---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Analyzing and resolving alerts

# Analyzing and resolving Log Analytics alerts {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Analyze and resolve Log Analytics alerts by investigating log data and taking action to resolve the underlying issue.

## Overview of analyzing and resolving a Log Analytics alert {#hla-analyzing-resolving-hla-alert__cf-using-parent-workflow}

As an Operator, you are responsible for analyzing and resolving the alerts that Health Log Analytics generates. When HLA creates an alert, you review the alert's severity, the affected Configuration Item (CI), the log data associated with the anomaly, and the impacted services. You try to identify the root
cause by investigating the logs that surround the anomaly.

In the Express List, review alert details and use Now Assist to get an in-depth analysis of the alert and potential resolutions in straightforward, human-readable language. By drilling down into the alert, you can quickly identify the issue and proceed to resolve
it before it affects your users.

Using the Log Viewer, you can browse the alert logs by timestamp or range for further investigation. You can visualize the frequency of anomalous log lines in a chart.

More detailed information on tasks and procedures for analyzing and resolving Log Analytics is available via the following links.

* [Start remediation of a Log Analytics alert from the Overview tab](https://servicenow-prod.fluidtopics.net/scaZOkYM~Hg1i0I_E_sF6g "Begin the remediation process of a Log Analytics alert from the alert Overview tab. This tab provides information on the alert, the log data associated with the anomalous behavior, CIs associated with the alert, and services impacted by it.")

  Begin the remediation process of a Log Analytics alert from the alert Overview tab. This tab provides information on the alert, log data associated with the anomalous behavior, CIs associated with the alert, and services
  impacted by it.
* [Analyze the logs that surround the anomaly](https://servicenow-prod.fluidtopics.net/uW7dSm2MiHpmIH~Sxqr7aw "When Health Log Analytics identifies an anomaly, viewing the logs that surround the anomaly provides clues about the state of faulting systems. This information can help you narrow down the root cause of an alert.")

  Review the log lines surrounding the anomaly for clues about the state of faulting systems. This information can help you narrow down the root cause of the alert.
* [Use log correlators to identify relationships in log data](https://servicenow-prod.fluidtopics.net/NQ1d6E9fJlxpioxlkY7pHg "Log correlators are keys or values in log data that detect correlations between alerts to help you determine whether an alert is part of a larger issue. For example, a log correlator could detect when the interface ID of a particular network device occurs simultaneously in multiple warnings across different service instances.")

  Identify relationships between alerts to help you determine whether an alert is part of a larger issue.
* Navigate to the [Express List](https://servicenow-prod.fluidtopics.net/vWP5n4vciu88UvkwnR_C0g "The ServiceNow Event Management Express List feature helps you identify health issues across the datacenter on the Service Operations Workspace. It provides a list of quick information on alerts so you can more efficiently monitor systems and services,​ resolve alerts, evaluate the alert impact,​ track issues, and report incidents.") and select an alert from the Alerts list.

  Use [Now Assist](https://servicenow-prod.fluidtopics.net/hIGt76AzkFIdAsICtuVFHA "View an alert analysis created by Now Assist using generative AI. Alert analyses include a human-readable brief of the alert and technical information to help you investigate the alert more effectively.") to get an in-depth analysis of the alert and potential resolutions. By drilling down into the alert, you can quickly identify the issue and proceed to resolve
  it.
* [Review the logs for an alert on the Log viewer](https://servicenow-prod.fluidtopics.net/~KZgCI02ygNerk6YUa8png "The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.")

  For further investigation you can navigate to the Log Viewer to browse the alert logs by timestamp or time range, and visualize anomaly frequency within a time period for a comprehensive view of log data
  over a specified time range.
* [Add a KB article to a Log Analytics alert](https://servicenow-prod.fluidtopics.net/TM90HlV7iIK9tp7~KshFDg "Add your own knowledge base (KB) article to an alert that was generated by Health Log Analytics. For example, you can provide additional information that might help to resolve the underlying issue. Health Log Analytics also uses your knowledge to enhance similar alerts.")

  When you have resolved an alert that Health Log Analytics generated, you can add a knowledge base (KB) article to it. For example, provide information that might help others resolve similar issues.

{#hla-analyzing-resolving-hla-alert__cf-using-parent-steps-ul}

For a brief explanation of key terms and concepts used in HLA, see the [Health Log Analytics terminology](https://servicenow-prod.fluidtopics.net/kZCbgPiSSUEbsL6nAZIO2A "Before getting started with Health Log Analytics, it's important to familiarize yourself with some key concepts used in the application.").

## Use cases {#hla-analyzing-resolving-hla-alert__cf-using-more-info}

[Use Case: Proactive monitoring of your ServiceNow instance in Health Log Analytics](https://servicenow-prod.fluidtopics.net/Wx7OmfVvH6ZgJE6LMM5qzg "Use Health Log Analytics to detect and resolve emerging issues in your organization's ServiceNow instance before they negatively impact users.") - Use Health Log Analytics to detect and resolve emerging issues in your organization's ServiceNow instance before they affect platform users.

