---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Run a remediation workflow on an alert

# Run a remediation workflow on an alert {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

As an Event Management operator, you can also run a workflow on your ServiceNow instance that helps remediate the alert. For example, you
might run a workflow that automatically restarts a server on your network, which might
resolve an alert about CPU usage.

## Before you begin

Note:  
The Operator Workspace interface is available only to customers who have upgraded from a release prior to the Utah release. New customers as of the Utah release can use the Service Operations Workspace for ITOM, which offers an enhanced UI for managing alerts.  

|-|-|-|
| Phase 1 | ![Analyze alert icon]() | [Analyze and acknowledge an alert](https://servicenow-prod.fluidtopics.net/PrSgA8TjNiAKggRLCw_gNg "As an Event Management operator, the first thing you should do is access alerts and then find the ones you want to focus on. You can open the Alert form to analyze the details, and then acknowledge it to let other operators know that the issue causing the alert should be addressed in some way.") |
| Phase 2 | ![Triage alert icon]() | Triage alerts |
| Phase 3 | ![Close alert icon]() | [Close an alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA "After you take action on an alert, you can verify several items on the alert and then close it.") |
[ ]

{#operator-run-remdiation__table_pw3_vg3_3db}  
Note:  
You can run a remediation workflow if your administrator already set up workflows for you to choose from. You should be familiar with your organization's policies regarding triaging of alerts.

Role required: evt_mgmt_operator

## Procedure

1. From the Service Operations Workspace dashboard, open the alert that you acknowledged in Phase 1: Analyze and acknowledge an alert.
2. On the Alert form, click Quick Response.  
3. In the Quick Response window, click the name of the remediation under Run Remediation.  

## What to do next

There are also other tasks you can take as part of the triage stage:

* [Launch a web application from an alert](https://servicenow-prod.fluidtopics.net/n4HUjFFrpJ~oeWKgClDLbA "As an Event Management operator, you can also launch a web application from an alert. The web application might be a console for the event monitoring tool that your organization uses, or any external website that provides additional information you might need about the alert.") to open a website or an event monitoring tool that provides more information about the alert.
* [Put an alert into maintenance](https://servicenow-prod.fluidtopics.net/ETUWWt9uk0~ILFRGPrw43A "As an Event Management operator, you can put an alert into maintenance if the alert does not require any further action, but you still want to keep the alert active. Putting the alert into maintenance hides it from the Service Operations Workspace dashboard so that other operators do not need to access it, but it does not close the alert.") to temporarily hide it from the Service Operations Workspace dashboard if the alert does not require action at this time.
* [Associate a knowledge base article with an alert](https://servicenow-prod.fluidtopics.net/Dced8MJkvxrPWn2g2yyF1A "As an Event Management operator, you can associate a knowledge base (KB) article with the alert to capture additional information about the alert. This might include a procedure that someone has to follow to resolve the underlying issue on your network, or a best practice to prevent the issue from reoccurring.") if there is existing information about the alert that might help resolve the underlying issue.
{#operator-run-remdiation__ul_ktk_3tj_hdb}

If you do not need to perform any other triage actions, proceed to [Phase 3: Close an
alert](https://servicenow-prod.fluidtopics.net/TXd9TsndwhlTCneB9tCEgA "After you take action on an alert, you can verify several items on the alert and then close it.").

