---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create an alert query

# Create an alert query {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

An alert query is a set of alerts that meet specific criteria for a particular service.

## Before you begin

Navigate to Event ManagementAdministrationEvent Management Properties and ensure that the Enable alert query support (evt_mgmt.impact_calulation.alert_group_support) property is set to Yes.

Role required:
evt_mgmt_admin or evt_mgmt_operator

## About this task

The main motivation to use alert queries is a modeling solution based on data contained in the alert itself, as an alternative to using either discovered, application, or technical services.

Create an alert query to combine
similar alerts that meet the specific criteria.

You can learn about Event Management basics, including alert queries, from this video:

## Procedure

1. Navigate to Event ManagementServicesAlert Queries.
2. Select New.
3. On the Alert Query form, fill in the fields.  
   For a description of the field values, see [Alert Query form](https://servicenow-prod.fluidtopics.net/eKWJtvv7xGaVtCWkdcrw~A "You can combine similar alerts that meet specific criteria for a particular service by creating an alert query.")  
   Note:  
   In the Filter field:
   * When defining an alert query filter, include only fields that appear in the Alert Histories \[em_alert_history\] table. Impact calculation is based on Alert History data and fields such as Overall Event Count, Priority, and Priority group are not copied to the Alert Histories \[em_alert_history\] table.
   * Do not specify a dynamic time condition. For example, in the filter, do not specify <kbd class="ph userinput">Created</kbd> condition of <kbd class="ph userinput">Last 45 minutes</kbd> because impact calculation is triggered by a change of alert or alert query. However, for the dynamic time condition, none of these conditions have changed.
   * Some filters may slow down impact calculation. To solve this problem, adjust your alert query by adding an appropriate index, as described in [Index suggestions for slow queries](https://www.servicenow.com/docs/access?context=index-suggestions&version=yokohama&pubname=yokohama-platform-administration&ft:locale=en-US).
   {#t_EMCreateAlertGroup__ul_xkb_kg2_l1c}
4. Select Update.
**Related tasks**   

* [Create alert group manually](https://servicenow-prod.fluidtopics.net/XePf~1wocrzckKRb2Ij~jQ "Manually create an alert group to organize and manage related alerts when not using scheduled jobs. This provides flexibility to group alerts on-demand for effective resolution.")

*[\>]: and then


