---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Subflows in the base system

# Event Management subflows in the base system {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 Minuten Lesedauer

The subflows provided with the base system appear in the Remediation Subflows area of alert management rules.

## Accessing the subflows {#subflows-provided__section_mb5_123_4gb}

Navigate to Event ManagementRulesAlert Management Rules and click New. Click the Actions tab. In the Remediation Subflows area, double-click the Insert a new row field.

![Specify subflow]()

Click the search icon ![Search icon]() to add subflows. The list of subflows that are provided with the base system appears.  
{#subflows-provided__table_ffj_gwd_b2b__entry__2}

| Name | Description |
|-|-|
| Acknowledge Alert | Subflow to mark the alert as being Acknowledged. Acknowledge an alert to show that further attention is required. |
| Attach Knowledge Article (legacy) | Subflow to attach a knowledge article to the alert. This subflow is provided for instances that are migrated from legacy releases (prior to the London release). Hinweis: Add the Knowledge article column to the Alert Management Rules \[em_alert_management_rule\] table, and select an article to attach to an alert when the rule executes. |
| Change Alert to Maintenance Mode | Subflow to mark the alert as being in Maintenance. |
| Close Alert | Subflow to mark the alert as being Closed. |
| Create Incident | Subflow to create an incident. Fields from the alert are used to populate the matching fields in the incident that is created. Hinweis: * If there is an existing incident that is attached to the alert, this subflow is not activated. * If the alert is in Maintenance, an incident is not created. * The alert management job runs even if the alert grouping job is not complete, if a specified time frame has passed. When this occurs, you can enable the Avoid INTs on secondary alerts rule to prevent incidents from being created for secondary alerts (when the evt_mgmt.avoid_int_enabled property is enabled), since an incident already exists for the primary alert. {#subflows-provided__ul_amh_d32_b2b} |
| Create Major Incident Candidate | Subflow to create a major incident candidate. Fields from the alert populate the matching fields in the major incident candidate that is created. A major incident candidate can be upgraded to become a major incident. Hinweis: * If there is an existing incident that is attached to the alert, this subflow is not activated. * If the alert is in Maintenance, a major incident candidate is not created. * If the Role in group is Secondary, the major incident candidate is not created. {#subflows-provided__ul_ocz_tg5_lhb} |
| Create Major Incident from Alert | Subflow to create a major incident from alert. Fields from the alert are used to populate the matching fields in the major incident that is created. Hinweis: * If there is an existing incident that is attached to the alert, this subflow is not activated. * If the alert is in Maintenance, an incident is not created. * If the Role in group is Secondary, the major incident candidate is not created. {#subflows-provided__ul_irz_wg5_lhb} |
| Create Major Incident with Impact | Subflow to create a major incident from an alert in which the Impact field is also taken as input. Fields from the alert are used to populate the matching fields in the major incident that is created. Hinweis: * If there is an existing incident that is attached to the alert, this subflow is not activated. * If the alert is in Maintenance, an incident is not created. * If the Role in group is Secondary, the major incident candidate is not created. {#subflows-provided__ul_ayn_4s4_llb} |
| Create Major Incident Candidate with Impact | Subflow to create a major incident candidate in which the Impact field is also taken as input. Fields from the alert populate the matching fields in the major incident candidate that is created. A major incident candidate can be upgraded to become a major incident. Hinweis: * If there is an existing incident that is attached to the alert, this subflow is not activated. * If the alert is in Maintenance, a major incident candidate is not created. * If the Role in group is Secondary, the major incident candidate is not created. {#subflows-provided__ul_gfx_xs4_llb} |
| Create Task (legacy) | This subflow uses a task template, if provided, or the EventMgmtCustomIncidentPopulator script for instances migrated from legacy releases (prior to the London release). If configured, apply the task template. Hinweis: Add the Task template column to the Alert Management Rules \[em_alert_management_rule\] table, and select a task template and task to apply when the rule executes. |
| Overwrite Alert Template (legacy) | This subflow applies the alert template. This subflow is provided for instances that are migrated from legacy releases (prior to the London release). Hinweis: Add the Task type column to the Alert Management Rules \[em_alert_management_rule\] table, and select an alert template to apply when the rule executes. |
[Tabelle : 1. Subflows in the base system]

{#subflows-provided__table_ffj_gwd_b2b}

1. Select the subflow that you need.
2. To customize a subflow, see [Create a custom subflow for alerts](https://servicenow-prod.fluidtopics.net/gb84IwJ3MGDT6ATL1wbMPg "You can create a subflow according to your requirements. For example, you can resolve alerts, notify teams, or run remediation actions."). This topic also describes the input parameters in a subflow.
3. To specify when the workflow must be executed, double-click the cell under Execution.

   .
{#subflows-provided__ol_szd_jvx_vgb}

