Review alert-related logs on the Log Viewer

  • Release version: Zurich
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Review alert-related logs on the Log Viewer

    The Log Viewer in Health Log Analytics provides ServiceNow customers with a powerful interface to browse and analyze logs associated with alerts. It enables you to examine log data by timestamp or time range, visualize anomaly frequencies, and customize filters to better understand the context of anomalies. This helps accelerate root cause analysis and improves issue resolution efficiency.

    Show full answer Show less

    Key Features

    • Comprehensive Alert Log Data: Displays the query related to the anomaly, selected components, and time filters, allowing for detailed inspection of alert-related logs.
    • Customizable Filters and Time Ranges: You can add or remove filters in the Filters pane and adjust time ranges independently to focus on relevant log data without altering other settings.
    • Anomaly Frequency Visualization: Shows a chart of anomalous log line frequency from one minute before to one minute after the alert, helping identify trends around the event.
    • Search Query Management: Allows fine-tuning of queries to pinpoint causes, saving useful searches, and sharing them with team members to enhance collaboration.
    • Saved Searches: Enables reuse and modification of saved searches for consistent log analysis and quicker troubleshooting.
    • Table Customization: Add or remove columns in the Log Viewer table to tailor the display to your specific needs.

    Practical Application

    By leveraging the Log Viewer, you can quickly identify the conditions leading up to and following an alert, improving your ability to diagnose and resolve underlying issues. Additionally, discovering critical metrics in logs allows you to create custom Log Analytics alert rules, further optimizing your monitoring and incident response processes.

    The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.

    The Log Viewer presents all data connected with the Log Analytics alert. It shows the query that relates to the anomaly, the selected component, and the appropriate time filter. You can personalize the displayed data, and manually adjust the time range without affecting the other settings. The applied filters appear in the Filters pane. You can add or remove filters as needed to show only the data you want to view.

    The Log Viewer displays a chart of the frequency of anomalous log lines during one minute before and one minute after the Log Analytics alert and lists the associated log data. This information helps you identify trends leading up to and following the event, providing context for root cause analysis.

    As you analyze the logs for an alert on the Log Viewer, you can modify the query to fine-tune the search, save useful searches, and share them with others. For a description of the information displayed in the Log Viewer table, see Log Viewer table fields.

    You can perform the following tasks on the Log Viewer:

    If you discover an important metric in the log data, you can use it to define a new Log Analytics alert rule. For more information, see Define a custom Log Analytics alert rule in Health Log Analytics.