---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Close an alert

# Close an alert {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Close an alert by an event or a user action. Closing an alert also closes any related
incident that is not already resolved or closed.

## Before you begin

Role required: evt_mgmt_admin or evt_mgmt_operator

## About this task

An alert can be closed manually, automatically by a close or clear event, or when a related incident is resolved. Whether the alert is closed when the incident is closed is determined by the
evt_mgmt.incident_closes_alert property. The default value is Yes (True).

When a Clear event is triggered for an open alert, the corresponding alert is set to the "Closed" state. Closing an alert also closes any related incident that is not already resolved or closed. This default behavior can be
configured using the evt_mgmt.alert_closes_incident property.

## Procedure

1. Navigate to Event ManagementAll Alerts.
2. Select the alert you want to close.
3. In the Alert Form, select Close.  
   The alert closes without confirmation. If the alert has any resolved or closed incidents, a work note is added to the incident indicating that the related alert was closed.

   If an alert has an open incident that is not
   related to any other open alerts, the incident is either closed, resolved, or left unchanged based on the evt_mgmt.alert_closes_incident property. The available values are: Resolve Incident, Close
   Incident and Do Nothing.
{#t_EMCloseAlert__steps_tfh_t3h_25}

*[\>]: and then


