---
sourceDocument: Australia IT Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-service-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Service Management

ft:clusterId :

    - itsm

bundleId :

    - itsm

workflow :

    - Technology


---

# Create an incident

# Create an incident {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 Minuten Lesedauer

Create an incident record to document a deviation from an expected standard of operation.

## Vorbereitungen

Role required: itil, sn_incident_write, or admin

## Warum und wann dieser Vorgang ausgeführt wird

This procedure describes how an ITIL agent completes the Incident form. Incidents are also logged when a user fills out a record producer in the service catalog, or sends an email to the instance.

## Prozedur

1. Navigate to AllIncidentCreate New.  
   You can also click New from the Incident list view.  
   Hinweis:  
   If the UI16 module link redirection feature is enabled in Service Operations Workspace (SOW) and the UI16 module supports the redirect configuration, navigating through UI16 paths automatically redirects you to the equivalent list or record pages in SOW instead of displaying the UI16 forms or lists. For more information, see [Redirect UI16 module links to Service Operations Workspace](https://servicenow-prod.fluidtopics.net/HGF9BPoMvW0Tg5HI2nuUcw "Redirect classic UI16 module navigation links to the equivalent Service Operations Workspace (SOW) experience.").
2. **Wahlweise:** [Use a template](https://servicenow-prod.fluidtopics.net/daDFMnigG_6TZc05ZI8Pkw "Apply a template to a new incident record if the pre-populated information in the template is applicable to the incident record. It saves your time and effort to enter values in the incident record fields individually."), if one exists for the type of incident that you are logging.  
   If the organization uses form templates, then you can apply a template to pre-populate some of the fields for specific types of incidents.
3. On the form, fill in the fields.  
   Your organization has configured the Incident form to adhere to its incident management process. Enter information in the form field is based on the process. The following table describes typical Incident form fields.  
   {#create-an-incident__table_wjm_hsv_vy__entry__2}

   | Field | Description |
   |:-|:-|
   | Number | Unique system-generated incident number. |
   | Caller | User who contacted you with an issue. |
   | Category and Subcategory | Type of issue. After selecting the category, select the subcategory, if applicable. |
   | Service | Affected business service, if applicable. Hinweis: If you select a business service as the configuration item and if that business service is also listed as the configuration item in any other active task, then the active tasks icon (![Other active tasks]()) appears. Click the icon to view the list of all the other active tasks that are affecting the business service. You can view the BSM map (dependency view) of the selected business service by clicking the dependency icon (![Open dependency view]()). |
   | Service Offering | Service offering consists of one or more service commitments that uniquely define the level of service in terms of availability, scope, pricing, and packaging options. This field enables you to receive different features and their levels of performance for a given service. |
   | Configuration item | Affected CI, if applicable. After a CI is selected, you can click the open Dependency views icon (![Open dependency view]()) next to the field to see how the CI maps into the infrastructure. The dependency view shows you what is impacted and whether other CIs or services are experiencing issues. To capture information on the affected CIs, refer to [Capture information on affected configuration items in an incident](https://servicenow-prod.fluidtopics.net/3GUzUkUIVQkGf06ZSizUsw "Capture information on affected configuration items (CIs), with type as asset, in an incident to keep a record of the updated, repaired, swapped, or retired configuration items."). When adding configuration items to the Configuration item field of an incident form, the search result containing a list of configuration items (CI) is displayed and sorted based on the CI names in alphabetical order. |
   | Channel | Communication method that is used by the user to create the incident. Following are the available options: * Chat * Email * Phone * Monitoring * Self-service * Virtual agent * Walk-in {#create-an-incident__ul_stk_tpr_qtb} |
   | Origin | Source of the incident. For example, if an incident is created from alert, this field contains the value Alert. This is a auto-populated field and you cannot fill the value manually. |
   | State | State of the incident. The state moves and tracks incidents through several stages of resolution. Tipp: Use the State field, rather than the Incident State or Problem State fields, as your primary means of tracking the state of an incident because this state progresses through the entire processing cycle. To learn more, see [Life cycle of an Incident](https://servicenow-prod.fluidtopics.net/lqUWqWwgRrnEDD_ssPLj9g "Incident Management is responsible for managing the life cycle of incidents, from creation to closure."). |
   | Impact | Impact is a measure of the effect of an incident, problem, or change on business processes. |
   | Urgency | Urgency is a measure of how long the resolution can be delayed until an incident, problem, or change has a significant business impact. |
   | Priority | Priority is based on impact and urgency, and it identifies how quickly the service desk should address the task. |
   | Assignment group | Group who will work on the incident. The business rule Populate Assignment Group based on CI/SO populates the Assignment group field based on the support group available for the configuration item (CI) or the Service offering consecutively. Hinweis: The business rule is triggered when an incident is created or updated, and when the Assignment group and the Assigned to fields are empty. If you want to override the default value, then you need to create new properties and provide the field in the property value that must be used to populate the Assignment group field. Create the properties in the following order of preference: * com.snc.incident.ci_assignment_group.field_name: Identifies which CI field populates the Assignment group field. * com.snc.incident.service_offering_assignment_group.field_name: Identifies which service offering field populates the Assignment group field. {#create-an-incident__ul_lmp_tp2_s4b} Hinweis: * The sys_user_group read ACL calls the SNCRoleUtil function. The function verifies whether the group that is reviewed contains either the admin role or security_admin role. The function enables the user to view the group only if the user has the same role. As a result, a user with the itil role cannot assign an incident to a group that has the admin role or security_admin role, nor to any group whose parent has those roles. * Other than using the read ACLs, you can also restrict incidents with specific assignment group(s) for visibility only to the group members using before-query business rule. For details, see [How to restrict a specific group incidents to only its group members \[KB0790987\]](https://support.servicenow.com/nav_to.do?uri=/kb?id=kb_article_view&sysparm_article=KB0790987) article in the Now Support Knowledge Base. You must log in to view the article. {#create-an-incident__ul_a1p_yls_vvb} |
   | Assigned to | User who works on this incident. If the Assignment group changes, the Assigned to field is cleared. |
   | Short description | Brief description of the incident. |
   | Description | Detailed explanation on the incident. |
   | Attachments | Attachments related to the incident that helps in incident resolution such as screenshots or pdfs. Select the Attachment (![Attachment icon]()) to add and manage the attachments. |
   | Notes ||
   | Watch list | Users who receive notifications about this incident when comments are added. Click the add me icon (![Add me icon]()) to add yourself to the watch list. |
   | Work notes list | Users who receive notifications about this incident when work notes are added. Click the add me icon (![Add me icon]()) to add yourself to the work notes list. Hinweis: The administrator must create an email notification for the work notes list. |
   | Additional comments | More information about the issue as needed. All users who can view incidents see additional comments. |
   | Work notes | Information about how to resolve the incident, or steps taken to resolve it, if applicable. |
   | Actions taken | A journal field where you can enter details of the actions taken for a major incident. This field is for only internal users. Hinweis: This field is only visible when you activate the Major Incident Management plugin (com.snc.incident.mim). |
   | Related Records ||
   | Parent Incident | Unique number of the parent incident for this incident record. |
   | Problem | Unique number of any related problem record that is related to the incident. |
   | Change Request | Unique number of any related change request that is related to the incident. |
   | Caused by Change | Unique number of the change request that resulted in the creation of the incident. |
   [Tabelle : 1. Incident form]

   {#create-an-incident__table_wjm_hsv_vy}  
   Hinweis:  
   The Caller and Company fields are optional for the following situations:
   * An incident is created from an alert.
   * An incident is created from a change request. In such case, the change request number is populated in the Caused by Change field.
   {#create-an-incident__ul_zyn_3jw_fsb}
4. Click Submit.
{#create-an-incident__steps_vf2_tzt_sbc}

## Ergebnisse

The incident record is created.

## Nächste Maßnahme

You can perform various actions and use the features in the incident record form to track and resolve the incident. For more information, see [Working with incident record form](https://servicenow-prod.fluidtopics.net/aJEguup4obhVhGmkwyArmg "Once an incident is created, you can use the incident record form to perform various actions to track, process and resolve the incident.").
**Zugehörige Konzepte**   

* [Managing major incidents](https://servicenow-prod.fluidtopics.net/KMrkR8AeN6sxkrRQ~_Qe3w "A major incident (MI) is an incident that results in significant disruption to the business. A major incident demands a response beyond the routine incident management process. Major incidents have a separate procedure with shorter timescales and higher priority, so that there is a faster resolution process for incidents with high business impact.")  
**Zugehörige Tasks**   

* [Create a record from incident](https://servicenow-prod.fluidtopics.net/mFYCN0eP9FYqJxy2U~wtNg "Create a problem, change, or request record from an incident.")

