---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Associate a knowledge base article with an alert

# Associate a knowledge base article with an alert {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As an Event Management operator, you can associate a knowledge base (KB) article with
the alert to capture additional information about the alert. This might include a procedure
that someone has to follow to resolve the underlying issue on your network, or a best
practice to prevent the issue from reoccurring.

## Before you begin

Note:  
The Operator Workspace interface is available only to customers who have upgraded from a release prior to the Utah release. New customers as of the Utah release can use the Service Operations Workspace for ITOM, which offers an enhanced UI for managing alerts.  

|-|-|-|
| Phase 1 | ![Analyze icon]() | [Analyze and acknowledge an alert](https://servicenow-prod.fluidtopics.net/PrSgA8TjNiAKggRLCw_gNg "As an Event Management operator, the first thing you should do is access alerts and then find the ones you want to focus on. You can open the Alert form to analyze the details, and then acknowledge it to let other operators know that the issue causing the alert should be addressed in some way.") |
| Phase 2 | ![Operator icon]() | Triage alerts |
| Phase 3 | ![Operator do icon]() | [Close an alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA "After you take action on an alert, you can verify several items on the alert and then close it.") |
[ ]

{#operator-associate-kb__table_ss3_vg3_3db}

This task assumes that your organization uses the Knowledge Base application in your
ServiceNow instance.

Role required: evt_mgmt_operator

## Procedure

1. From the Service Operations Workspace dashboard, open the alert that you acknowledged in Phase 1: Analyze and acknowledge an alert.
2. On the Alert form, click the lookup icon (![Lookup icon]()) next to the Knowledge article field.
3. Filter the list of existing KB articles by first selecting a field, such as Short Description, and then entering related text into the search text field.  
   You can use the <kbd class="ph userinput">contains</kbd> (\*) operator to search for articles that contain keywords. For example, entering <kbd class="ph userinput">*oracle</kbd> in the short description filters the KB articles that contain the word <kbd class="ph userinput">oracle</kbd> somewhere in the short description.

4. If you cannot find any related KB articles, you can click New, create a new one, and then click Submit.  
   The KB article number appears in the Knowledge article
   field on the Alert form.
5. Click Update on the Alert form to save the information.

## What to do next

There are also other tasks you can take as part of the triage stage:

* [Run a remediation workflow on an alert](https://servicenow-prod.fluidtopics.net/tlgUluoka2IKFXOakGCB~Q "As an Event Management operator, you can also run a workflow on your ServiceNow instance that helps remediate the alert. For example, you might run a workflow that automatically restarts a server on your network, which might resolve an alert about CPU usage.") if your Event Management administrator already set up a workflow in your ServiceNow instance and your policies allow you to trigger it from the alert.
* [Launch a web application from an alert](https://servicenow-prod.fluidtopics.net/n4HUjFFrpJ~oeWKgClDLbA "As an Event Management operator, you can also launch a web application from an alert. The web application might be a console for the event monitoring tool that your organization uses, or any external website that provides additional information you might need about the alert.") to open a website or an event monitoring tool that provides more information about the alert.
* [Put an alert into maintenance](https://servicenow-prod.fluidtopics.net/ETUWWt9uk0~ILFRGPrw43A "As an Event Management operator, you can put an alert into maintenance if the alert does not require any further action, but you still want to keep the alert active. Putting the alert into maintenance hides it from the Service Operations Workspace dashboard so that other operators do not need to access it, but it does not close the alert.") to temporarily hide it from the Service Operations Workspace dashboard if the alert does not require action at this time.
{#operator-associate-kb__ul_ktk_3tj_hdb}

If you do not need to perform any other triage actions, proceed to [Phase 3: Close an
alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA "After you take action on an alert, you can verify several items on the alert and then close it.").

