---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Start remediation of a Log Analytics alert

# Take action on a Log Analytics alert from the Overview tab {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Start the Log Analytics alert remediation process from the Overview tab in the Service Operations Workspace. This tab provides information on the alerts, log data associated with the anomalous behavior, CIs that generated the triggering metric, and services impacted by the alerts.

## Before you begin

Role required: evt_mgmt_operator, or evt_mgmt_user, or evt_mgmt_admin

## Procedure

1. In the Service Operations Workspace, select the lists icon (![Lists icon.]()).
2. Select the appropriate list in the Alerts sublist and navigate to the desired alert or group.  
   All alerts generated by Health Log Analytics have the value Log Analytics in the Source column. The value in the Group column identifies the type of Log Analytics alert. See [Types of Health Log Analytics alerts](https://www.servicenow.com/docs/HukQxEq5jxZUatgCi2wRbg "Health Log Analytics generates several types of alerts.") for a more detailed description of each type of alert or group.  
   Tip:  
   To preview an alert in the list, click its info icon (![Info icon.]()).
3. Select the alert number.  
   The Overview tab displays.
4. View the section of the Overview tab that provides the information that you need.  
   For a description of the sections and cards, see [Sections and cards on the alert Overview tab in Health Log Analytics](https://www.servicenow.com/docs/mfZPCziE_j4TAHZVOUJyzg "The Overview tab helps you understand component-based alerts, Log Analytics alerts, and Log Analytics alert groups.").  
   Note:  
   Because some sections on the Overview tab show only a portion of the information, many sections include a link that displays different or more complete information.
5. **Optional:** Run predefined remediation tasks to resolve alert issues.  
   1. Select Launch playbook.
   2. Select the Playbook tab.

      The Run remediation card displays the available remediation actions.
   3. Select the tile corresponding to the action you want to run.
   {#hla-op-overview-tab-view-sow__ol_cnz_jxy_mgc}  
   When the action is complete, it appears in the Completed card.
{#hla-op-overview-tab-view-sow__steps_fdz_bjk_4tb}
* **[Overview tab sections for Component-based alerts](https://www.servicenow.com/docs/WP4WKpQlJlAKkIy5HilqUQ)**   
  The Overview tab in the Service Operations Workspace helps you understand Component-based alerts.
* **[Overview tab sections for Log Analytics alert groups](https://www.servicenow.com/docs/Iu4yY4yyQOqCTe3MfZwWGQ)**   
  The Overview tab in the Service Operations Workspace helps you understand Log Analytics groups.
* **[Overview tab sections for Log Analytics alerts](https://www.servicenow.com/docs/FpS17Bj~_w9WVg0jqD3UFA)**   
  The Overview tab in the Service Operations Workspace helps you understand Log Analytics alerts.

