Combined ITOM Health release notes for upgrades from Xanadu to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 12 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined ITOM Health Release Notes for Upgrades from Xanadu to Zurich

    This document consolidates the ITOM Health release notes for ServiceNow customers upgrading from the Xanadu release through Yokohama to Zurich. It highlights new features, changes, deprecations, and activation details across these releases to help you prepare and optimize your upgrade process. The notes cover enhancements in alert automation, log data integration, service reliability management, and AI-driven incident investigation, enabling improved operational visibility and faster incident resolution.

    Show full answer Show less

    Key Features

    • Xanadu Enhancements:
      • App Service Extension app for improved application service mapping.
      • Ability to configure agent log levels directly from the ServiceNow instance.
      • Secure agent connections via self-signed certificates added to truststores.
      • Introduction of the Service Reliability Management application for collaborative alert and incident handling.
      • Support for Dynatrace metric connector in Event Management.
      • Expanded MID Server NIC monitoring during keepalive operations for enhanced stability.
      • Streaming of system logs from Glide Syslog to Health Log Analytics AI engine without MID Server dependency.
      • Alert automation improvements including enriched alert value mapping and enhanced alert grouping visibility.
      • Use of Now Assist AI to analyze past related incidents for accelerated alert resolution and to generate alert group descriptions.
      • View configuration item details on the Express List preview panel.
    • Yokohama Enhancements:
      • Regular data polling from Splunk for consistent log ingestion.
      • Ingest pre-processed structured data from Splunk using existing data inputs.
      • Integration with log data connectors via the Event Management Integrations Launchpad, supporting Elasticsearch, ServiceNow System Logs, UDP, TCP, and others.
      • Amazon Data Firehose integration for real-time log streaming to Health Log Analytics without requiring a MID Server.
      • Network traffic-based alert grouping with visual link views in Express List for better alert correlation.
    • Zurich Release: No new features or updates reported.

    Key Changes

    • Alert automation refinements, including renaming and user interface changes to simulation controls and enrich automation options to improve clarity without changing functionality.
    • Service Reliability Management now allows system administrators to associate any supported service regardless of owner or support group settings.
    • Now Assist incorporates Retrieval-Augmented Generation (RAG) for improved alert investigations by retrieving highly relevant past incidents and facilitating collaboration through contact notifications.
    • Deprecation of component-based alert grouping in Health Log Analytics to streamline alert models and improve management efficiency.

    Deprecations and Removals

    • Several Event Management dashboards including scorecards, insights, and overview have been deprecated.
    • The Service Management Dashboard is slated for future deprecation and will no longer be activated on new instances but remains supported for now.
    • No removals reported in the releases covered.

    Activation and Installation

    • ITOM Health is available through activation of the Event Management plugin (com.glideapp.itom.snac).
    • Health Log Analytics requires purchase of ITOM Predictive AIOps and installation of associated apps such as Service Operations Workspace (ITOM) and AIOps Experience from the ServiceNow Store.
    • Multiple apps and connectors can be installed and managed via the ServiceNow Store to extend ITOM Health capabilities.

    Accessibility and Localization

    • Yokohama release added support for reflow in the Service Dashboard and Log Viewer, allowing zoom up to 400% without content loss, aiding users with low vision.
    • Health Log Analytics supports multiple languages including US and UK English, French, German, Italian, Japanese, and Spanish.

    Highlights for ServiceNow Customers

    • Enhanced security and configuration flexibility for agents improve operational reliability.
    • AI-powered Now Assist accelerates root cause analysis and collaboration by leveraging historical incident data.
    • Expanded log ingestion options, including integrations with Splunk, Amazon Data Firehose, and other connectors, enable comprehensive log analytics.
    • New alert grouping methods based on network traffic correlations provide better insight into related incidents and their impact.
    • Streamlined alert models and automation options facilitate efficient incident management and reduce alert noise.

    Consolidated page of all release notes for ITOM Health from Xanadu to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family ITOM Health release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading ITOM Health to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Xanadu

    Enhance your application service mapping by installing the App Service Extension app from the ServiceNow® Store.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for ITOM Health.

    Release Release notes

    Xanadu

    Load the allow list only from the configuration file
    Enhance your security by loading the allow list from the configuration file and ignoring the allow-list parameters.
    Configure the agent log level from the instance
    Configure the agent log level directly from the ServiceNow® instance without needing to access the acc.yml configuration file.
    Ensure secure agent connections
    Ensure that your agent connections are secure by adding a self-signed certificate to your operating system's truststore. Adding a certificate to the truststore verifies that the certificate is authentic.
    Use the new application Service Reliability Management
    Use the Service Reliability Management application to respond, collaborate, track, and self-remediate when working on alerts and incidents.
    Configure the Dynatrace connector instance
    Starting in version 3.6.3, Event Management supports collecting raw metric data collection using the Dynatrace metric connector.
    Enable expanded processing for the MID server on Network Interface Controllers (NICs) during keepalive operation
    Starting in version 3.6.3, benefit from enhanced stability when running a keepalive operation. You can use the enhanced MID Server capability to configure the number of Network Interface Controllers (NICs) that can be monitored by a keepalive operation.
    Stream log data from the System Log table in Glide to the Health Log Analytics AI engine
    Use the Glide Syslog data input to stream log messages from the System Log table (Glide Syslog) in Glide to the Health Log Analytics AI engine (Occultus).
    Note:
    Only a single Glide Syslog data input can exist in the system. This data input doesn't run on a MID Server.
    Enrich automation
    Map current alert fields values to specified new values through the Change alert values option, in the "If these conditions are met, don't add an alert in ServiceNow" section.
    Group automation
    Track and optimize alert grouping efficiency through a new header displaying key details from the Test Automation section, including total alerts, alert groups, ungrouped alerts, and compression.
    View data on configuration items on the preview panel in Express List
    View additional details about configuration items (CIs) that are bound to alerts on the Express List preview panel.
    Speed up alert resolution with a Now Assist analysis of past related incidents
    Enhance efficiency and reduce downtime with a Now Assist analysis of past incidents related to the current alert. Now Assist investigates historical data to identify past incidents related to the current alert and reports their frequency and criticality levels. It also provides a summary of effective strategies used to resolve them. In addition, Now Assist offers contact information for individuals or teams who have resolved similar incidents in the past and could assist when needed.
    Generate an alert group description in Express List using Now Assist
    Use Now Assist to generate a description of an alert group in Express List that encompasses all the alerts within the group. The generated description replaces the original description of the group.
    Launch an alert analysis from the Now Assist panel
    Analyze an alert from the Now Assist panel. The alert analysis displays directly in the Now Assist panel for convenient review.

    Yokohama

    Pull data from Splunk regularly using the Splunk Polling data input
    Fetch data consistently over time by using the Splunk Polling data input, which sends recurring queries (polls) to Splunk. Handling most configurations on the HLA side, you need minimal additional stakeholder involvement, enabling swift integration with your existing Splunk setup. This enhancement accelerates proofs of concept (POCs) and enables faster iterations using real data.
    Use your Splunk data input to ingest pre-processed data from Splunk
    Ingest data from Splunk in a preprocessed, structured format using your existing Splunk data input for streaming log messages to Health Log Analytics with a heavy forwarder.
    Create Group automation
    View key details from the Test Automation section, including total alerts, alert groups, ungrouped alerts, and compression, to help track and optimize alert grouping efficiency. Simulate other group types, such as CMDB, ML, and text-based grouping. The simulation processes only alerts that match the condition filter.
    Integrate with log data connectors from the Integrations Launchpad
    Set up your log data connectors for HLA from the Event Management Integrations Launchpad in Service Operations Workspace for ITOM. The Integrations Launchpad provides a unified interface for convenient integration with log data connectors that feed raw log data from external sources into your instance. In this release, the Integrations Launchpad enables integration with the following connectors: Elasticsearch, ServiceNow System Logs, UDP, and TCP.

    Starting in version 36.0.19, benefit from additional log data integrations for Splunk TCP/UDP, Splunk Poller, MID Server, Apache Kafka, Microsoft Azure Log Analytics, and REST API that can be easily set up through the Integrations Launchpad.

    Set up an Amazon Data Firehose integration for real-time log data streaming from multiple sources
    Starting in version 36.0.19, leverage an integration for streaming log data from Amazon Data Firehose directly to the collector service in ITOM Gateway, where it is queued and then processed by Health Log Analytics. This integration doesn't run on a MID Server and can be configured from the Integrations Launchpad.
    View links between alerts in Network Traffic-based alert groups
    Once network traffic correlation is enabled, investigate network traffic alert group details and visualize connections through Link View in Express List®.

    Zurich

    No updates for this release.

    Changes

    Between your current release family and Zurich, some changes were made to existing ITOM Health features.

    Release Release notes

    Xanadu

    Alert automation enhancements
    In Group automation, in the Simulation section, Re-run test has been renamed Re-run simulation.
    The Active toggle switch has been replaced with a check box.
    Enrich automation
    A new section, And finally, featured two radio buttons, Run other enrich alert automations and Don't run other enrich alert automations, which replace the previous Continue running automations of this type toggle switch. Although this section is new, the functionality is unchanged. Selecting Run other enrich alert automations continues running automations with the same filter conditions, while Don't run other enrich alert automations halts additional automations after execution except for those owned by other assignment groups.
    Associate services to use in Service Reliability Management
    System admins can select any supported service and associate it to use in Service Reliability Management regardless of the owner or support group configurations.

    Yokohama

    Enrich automation
    Introduced a new section And finally that contains two radio buttons that replace the previous Continue running automations of this type toggle switch.
    • Run other enrich alert automations continues running automations with the same filter conditions.
    • Don't run other enrich alert automations halts additional automations after execution, except those owned by other assignment groups.
    Investigate alerts using Now Assist

    Investigate alerts using Now Assist, which now uses the Retrieval-Augmented Generation (RAG) process to enhance alert investigation. This enhancement enables the retrieval of highly relevant past incidents, providing accurate context and actionable insights. Now Assist also notifies users of those involved in past or present efforts to resolve similar issues, promoting collaboration and reducing duplicated efforts.

    Component-based alert grouping is deprecated
    Starting in version 36.0.19, component-based alert groups are removed as Health Log Analytics adopts a streamlined, two-tier alert model: Log Analytics Group to Single Alert. It aligns alert representation with the service-level anomalies identified by Health Log Analytics, rather than individual host CIs. The update improves alert visibility, simplifies correlation, and enhances overall alert management efficiency.

    Zurich

    No updates for this release.

    Removed

    Between your current release family and Zurich, some ITOM Health features or functionality were removed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some ITOM Health features or functionality were deprecated.

    Release Release notes

    Xanadu

    The following dashboards have been deprecated:
    • Event Management scorecards
    • Event Management insights
    • Event Management overview
    • Health Log Analytics Overview
    Service Management Dashboard is being prepared for future deprecation. It will be hidden and no longer activated on new instances but will continue to be supported. For details, see the Deprecation Process [KB0867184] article in the Now Support knowledge base.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate ITOM Health.

    Release Release notes

    Xanadu

    is available with activation of the Event Management plugin (com.glideapp.itom.snac). To work with Health Log Analytics, you must purchase ITOM Predictive AIOps, a more comprehensive package. For details, see Event Management setup.

    Install Service Operations Workspace (ITOM) by installing the AIOps Experience [sn_sow_aiops] application from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Yokohama

    • is available with activation of the Event Management plugin (com.glideapp.itom.snac). You must purchase a more comprehensive package, ITOM Predictive AIOps, to enable working with Health Log Analytics. For details, see Event Management setup.
    • Install Service Operations Workspace (ITOM) by installing the AIOps Experience [sn_sow_aiops] application from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
    • Install Health Log Analytics by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    No updates for this release.

    Additional requirements

    If any additional requirements were introduced or changed for ITOM Health we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for ITOM Health we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for ITOM Health, such as specific requirements or compliance levels.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    Support for reflow
    The Service Dashboard and Log Viewer component was updated to support reflow, which enables pages and content to be zoomed up to 400% through your browser settings without loss of content or functionality. Additionally, content can be enlarged without scrolling in two dimensions at a width equivalent to 320 CSS pixels or a height equivalent to 256 CSS pixels.
    This enhancement helps users with low vision or who have trouble seeing web content in a browser due to monitor size, device type, poor lighting, or other situations. Reflow can be turned off with a system property for instances, experiences, and pages. See Reflow for Configurable Workspace for details.

    Zurich

    No updates for this release.

    Localization information

    If there are specific localization considerations for ITOM Health we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    The current available languages for Health Log Analytics are US English, UK English, French, German, Italian, Japanese, and Spanish. The default language is US English.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for ITOM Health we have noted them here.

    Release Release notes

    Xanadu

    Agent Client Collector highlights:
    • Configure the agent log level from the instance without needing to access the acc.yml configuration file.
    • Ensure secure agent connections by adding a self-signed certificate.
    • Gather expanded information on your Linux and Windows servers by using expanded Linux and Windows checks.
    Health Log Analytics highlights:
    • Enhance your system with the latest updates: Security fixes; Filebeat, Elasticsearch, and Microsoft Azure Event Hubs data input updates; Java JDK 17 update and support, and dependency upgrades.
    • Stream system logs from Glide to Health Log Analytics using the Glide Syslog data input.
    Event Management release notes highlights:
    • View configuration item (CI) information on the preview panel in Express List.
    • Optimize alert resolution with Now Assist AI-driven investigation of past related incidents.
    • Generate an alert group description in Express List using Now Assist.
    • Launch an alert analysis from the Now Assist panel.

    Yokohama

    Health Log Analytics highlights:
    • Pull data from Splunk consistently over time using the Splunk Polling data input, which sends recurring queries (polls) to Splunk.
    • Use your Splunk data input to ingest data from Splunk in a pre-processed, structured format.
    • Integrate with log data connectors from the Integrations Launchpad
    • Use dedicated Cribl, Edge Delta and Vector Agent data inputs to streamline HLA data ingestion with tools handling large log volumes.
    • Generate a description of Health Log Analytics alerts using Now Assist.

    Event Management highlights:

    Service Operations Workspace for ITOM
    • Starting with version 26.3.1, benefit from the new alert grouping based on network traffic correlation:
      • Use Express List® to investigate network traffic-based alert groups
      • View connections between network traffic-based alerts in Link View.
      • Starting with version 2.5.3, review alert group analysis by Now Assist
    • Review relevant information in the Now Assist panel based on records selected in Express List®.
    • Enable team-level operators to create and manage new alert automations by assigning the new team_operator role.
    • Map current alert field values to new specified values through the new Change alert values option in the Enrich automation section.
    • Track and optimize grouping efficiency by viewing key details such as total alerts, alert groups, ungrouped alerts, and compression in Group Automation. Simulate other group types, such as CMDB, ML, and text-based grouping.

    Agent Client Collector highlights:

    See ITOM Health for more information.

    Zurich

    No updates for this release.