---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# View alerts in the flapping state

# View alerts in the flapping state {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can view alerts that are specifically in the flapping state.

## Before you begin

Before starting this procedure, ask your administrator to configure alert flapping properties.

Role required: evt_mgmt_admin, evt_mgmt_operator, or
evt_mgmt_user

## About this task

Flapping occurs when the event source continues to generate events even after its associated alert has been closed. Flapping causes the resource's status to repeatedly fluctuate between the OK severity and a severity requiring attention, for example, Critical.

The frequency of events from an identical source within a given time interval
determines whether an alert is in a flapping state or a new issue has occurred.
Based on the evt_mgmt.flap_frequency and
evt_mgmt.flap_interval property
values:

* If the same issue is recurring, Event Management associates the new event with the existing alert and the state of the alert is set to Flapping.
* If the issue occurs after the time interval expires, Event Management creates an alert.

For example, you can respond to an alert by rebooting a problematic server. After no
events are generated for several minutes, it is assumed that the issue is fixed and
the alert is closed. If the reboot did not actually fix the issue, this server can
generate more events later. Then additional alerts are generated for the same
issue.

## Procedure

1. Navigate to AllEvent ManagementAll Alerts.
2. Click the number of an alert that is in the Flapping state.
3. On the alert, click the Flapping tab.  
   {#t_EMViewAlertFlapping__entry__2}

   | Field | Description |
   |-|-|
   | Flapping tab ||
   | Flap count | The number of times the alert has flapped---that is, has fluctuated between a closed and a non-closed state---within the flap interval since the start time in the Flap start window. |
   | Flap start window | The initial start time to measure the flapping occurrences. |
   | Flap last update time | The last time flapping occurred. This time is the platform processing time, not the source system time. |
   | Flap last state | The state before the alert entered the flapping state. |
   [Table 1. Flapping tab on Alert form]

4. If the Parent field is empty, address this alert as a new issue.
**Related tasks**   

* [Configure alert flapping](https://servicenow-prod.fluidtopics.net/e8HTvciLULJkL2tY96KBYA "Set flapping properties to determine when an alert enters and exits the flapping state. Flapping can indicate configuration problems (that is, thresholds set too low), troublesome services, or real network problems.")

*[\>]: and then


