Shared impacted services alert grouping
Summarize
Summary of Shared impacted services alert grouping
The Shared impacted services alert grouping feature in ServiceNow Event Management automatically consolidates related alerts by the business service they affect. Instead of managing numerous disconnected alerts during incidents, your team receives a single organized view focused on the impacted business service. This approach accelerates the identification of broken services and streamlines response efforts.
Show less
How the Grouping Works
Each alert is linked to a Configuration Item (CI), such as a server or network device. The system traces the CI upward through its application and infrastructure dependencies to identify the top-level Business Service affected, known as the Top Service. All alerts that trace back to the same Top Service are grouped together, regardless of their physical or network distance within the infrastructure. This grouping provides a comprehensive view of the overall impact on critical services, similar to a NOC dashboard that prioritizes service-level issues over individual alerts.
When to Use Shared Impacted Services Grouping
ServiceNow offers two alert grouping methods:
- CMDB-based alert grouping: Best suited for simpler, flatter service topologies where CIs are within four hops of each other. It groups alerts based on direct CI relationships in the CMDB.
- Shared Impacted Services grouping: Ideal for complex or deep service topologies common in large organizations, where business services are supported by long chains of applications and infrastructure components. This method groups all alerts linked to the same Top Service, regardless of how many hops away the CIs are.
Use Shared Impacted Services grouping when your service trees have multiple topology levels to ensure no related alert is missed in the group, providing a complete picture of service impact in complex environments.
The Shared impacted services alert grouping automatically gathers related alerts under the business service they affect. When your IT environment generates multiple alerts at once, instead of facing a flood of disconnected notifications, your team gets one focused, organized view — making it faster to spot what is broken and act.
The Shared impacted services alert grouping feature solves this by automatically gathering related alerts into one place. It looks at each alert, figures out which business service is ultimately affected — for example, Online Payments or HR Portal — and groups all alerts that point to the same service together.
For details on creating a group automation, see Create Group automation.