---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Analyze log lines around the anomaly

# Analyze log lines around the anomaly to help find the root cause {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

View the log lines around an anomaly to help you identify the root cause of a Log Analytics alert.

## Vorbereitungen

Role required: evt_mgmt_operator or evt_mgmt_admin  
Wichtig:  
From the Vancouver release onward, the Operator Workspace is deprecated and replaced with Service Operations Workspace. For the new procedure, see the corresponding topic in the Service Operations Workspace for ITOM documentation: [Analyze log lines that surround an anomaly in Health Log Analytics](https://servicenow-prod.fluidtopics.net/kf5PzNSn6rBDcmsaA9e8XA "View the log lines around an anomaly to help you identify the root cause of a Log Analytics alert.").

## Prozedur

1. Open a Log Analytics alert.  
   For more information, see [Start remediation of a Log Analytics alert from the Overview tab](https://servicenow-prod.fluidtopics.net/scaZOkYM~Hg1i0I_E_sF6g "Begin the remediation process of a Log Analytics alert from the alert Overview tab. This tab provides information on the alert, the log data associated with the anomalous behavior, CIs associated with the alert, and services impacted by it.").
2. In the Service Operations Workspace, select the Surrounding logs tab and review the information.  
   The tab displays the list of log lines that were generated one minute before and one second after the anomaly occurred. For an explanation of the information on the tab, see [Surrounding logs tab fields](https://servicenow-prod.fluidtopics.net/C~8SJShzJnj4wbEmgVD~0g "This section describes the information displayed on the Surrounding logs tab.").
3. **Wahlweise:** View a different timespan of the log lines using one of the following methods:
   * Update the Time range relative to alert to a predefined time range in the Select range list.
   * Specify a Start time or End time using the time picker.
   {#hla-op-surrounding-logs-view__choices_k4z_1r5_hnb}
4. **Wahlweise:** View the anomalous log data graphically as a function of time by selecting the Log viewer tab.
**Zugehörige Konzepte**   

* [Reviewing the logs that are connected with an alert on the Log Viewer in Health Log Analytics](https://servicenow-prod.fluidtopics.net/~KZgCI02ygNerk6YUa8png "The Log Viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.")
* [Analyzing the logs around an anomaly to help find the alert's root cause](https://servicenow-prod.fluidtopics.net/uW7dSm2MiHpmIH~Sxqr7aw "When Health Log Analytics identifies an anomaly, viewing the logs that surround the anomaly provides clues about the state of faulting systems. This information can help you narrow down the root cause of an alert.")

