or teams who have resolved similar incidents in the past and could assist when needed.
- Generate an alert group description in Express List using Now Assist
- Use Now Assist to generate a description of an alert group in Express List that encompasses all the alerts within the group. The generated description replaces the original description of the group.
- Launch an alert analysis from the Now Assist panel
- Analyze an alert from the Now Assist panel. The alert analysis displays directly in the Now Assist panel for convenient review.
|
Yokohama |
- Pull data from Splunk regularly using the Splunk Polling data input
- Fetch data consistently over time by using the Splunk Polling data input, which sends recurring queries (polls) to Splunk. Handling most configurations on the HLA side, you need minimal additional stakeholder involvement, enabling swift integration with your existing Splunk setup. This enhancement accelerates proofs of concept (POCs) and enables faster iterations using real data.
- Use your Splunk data input to ingest pre-processed data from Splunk
- Ingest data from Splunk in a preprocessed, structured format using your existing Splunk data input for streaming log messages to Health Log Analytics with a heavy forwarder.
- Create Group automation
- View key details from the Test Automation section, including total alerts, alert groups, ungrouped alerts, and compression, to help track and optimize alert grouping efficiency. Simulate other group types, such as CMDB, ML,
and text-based grouping. The simulation processes only alerts that match the condition filter.
- Integrate with log data connectors from the Integrations Launchpad
- Set up your log data connectors for HLA from the Event Management
Integrations Launchpad in Service Operations Workspace for ITOM. The Integrations Launchpad provides a unified interface for convenient integration with log data connectors that feed raw log data from external sources into your instance. In this release, the Integrations Launchpad enables integration with the following connectors: Elasticsearch, ServiceNow System Logs, UDP, and TCP.
Starting in version 36.0.19, benefit from additional log data integrations for Splunk TCP/UDP, Splunk Poller, MID Server, Apache Kafka, Microsoft Azure Log Analytics, and REST API that can be easily set up through the Integrations Launchpad.
- Set up an Amazon Data Firehose integration for real-time log data streaming from multiple sources
- Starting in version 36.0.19, leverage an integration for streaming log data from Amazon Data Firehose directly to the collector service in ITOM Gateway, where it is queued and then processed by Health Log Analytics. This integration doesn't run on a MID Server and can be configured from the Integrations Launchpad.
- View links between alerts in Network Traffic-based alert groups
- Once network traffic correlation is enabled, investigate network traffic alert group details and visualize connections through Link View in Express List®.
|
Zurich |
- Facilitate Cribl log data ingestion by Health Log Analytics using the Cribl integration
- Starting in version 37.0.15, use the Cribl log data integration to streamline Health Log Analytics data ingestion with Cribl. If your organization uses Cribl for filtering and routing large volumes of log data from various sources, the log format received by HLA is distinct from other types. The Cribl integration enables HLA to detect and separate transport headers from inner log messages in this format, forwarding only the inner message to the source type structure for processing. You can configure the Cribl integration conveniently through the Integrations Launchpad.
- Leverage additional information available on the integration's Overview screen
-
Starting in version 37.0.15, take advantage of additional information presented on the Overview screen. The screen now displays the ITOM Gateway in the log processing pipeline and the log streaming rate per minute, aligning it with the metrics for the MID Server and the HLA Engine. The Overview screen also shows the source time of the last processed log.
- Benefit from enhanced Log Analytics alert group and mixed alert group functionality in the Express List
- Starting in version 26.9.0, identify connected Log Analytics alerts and mixed alert group correlations faster using the Link View functionality. Utilize enhanced Now Assist Alert Analysis with additional context for Log Analytics alerts.
- View visualizations of anomaly information for Log Analytics-based alerts and metric intelligence alerts in Express List®
- Starting in version 26.9.0, review anomaly charts for Log Analytics alerts and Metric Intelligence alerts in the preview panel in Express List®.
- Configure automatic resume for live updates when the live alert list is paused, and configure time ranges in Express List®
- Starting in version 26.9.0, enable admins to configure the amount of time until the active display resumes after being paused in Express List®. Admins are also able to customize the time range options displayed in Express List®.
- Map log data to service instances and components for alerts in context
- Starting in version 38.0.16, map your logs to service instances and components so that Health Log Analytics can generate alerts in the correct context. Contextualizing your log data is especially important when the integration processes logs from multiple service instances and components.
- Monitor ServiceNow instance logs with the ServiceNow Log Export data input
- Starting in version 38.0.16, set up a data input for monitoring ServiceNow instance node logs from both Java code and JavaScript in Health Log Analytics.
- Live updates functionality has been updated in the Service Operation Workspace Lists.
-
Starting in version 26.11.0, a new toggle switch allows users to enable or disable live updates. When the toggle is set to on, alerts are updated automatically. When the toggle is set to off, a badge displays the number of
available updates until the page is refreshed manually. The setting is saved for future logins by the same user.
- Explore the new Dependency view for an alert
- Starting in version 26.11.0, explore the new Dependency view for an alert. Access maps from the following locations:
- in the preview panel, in the Configuration item section for the CI topology
- in the Utilities panel of the alert record
- in the action drop-down menu
- in the Core UI alert form
- Respond to multiple alerts in Express List
- Starting in version 26.11.0, run response actions on multiple alerts at the same time in Express List.
|