Exploring Event Management

  • Release version: Zurich
  • Updated July 31, 2025
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exploring Event Management

    Event Management in ServiceNow provides comprehensive monitoring, analysis, and remediation of IT issues by managing various IT environment components such as discovered services, application services, dynamic CI groups, and alert groups. It enables customers to detect, prioritize, and resolve IT issues efficiently, reducing downtime and operational costs while improving system visibility.

    Show full answer Show less

    Key Components

    • Discovered Services: Identified via Service Mapping from interrelated Configuration Items (CIs) in the CMDB, including service maps, impact trees, alerts, and CI properties, displayed on dashboards and alerts/events lists.
    • Application Services: Created by selecting specific CIs for targeted monitoring and management of critical services.
    • Dynamic CI Groups: Flexible collections of CIs grouped by criteria like location, used to populate application services and simplify management.
    • Alert Groups: Organize sets of alerts for streamlined maintenance and faster response to IT incidents.

    Process Flow

    Event Management receives external events via MID Servers polling event tracking tools. Events are stored and processed by matching predefined rules to generate alerts. Alerts are enriched, accumulated, and mapped to CIs for root cause analysis. The system consolidates related events under single alerts, enabling efficient issue tracking and resolution.

    User Roles

    • Admin (evtmgmtadmin): Full read/write access to configure Event Management, including managing scripts and rules globally. Requires careful access control due to elevated permissions.
    • Operator (evtmgmtoperator): Manages alert lifecycle, including acknowledging and closing alerts, ensuring proper categorization and prioritization.
    • Team Operator (evtteamoperator): Manages alerts and configurations for their assigned team only, with read/write access limited to their assignment group.
    • User (evtmgmtuser): Performs basic alert operations such as viewing and acknowledging alerts.

    Benefits

    • Rapid Issue Detection: Quickly identifies potential IT problems.
    • Efficient Alert Handling: Aggregates and correlates alerts to reduce noise and improve management.
    • Automated Actions: Supports automatic remediation for faster issue resolution.
    • Comprehensive Monitoring: Integrates with multiple tools for a holistic view of system health.
    • Root Cause Analysis: Associates alerts to CIs to identify underlying causes.
    • Customizable Rules: Allows tailoring of event and alert management to specific organizational needs.
    • Reduced Downtime: Enables prompt problem resolution to minimize service interruptions.
    • Enhanced Visibility: Real-time dashboards provide actionable insights.
    • Cost Efficiency: Helps prevent prolonged issues, lowering operational expenses.

    Explore Event Management to understand its overview, process flow, user roles, and benefits for comprehensive IT issue monitoring and resolution.

    Event Management provides comprehensive monitoring, analysis, and remediation of IT issues by effectively managing various components within an IT environment. These components include discovered services, application services, dynamic CI groups, and alert groups.
    • Discovered Services: Defined by interrelated Configuration Items (CIs) from the CMDB, a discovered service is identified through Service Mapping. It includes a service map with mapping relationships, an impact tree showing outage severity, active and related alerts, and CI properties. This service information is displayed on dashboards, the Alerts list, and the Events list.
    • Application Services: Created by selecting specific CIs, application services allow for targeted monitoring and management. For more details, refer to the Application Services documentation.
    • Dynamic CI Groups: These are collections of CIs grouped based on shared criteria, such as location. Dynamic CI groups help populate application services, simplifying management.
    • Alert Groups: Alert groups organize sets of alerts to streamline maintenance and management, making it easier to respond to IT issues efficiently.

    Process flow

    Event Management receives external events and generates alerts based on predefined rules. The MID Server polls external event tracking tools and sends data to Event Management for storage and processing. Events are stored in the Event [em_event] table, and alerts are created by matching event rules. Alerts are then transformed and enriched with additional content, accumulated if thresholds are met, and mapped to specific fields. The system searches for matching message keys to update existing alerts or create new ones, associating related events under a single alert. Alerts are bound to specific Configuration Items (CIs) for root cause analysis. For more information, see Event Management process flow.

    Users

    Role title [name] Description
    Admin

    [evt_mgmt_admin]

    Has read and write access to all Event Management features to configure Event Management.
    Note:
    Exercise caution with the evt_mgmt_admin role, as it can be elevated to the admin role. A user with the evt_mgmt_admin role has the ability to add and modify scripts that run on a global scope. Ensure proper access control. With this role, the user can create and/or update the following scripts:
    • Alert correlation rules
    • Alert management rules
    • Maintenance rules
    • Advanced scripts
    • Event field mapping
    • Pre- and post-binding scripts
    Operator

    [evt_mgmt_operator]

    Manages alerts, including closing and acknowledging them. Oversees the overall Event Management process, ensuring events are properly categorized, prioritized, and routed for resolution.
    Team Operator

    [evt_team_operator]

    Manages Event Management operations within a specific team as defined in the Assignment Group field. This role allows the operator to read and write alerts exclusively for their assigned team. Additionally, the operator can make configuration changes specific to their team, including updates to Alert Automation and the Integrations Launchpad.
    Note:
    The evt_team_operator role must be assigned to an assignment group to view and manage alerts for that group. If the role is created but not associated with any groups that have alerts assigned, the operator cannot see any alerts.
    User

    [evt_mgmt_user]

    Manages the lifecycle of alerts, including performing basic operations such as viewing and acknowledging them.

    Benefits

    • Rapid Issue Detection: Quickly identifies and highlights potential IT issues.
    • Efficient Alert Handling: Aggregates and correlates alerts for streamlined management.
    • Automated Actions: Initiates automatic remediation processes to speed up issue resolution.
    • Comprehensive Monitoring: Integrates with multiple tools for a complete system overview.
    • Root Cause Analysis: Offers tools to identify underlying causes of issues.
    • Customizable Rules: Tailors event and alert management rules to specific needs.
    • Reduced Downtime: Minimizes system downtime with prompt problem resolution.
    • Enhanced Visibility: Real-time dashboards offer insights into system health.
    • Cost Efficiency: Lowers operational costs by preventing prolonged issues.