---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Overview tab sections for Log Analytics alert groups

# Overview tab sections for Log Analytics alert groups {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Overview tab sections for Log Analytics alert groups

The Overview tab in the Service Operations Workspace offers a comprehensive view of Log Analytics alert groups, enabling you to understand the issues behind alerts and their correlations.
It is designed to help you analyze and manage Log Analytics alerts effectively by providing detailed information about identified issues, correlated alerts, and impacted configuration items and services.
Show full answer Show less  

## Key Features

* **Identified issue card:** Displays the root issue causing the alert, visible on the alert card and title, with alert details shown in a banner.
* **Correlations list:** During initial analysis, alerts are scored based on correlations with other alerts. Correlation criteria include:
  * Time proximity of events
  * Matching metadata values (e.g., same host)
  * Similarity in message text
  * Similar trends in metric values or rates
  The first correlation expands to show individual correlated alerts and their shared log correlator identifier, grouping alerts by common log-line data or metadata such as IP address or user name.
* **Alerts in group card:** Lists all Log Analytics alerts grouped under a specific alert. Selecting an alert allows viewing detailed information. You can also access the full list of alerts in a group via the Related records tab.
* **Impact section:** Provides insight into Configuration Items (CIs) and services affected by the alert, helping you assess the scope and potential impact of issues.

## Key Outcomes

By utilizing the Overview tab for Log Analytics alert groups, you can:

* Quickly identify and understand the main issue triggering alerts.
* Analyze how alerts are correlated based on time, metadata, message similarity, and trends, improving incident grouping and prioritization.
* View all alerts within a group to get a complete picture of related issues.
* Assess the impact on configuration items and services to support effective incident response and resolution.  
The Overview tab in the Service Operations Workspace helps you understand Log Analytics groups.
For a detailed description of Log Analytics groups, see
[Types of Health Log Analytics alerts](https://servicenow-prod.fluidtopics.net/TBh~aeSheIv0nk6SdDEiEg "Health Log Analytics generates several types of alerts.").

## Summary {#hla-op-ovrvw-tab-log-anltcs-alerts-sow__section_ewf_1lw_wtb}

Identified issue

:   This card describes the issue that led to the alert. The identified issue appears
    on the card and in the title for the alert. Information about the alert appears in
    the banner.

    Figure 1. Identified issue

    Select View correlations to view the list of correlations
    that relate the Log Analytics alerts.

Correlations list

:   During initial analysis, alerts are scored. Each correlation in the alert's log data with another alert contributes to the score. The higher the score, the more likely the alert is to be included as a Log Analytics alert in a Log Analytics group.

    The following kinds of data are considered when determining whether alerts are
    correlated:

    * Time: The events all occurred within a configured time interval.
    * Metadata: The alerts have matching values in log-line metadata. For example, all alerts involve the same host.
    * Message text: The message text in the log data is similar or identical between alerts.
    * Trend: The alerts show a similar tendency in values or rates. For example, a particular metric value is increasing in all alerts.

    {#hla-op-ovrvw-tab-log-anltcs-alerts-sow__ul_il5_bms_znb}  
    Figure 2. Correlations  
    1. List of correlations: The first correlation in the list is expanded to show the individual Log Analytics alerts that are correlated and the log correlator that the alerts share.
    2. An individual log correlator: The identifier for a group of correlated Log Analytics alerts. The alerts are grouped by the log-line data or metadata that is common to the alerts (for example, IP address, host name, or user name). The number in the blue square indicates the number of correlated alerts.
    3. Log Analytics alerts that are correlated.
    {#hla-op-ovrvw-tab-log-anltcs-alerts-sow__ol_n3b_gjm_4tb}

Alerts in group

:   For a Log Analytics alert, the Alerts in group card shows the Log Analytics alerts that are grouped under the Log Analytics alert. Select a Log Analytics alert to view its details.

    Figure 3. Alerts in group

    Select View all to the view the list of all Log Analytics alerts in the group and relevant information about them.
    You can also view the Alerts in group list by selecting the Related records tab and then selecting Alerts in group.
    For more information, see [View Log Analytics alerts in a group](https://servicenow-prod.fluidtopics.net/6VKfgwk9S183cfX5BU7Uzg "View the list of all Log Analytics alerts in a Log Analytics group on the Related records tab.")

## Impact {#hla-op-ovrvw-tab-log-anltcs-alerts-sow__section_sfw_1lw_wtb}

Configuration Items
:   This card provides information about the CIs that are impacted by the alert.

Impacted services
:   This card provides information about the services that are impacted by the alert.  
    Figure 4. Impact section
* **[View Log Analytics alerts in a group](https://servicenow-prod.fluidtopics.net/6VKfgwk9S183cfX5BU7Uzg)**   
  View the list of all Log Analytics alerts in a Log Analytics group on the Related records tab.

