---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Work with flapping alerts

# Work with flapping alerts {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If an alert is in the flapping state, you might need to triage the alert
again.

## Before you begin

Note:  
The Operator Workspace interface is available only to customers who have upgraded from a release prior to the Utah release. New customers as of the Utah release can use the Service Operations Workspace for ITOM, which offers an enhanced UI for managing alerts.

Role required: evt_mgmt_operator

## About this task

If an event repeatedly triggers the same alert in a short amount of time, the alert is put into the flapping state, even if an operator closed it previously. The event can also be fluctuating between severity levels, such as Info and Critical. You should triage the alert again, and take action to try to prevent the event from reoccurring.  
Note:  
Your Event Management administrator can configure several settings that determine when to mark an alert as flapping, and other settings that determine what action you can take. This topic covers a generic example.

## Procedure

1. Find alerts in the flapping state:
   1. Navigate to Event ManagementOperators Workspace.
   2. Modify the list of alerts by clicking the filter icon (![Filter icon]()) and specifying criteria to find flapping alerts.  
      Click Advanced view to modify filter settings. For example, you can specify:

      `State` \| `is` \|
      `Flapping`.
2. Click the alert number to open it.
3. On the alert, click the Flapping tab and review the information:  
   {#operator-handle-alerts-flapping__table_uzq_zff_3db__entry__2}

   | Field | Description |
   |-|-|
   | Flap count | The number of times the alert started flapping since the time in the Flap start window field. |
   | Flap start window | The time that flapping started. |
   | Flap last update time | The last time flapping occurred. This time is the instance processing time, not the source system time. |
   | Flap last state | The state of the alert before it entered the flapping state. |
   [ ]

   {#operator-handle-alerts-flapping__table_uzq_zff_3db}
4. Decide which action to take based on how often flapping has occurred.  
   You can do any of the following, depending on what your organization's standard operating procedures are and what your Event Management administrator configured:
   * [Run
     a remediation workflow](https://servicenow-prod.fluidtopics.net/tlgUluoka2IKFXOakGCB~Q "As an Event Management operator, you can also run a workflow on your ServiceNow instance that helps remediate the alert. For example, you might run a workflow that automatically restarts a server on your network, which might resolve an alert about CPU usage.") that might do something like reboot a server or reset a router.
   * [Access a web application](https://servicenow-prod.fluidtopics.net/n4HUjFFrpJ~oeWKgClDLbA "As an Event Management operator, you can also launch a web application from an alert. The web application might be a console for the event monitoring tool that your organization uses, or any external website that provides additional information you might need about the alert."), like the application for your event monitoring software on your network.
   * [Modify an associated incident](https://servicenow-prod.fluidtopics.net/KFr9vT5_oAy5Xg2xn4M2Pw "After you analyze and acknowledge an alert, you must triage it. The triage phase involves verifying alert correlation and taking an action to help resolve the issue that caused the alert. This topic covers the most common triage task: creating an incident from an alert.") or a [KB
     article](https://servicenow-prod.fluidtopics.net/Dced8MJkvxrPWn2g2yyF1A "As an Event Management operator, you can associate a knowledge base (KB) article with the alert to capture additional information about the alert. This might include a procedure that someone has to follow to resolve the underlying issue on your network, or a best practice to prevent the issue from reoccurring.") to include additional information or steps.
   {#operator-handle-alerts-flapping__ul_mhk_wjf_3db}
5. After you are certain that the underlying issue is addressed, [close the
   alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA "After you take action on an alert, you can verify several items on the alert and then close it.").

*[\>]: and then


