Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Application services for Event Management operators

As an Event Management operator, you need to understand what application services are.

This is the second lesson in the Event Management tutorial.

Lesson 1
Image omitted: progress-complete2.png
Overview events icon
An overview of events and alerts
Lesson 2
Image omitted: progress-wip.png
Overview BS icon
An overview of application services
Lesson 3
Image omitted: progress-not-started.png
Operator icon
Event Management operator workspaces
Lesson 4
Image omitted: progress-not-started.png
What operators do icon
What operators do

An application service is a collection of components, such as network devices, computers, and applications that offer a service to your organization. The services can be something like an email system or a website that tracks orders or requests in a database. Your administrator should have already specified the application services in your ServiceNow instance.

Each component that makes up an application service is referred to as a configuration item or CI. This service map provides a visual representation of an application service:

Image omitted: operator-business-service.png
Service map

In this example, you can see a Web Portal application service with these CIs:

  • PS Apache03: An Apache web server that hosts a company website.
  • PS LinuxApp01 and PS LinuxApp02: Two Linux servers that share the workload from the web server.
  • PS ORA01: A database server that both Linux servers need to access.
  • Storage Area Network 001: A mass storage device on which the other CIs depend.

You can see service maps like this on the Service Operations Workspace dashboard. Later in this tutorial, you will learn about the dashboard and what an application service looks like when an alert is associated with a CI.

Types of application services

Event Management classifies application services into the following types:

  • Technical services

    A technical service is a dynamic grouping of CIs based on some common criteria. For example, a technical service could be comprised of all web servers or all Oracle databases for a specific location, like North America.

  • Application services

    An application service can consist of discovered services, manual services, or both. A discovered service is an application service that the Service Mapping application finds (if your organization uses Service Mapping). A manual service is an application service that your administrator configures by selecting and adding each CI and specifying the relationships between CIs.

  • Alert groups

    Alerts that are grouped together, either manually or automatically.

Alert impact

Application services are critical to the operations of your organization. If an issue occurs on one CI, the entire application service can be affected. Part of your role as an operator is to analyze alerts on CIs and see how they impact the application service as a whole, and then take an action to help remediate or solve the underlying issue. Your administrator can configure impact rules that go into calculations for the severity of an alert.

Later, when you learn how to use the Service Operations Workspace dashboard, you will learn how to view an impact tree for an application service so you can understand the relationship between the severity of an alert and the overall application service.

In this example, you can see how a Major alert on an Oracle database (PS ORA01) also causes a major alert on its parent CIs and on the Web portal application service itself.

Image omitted: operator-dashboard-impact-tree.png
Impact tree

Continue the tutorial

Proceed to the next lesson: Event Management operator environment.

Parent Topic:Event Management Operator Tutorial