---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Analyze log lines that surround an anomaly

# Analyze log lines that surround an anomaly {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

View the log lines around an anomaly to help you identify the root cause of a Log Analytics alert.

## Before you begin

Role required: evt_mgmt_operator or evt_mgmt_admin

## Procedure

1. In the Service Operations Workspace, open a Log Analytics alert.
2. Select the Surrounding logs tab and review the information.  
   The tab displays the list of log lines that were generated one minute before and one second after the Log Analytics alert. For an explanation of the information on the tab, see [Surrounding logs tab fields](https://servicenow-prod.fluidtopics.net/yZ4HAFcTeuHyrFgdIL6o4g "This section describes the information displayed on the Surrounding logs tab.").
3. **Optional:** View a different timespan of the log lines using one of the following methods:
   * Update the time range relative to the alert to a predefined time range in the Select range list.
   * Specify a Start time or End time using the time picker.
   {#hla-op-surrounding-logs-view-sow__choices_k4z_1r5_hnb}
4. **Optional:** View the anomalous log data graphically as a function of time by selecting Log viewer.  
   For more information, see [Reviewing alert logs on the Log viewer](https://servicenow-prod.fluidtopics.net/Hh7qEnJebE7N2HDaFk_Log "The Log viewer tab lets you browse the logs for an alert by timestamp or time range, and visualize anomaly frequency within a specific time period. Customizing the displayed data and adjusting time filters enables you to better understand the framework in which the anomaly occurred, helping you find the root cause faster.").
{#hla-op-surrounding-logs-view-sow__steps_lf2_1rr_stb}

