---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add, edit, or delete lexical keywords

# Add, edit, or delete lexical keywords in Health Log Analytics {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Manage the keywords that Health Log Analytics looks for in your log
data.

## Vorbereitungen

Role required: evt_mgmt_operator or evt_mgmt_admin

## Warum und wann dieser Vorgang ausgeführt wird

In log data, terms like "crash" or "failed" are called lexical keywords
because they indicate issues that can merit attention. When text in log data for a
source matches a lexical keyword that exceeds a specified count threshold, the
system identifies an anomaly and generates an alert.  
Wichtig:  
A lexical keyword differs from a key in a `key:value` pair in a log line. For example, Hostname is a key that takes on a value: the name or IP address of the host. In contrast, a keyword like Failed is important by itself and does not take on a value.  
The application comes with many default global keywords. You can add, edit, and delete global keywords or phrases. These keywords apply to all source types.  
Hinweis:  
To add a specified keyword that is associated with a specific source type, see [Configure source type capabilities in Health Log Analytics](https://servicenow-prod.fluidtopics.net/3jmdXC92oPSSalx4jb9uQg "Health Log Analytics extracts source types automatically in the mapping process. You can add timestamp formats and specify, delete, or exclude keywords for individual source types.").

## Prozedur

1. Navigate to AllHealth Log AnalyticsLog Anomaly DetectionLexical Keywords.  
   By default, the Lexical Keywords table lists only global keywords.
2. **Wahlweise:** Add a global keyword.
   1. Select New.
   2. On the form, fill in the fields.  
      {#hla-lexical-keywords-admin__table_z5c_ycf_r4b__entry__2}

      | Field | Description |
      |-|-|
      | Name | Unique and descriptive name for the keyword. |
      | Regular expression | Regular expression (regex) that defines matches. |
      | Exact match | Option to make Health Log Analytics match the exact regex. For example, 'NullPointerException' in a message would not match the regex 'exception'. This field is automatically set to True. |
      | Case-sensitive | Option to make Health Log Analytics look for a case-sensitive match of the regex. This field is automatically set to False. |
      | Range of analysis | Range of sources types where Health Log Analytics looks for the keyword in the log data. Choices are as follows: * All source types * Specified source type {#hla-lexical-keywords-admin__ul_avc_ycf_r4b} |
      | Excluded source types | Source types that are not associated with the keyword. Health Log Analytics does not look for the keyword in the log data of these source types. |
      [Tabelle : 1. Lexical keyword form]

      {#hla-lexical-keywords-admin__table_z5c_ycf_r4b}
   3. Select Submit.
   {#hla-lexical-keywords-admin__substeps_cnp_r25_fsb}
3. **Wahlweise:** Edit a global keyword.
   1. Click the keyword that you want to edit in the list.
   2. On the form, edit the relevant fields.
   3. Select Update.
   {#hla-lexical-keywords-admin__substeps_v1n_m25_fsb}
4. **Wahlweise:** Delete one or more global keywords.
   1. Select the rows of the keywords that you want to delete.
   2. From the Actions on selected rows list at the bottom of the page, select Delete.
   3. Select OK.
   {#hla-lexical-keywords-admin__substeps_obg_p25_fsb}
{#hla-lexical-keywords-admin__steps-view-lexical-keyword-list}
**Zugehörige Tasks**   

* [View the lexical keywords that generate alerts in Health Log Analytics](https://servicenow-prod.fluidtopics.net/qD7XHUT0NjOnNTU4NTxF~g "View the list of lexical keywords that can indicate important issues in log entries.")

