---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add a log correlator to find related alerts

# Add a log correlator to identify relationships between alerts in log data {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Detect related alerts in log data by adding log correlators. The base system includes several log correlators and you can define custom log
correlators.

## Vorbereitungen

Role required: evt_mgmt_operator or evt_mgmt_admin

## Warum und wann dieser Vorgang ausgeführt wird

For information about the types and functions of log correlators, see [Identifying related alerts in log data by using log correlators](https://servicenow-prod.fluidtopics.net/NQ1d6E9fJlxpioxlkY7pHg "Log correlators are keys or values in log data that detect correlations between alerts to help you determine whether an alert is part of a larger issue. For example, a log correlator could detect when the interface ID of a particular network device occurs simultaneously in multiple warnings across different service instances.").

## Prozedur

1. Use one of the following methods to add a log correlator.

   | Option | Procedure |
   | Add a log correlator for a specific log source | 1. Navigate to Health Log AnalyticsLog Anomaly DetectionLog Correlators. The list of existing log correlators opens. 2. Click the name of a log correlator. The names appear in the Correlation indicator column. 3. Click New. {#hla-op-correlator-define__ol_czd_lfs_lnb} |
   | Add a log correlator that applies either to all log sources or to only those log sources that become active after you define this log correlator | 1. Navigate to Health Log AnalyticsData InputLog Sources. 2. Click the name of the log source. The Log correlators related list displays the list of existing log correlators that analyze log data from the selected log source. 3. On the Log correlators tab, click New. {#hla-op-correlator-define__ol_rvq_y2s_lnb} |
   |-|-|

   {#hla-op-correlator-define__choicetable_aks_4jj_dpb}
2. Fill in the Log correlator form.  
   For a description of the fields, see [Log correlators form fields](https://servicenow-prod.fluidtopics.net/v0OJBOxmYMHr25EHUXBQAw "This section describes the fields on the Log correlators form."). {#hla-op-correlator-define__step-click-new-fill-form}
{#hla-op-correlator-define__step-click-new-fill-form}
3. Select Active and then click Submit.
{#hla-op-correlator-define__steps_ccc_gkb_bnb}

