---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# What Event Management operators do

# What Event Management operators do {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As an Event Management operator, your typical workflow involves three
phases: analyzing an alert and its effect on application services, taking some type of action,
and making sure the alert is finally closed.
This is the last lesson in the Event Management tutorial. In this lesson, you will
run through the three phases of a typical operator day-to-day workflow.  

|-|-|-|
| Lesson 1 | ![Overview icon]() | [An overview of events and alerts](https://servicenow-prod.fluidtopics.net/9EuljE91z_xddMbnCHelgg "As an Event Management operator, you need to understand how an alert is generated from an event, what to look for in an alert, and how alerts can be grouped together.") |
| Lesson 2 | ![Overview of BS icon]() | [An overview of application services](https://servicenow-prod.fluidtopics.net/~a0KcRlk6h25yMB4DOxYOQ "As an Event Management operator, you need to understand what application services are.") |
| Lesson 3 | ![Operators icon]() | [Event Management Service Operations Workspace](https://servicenow-prod.fluidtopics.net/xdBUDZ55_nNukbuOOxD_KA "As an Event Management operator, your primary work environment is the Service Operations Workspace dashboard.") |
| Lesson 4 | ![Operators do icon]() | What operators do |
[ ]

{#operator-process__table_or3_vg3_3db} Your organization will have specific policies and procedures that may differ from the
phases outlined in this topic. In addition, your administrator might have customized the
Event Management application so that some of these phases are automated and do not actually
require any action on your part.

For the purposes of this tutorial, we will walk you through each phase and allow you to
perform the tasks manually.  

|-|-|-|
| Phase 1 | Analyze and acknowledge an alert | In this phase, you will find an alert to work on, analyze the details, and acknowledge it so that other operators know it is a legitimate alert. |
| Phase 2 | Triage an alert | In this phase, you take an action to help remediate the issue that caused the alert. The most common action to take is to create an incident and assign it to someone who can solve the underlying issue. |
| Phase 3 | Close an alert | In this phase, you will verify that the alert is resolved, and then close the alert. |
[ ]

{#operator-process__table_kj3_nzw_hdb}

## Start here {#operator-process__section_m4y_ccx_hdb}

Start out by learning how to [Analyze and acknowledge an alert](https://servicenow-prod.fluidtopics.net/PrSgA8TjNiAKggRLCw_gNg "As an Event Management operator, the first thing you should do is access alerts and then find the ones you want to focus on. You can open the Alert form to analyze the details, and then acknowledge it to let other operators know that the issue causing the alert should be addressed in some way.").
* **[Operator phase 1: Analyze and acknowledge an alert](https://servicenow-prod.fluidtopics.net/PrSgA8TjNiAKggRLCw_gNg)**   
  As an Event Management operator, the first thing you should do is access alerts and then find the ones you want to focus on. You can open the Alert form to analyze the details, and then acknowledge it to let other operators know that the issue causing the alert should be addressed in some way.
* **[Operator phase 2: Triage an alert](https://servicenow-prod.fluidtopics.net/KFr9vT5_oAy5Xg2xn4M2Pw)**   
  After you analyze and acknowledge an alert, you must triage it. The triage phase involves verifying alert correlation and taking an action to help resolve the issue that caused the alert. This topic covers the most common triage task: creating an incident from an alert.
* **[Operator phase 3: Close an alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA)**   
  After you take action on an alert, you can verify several items on the alert and then close it.

