---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Log Analytics in SOW for ITOM

# Log Analytics in Service Operations Workspace for ITOM {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

View and address the alerts that Health Log Analytics generates in the
Service Operations Workspace.
* **[Take action on a Log Analytics alert from the Overview tab](https://www.servicenow.com/docs/p7lUAEkljj~IE6UeonNXZg)**   
  Start the Log Analytics alert remediation process from the Overview tab in the Service Operations Workspace. This tab provides information on the alerts, log data associated with the anomalous behavior, CIs that generated the triggering metric, and services impacted by the alerts.
* **[Analyze log lines to identify an alert root cause](https://www.servicenow.com/docs/wv74ez94XAmqyQSo~DIjlQ)**   
  When Health Log Analytics identifies an anomaly, viewing the logs that surround the anomaly provides clues about the state of faulting systems. This information can help you narrow down the root cause of an alert.
* **[Review alert logs on the Log viewer](https://www.servicenow.com/docs/xGsJxEGve7Bem4vrAbLfkQ)**   
  The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.
* **[Assigning higher or lower significance to an alert in Health Log Analytics](https://www.servicenow.com/docs/VJid975hXeXWUoUBvXknLg)**   
  Label an alert as meaningful or insignificant, or restore normal importance to the metric involved in generating it.
* **[Dashboards for real-time visualization of log data in Health Log Analytics](https://www.servicenow.com/docs/yKLACj6_CP9~J~mbKlYovA)**   
  Health Log Analytics enables you to create log data dashboards and visualizations in real time for enhanced data monitoring and faster identification of deviations.
* **[Add a KB article to a Log Analytics alert](https://www.servicenow.com/docs/6d~wzIna~Jre1yyUOY4xxg)**   
  Add your own knowledge base (KB) article to an alert that was generated by Health Log Analytics. For example, you can provide additional information that might help to resolve the underlying issue.

