---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create or edit an event rule

# Create or edit an event rule {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

You can create event rules to generate alerts for tracking and remediation. Use team-based integrations in event rules to make sure that connector ownership and execution of rules give precedence to general rules. Teams can
maintain consistency and hierarchy while offering flexibility and customization options.

## Before you begin

Role required: evt_mgmt_admin

## About this task

View the list of available event rules on the Event Rules page to determine whether you want to create or edit an event rule.  
You can create rules that:

* Transform information in events to populate specified alert field values and compose alert fields from various values.
* Configure threshold rules that create or close alerts only when the incoming matching events exceed the specified threshold.
* Bind alerts to CIs using CI identifiers.
{#create-or-edit-event-rule__ul_ztz_kqq_2x}  
Options to create the rule are:

* Create an event rule and assign event fields for alert generation.
* Create a rule from an existing event or group of events that don't have a rule. In this case, the event fields are copied to the Event Match Fields section of the rule.
* Edit an existing event rule.
* For Team-based integrations, select an assignment group.
* Run multiple sequential rules defined for the same event by selecting the Apply additional matching rules check box. The event rules run in ascending order as defined in the
  Order field. Event rules applied to assignment groups only run after the global rules have run.

{#create-or-edit-event-rule__ul_xmj_k5p_f5}

You can refresh an existing event rule with new event data. For more information see, [Refresh event rules](https://servicenow-prod.fluidtopics.net/AImwydPDeal3lr9CPo_o2A "Manually update event rules to reflect current event information because once an event rule is created, the Event Additional info and Event Raw info fields are not automatically updated.").  
Note:  
* Event rules that aren't configured to perform any action are skipped. Therefore, if the rule isn't configured as ignore, threshold, or binding, it's important to specify either the match or the composed fields.
* Make sure that you don't change the Classification field value in event \[em_event\] tables, either manually, by script, or by event rule.
{#create-or-edit-event-rule__ul_q4f_lsl_tlb}

## Procedure

1. Navigate to AllEvent ManagementRulesEvent Rules and take one of the following actions.

   | Option | Description |
   | Create an event rule from an existing event | 1. Select the link for unassociated events or grouped events that aren't mapped to the rules. 2. Select the event that you want to use for creating the rule. The event fields are copied to the Event Field Rules section of the rule. {#create-or-edit-event-rule__ol_cv3_h2v_ty} |
   | Edit an existing event rule | In the event rule list, select the required event rule to be modified. The event rule opens in the event rule designer where you can modify the values of the fields. Select Save and Upgrade ![Event Management save]() to modify the rule when the following banner message appears and you want to convert the event rule. Rule cannot be viewed in the event rule designer. To modify the rule click 'Save and Upgrade'. |
   | Create an event rule | Select New. |
   |-|-|

   {#create-or-edit-event-rule__choicetable_u5d_w1m_zt}
2. Ensure that Active ![Active toggle]() is selected.  
   When the rule is deactivated, Event Management finds and applies another event rule. An alert is still created for the event unless Ignore is selected in another applicable rule or when configuring the filter for this event rule.
3. Enter a unique and meaningful name and fill in the form.  
   {#create-or-edit-event-rule__table_zdm_zwc_sy__entry__2}

   | Field | Description |
   |-|-|
   | Source | Category to which this matching rule applies. The mapping rule only applies to events with the same event class value. If this value is empty, apply the rule to all events. |
   | Order | Order in which an event rule is evaluated when multiple rules are defined for the same type of event. Event rules are evaluated in ascending order. |
   | Description | Type additional information that describes the event rule. |
   | Apply additional matching rules | Select to apply additional event matching rules according to the Order field. The last rule with binding settings sets the CI binding. When selected, the Thresholds tab is inactive. |
   | Assignment group | For team-based integrations, select an assignment group. If no assignment group is defined in the event rule, then this event rule is considered as a global rule. When the rules are running -- first the global rules run and then the rules that belong to the assignment group that the event's source instance belongs to. |
   [Table 1. Event Rule Info form]

   {#create-or-edit-event-rule__table_zdm_zwc_sy}
4. **Optional:** Define the event rule using these Event Rule Designer features.

   | Option | Description |
   | Event Filter | Define a filter to restrict to which events the event rule must apply. See [Filter the events that an event rule applies to](https://servicenow-prod.fluidtopics.net/ieu8q5TI7rJv10SQ5gdxgw "Define a filter to restrict to which events the event rule must apply. Configure the filter by providing a set of conditions that each event must match to be either excluded or included from applying to the event rule."). |
   | Transform and compose alert output | Configure the customization of alert content. See [Configure an event rule to customize alert content](https://servicenow-prod.fluidtopics.net/y3wetDYMwXph7QgT~DFEhg "You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert."). |
   | Threshold | Create or close alerts according to the specified threshold. See [Set a threshold to suppress alert generation](https://servicenow-prod.fluidtopics.net/hz5gPG5ZhuIhZeKZaBd7gA "The event threshold is the rate upon which Event Management generates an alert. Receiving multiple events for a device over a short interval may warrant creating an alert, as the condition may be serious. However, receiving events over a longer interval may indicate a less serious situation which would not warrant creating an alert."). |
   | Binding | Configure event rules to automatically bind alerts to CI information from the CMDB. See [Binding alerts to CIs](https://servicenow-prod.fluidtopics.net/yhAevCrJwBxWNoZGxoo2EQ "CI binding or linking is the process of finding and connecting a Configuration Item (CI) from the Configuration Management Database (CMDB) to an alert, using the logic defined in event rules. This helps ensure alerts are tied to the right IT components for better visibility and faster issue resolution."). |
   |-|-|

   {#create-or-edit-event-rule__choicetable_n2q_nks_sy}
5. Select Save, Submit, or Update.
**Related concepts**   

* [Use event input information](https://servicenow-prod.fluidtopics.net/Xf_3GkyF5V1e21XESUXm9A "The Event Input pane that is included in the steps to create an event rule provides a reference to the information that you can use when configuring an event rule.")  
**Related tasks**   

* [Configure an event rule to customize alert content](https://servicenow-prod.fluidtopics.net/y3wetDYMwXph7QgT~DFEhg "You can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand work area of the Transform and Compose Alert Output section of an event rule are the fields that appear in the generated alert.")
* [Refresh event rules](https://servicenow-prod.fluidtopics.net/AImwydPDeal3lr9CPo_o2A "Manually update event rules to reflect current event information because once an event rule is created, the Event Additional info and Event Raw info fields are not automatically updated.")
* [Simulate event processing](https://servicenow-prod.fluidtopics.net/yo53HhUJdrAHbtEkUYfJZA "You can simulate event processing logic on events and display the resulting alert to better understand which rules are executed on a given event and how the event fields change after the rule is executed.")
* [Filter the events that an event rule applies to](https://servicenow-prod.fluidtopics.net/ieu8q5TI7rJv10SQ5gdxgw "Define a filter to restrict to which events the event rule must apply. Configure the filter by providing a set of conditions that each event must match to be either excluded or included from applying to the event rule.")  
**Related topics**   

* [Pattern matching](https://www.servicenow.com/docs/access?context=c_PatternMatching&version=yokohama&pubname=yokohama-platform-administration&ft:locale=en-US)

*[\>]: and then


