---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Add a log correlator to identify related alerts

# Add a log correlator to identify related alerts {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Detect related alerts in log data by adding log correlators. The base system includes several log correlators and you can define custom log
correlators.

## Before you begin

Role required: evt_mgmt_operator or evt_mgmt_admin

## About this task

For information about the types and functions of log correlators, see [Log correlators for identifying related alerts](https://servicenow-prod.fluidtopics.net/Zgp6T7g6fBWpxgZrqK4A1g "In Health Log Analytics, log correlators are keys or values in log data that detect correlations between alerts. These correlations help you determine whether an alert is part of a larger issue.").

## Procedure

1. Use one of the following methods to add a log correlator.

   | Option | Procedure |
   | Add a log correlator for a specific log source | 1. Navigate to Health Log AnalyticsLog Anomaly DetectionLog Correlators. The list of existing log correlators opens. 2. Click the name of a log correlator. The names appear in the Correlation indicator column. 3. Click New. {#hla-op-correlator-define__ol_czd_lfs_lnb} |
   | Add a log correlator that applies either to all log sources or to only those log sources that become active after you define this log correlator | 1. Navigate to Health Log AnalyticsData InputLog Sources. 2. Click the name of the log source. The Log correlators related list displays the list of existing log correlators that analyze log data from the selected log source. 3. On the Log correlators tab, click New. {#hla-op-correlator-define__ol_rvq_y2s_lnb} |
   |-|-|

   {#hla-op-correlator-define__choicetable_aks_4jj_dpb}
2. Fill in the Log correlator form.  
   For a description of the fields, see [Log correlators form fields](https://servicenow-prod.fluidtopics.net/~xHMnwFdXiLStt1Rfl0wMA "This section describes the fields on the Log correlators form."). {#hla-op-correlator-define__step-click-new-fill-form}
{#hla-op-correlator-define__step-click-new-fill-form}
3. Select Active and then click Submit.
{#hla-op-correlator-define__steps_ccc_gkb_bnb}

*[\>]: and then


