Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Components installed with Event Management

Activating the Event Management (com.glideapp.itom.snac) plugin adds several roles, scheduled jobs, and tables.

Note: The Application Files table lists the components that are installed with this application. For instructions on how to access this table, see Find components installed with an application.

Parent Topic:Event Management reference

Roles installed with Event Management

Roles used by the Event Management application.

Event Management adds these roles.

Role title \[name\]DescriptionContains roles
Event Management Administrator\[evt\_mgmt\_admin\]

Has read and write access to all Event Management features to configure Event Management.Note: Exercise caution with the evt_mgmt_admin role, as it can be elevated to the admin role. A user with the evt_mgmt_admin role has the ability to add and modify scripts that run on a global scope. Ensure proper access control. With this role, the user can create and/or update the following scripts:

  • Alert correlation rules
  • Alert management rules
  • Maintenance rules
  • Advanced scripts
  • Event field mapping
  • Pre- and post-binding scripts
- evt\_mgmt\_user - template\_editor\_global
Event Management Operator\[evt\_mgmt\_operator\]In addition to the evt\_mgmt\_user permissions, can also activate operations on alerts such as acknowledge, close, open incident, and run remediations.evt\_mgmt\_user
Event Management User\[evt\_mgmt\_user\]Has read access to all Event Management features. Has the itil role to be able to manage incidents that are created from alerts.itil
Event Management Integrator\[evt\_mgmt\_integration\]Has create access to the Event \[em\_event\] and Registered Nodes \[em\_registered\_nodes\] tables to integrate with external event sources. 
Event Management AIOps Manager\[evt\_aiops\_manager\]Responsible for overseeing NOC teams performance and can onboard AI Specialists as part of the agentic workforce features in AIOps.evt\_team\_operator
Event Management Team Operator\[evt\_team\_operator\]Can create and manage their own integrations, set up their own alert automations, and enhance control over alert management for their teams. 

Scheduled jobs installed with Event Management

List of scheduled jobs that are provided with Event Management.

To review the list of scheduled jobs, navigate to System Scheduler > Scheduled Jobs. Event Management adds the following scheduled jobs.

Scheduled jobDescription
Event Management — Connector execution jobCompares current time with time when active connector instances were last run and sets relevant connectors to execute. Runs every 10 seconds.
Event Management — Handle Impact Stuck ServiceReleases stuck services and marks them as requiring rebuilding in the Impact Changes table to rebuild the impact tree. Runs every 2 minutes, 31 seconds.
Event Management — Impact Calculator TriggerTrigger the impact calculation. The Event Management dashboard and impact tree are refreshed using the calculated figures.Runs every 6 seconds.
Event Management — Impact Topology ConsumerConsumes topology changes and marks the related services as ‘require rebuilding’ in the Impact Changes table to rebuild their impact trees.Runs every 19 seconds.
Event Management — Update stuck connectorsRelease connector instances that are stuck. Runs every 2 minutes.
Event Management — Alert Priority QueueCalculate alert priority. Two Alert Priority Queue jobs are active and available and can be run multi-thread. Runs every minute.
Event Management — Auto Close AlertsAlerts that are idle longer than 7 days \(default time period\) are closed. Modify the default using the `evt_mgmt.alert_auto_close_interval` property. Runs every 10 minutes.
Event Management — Calculate Alert Priority GroupingRuns and calculates the priority groups: urgent, high, moderate and low for the alerts according to the highest and lowest priority score in the system.Runs every 30 minutes.
Event Management — Close Flapping AlertsClose flapping alerts. Runs every 5 minutes.
Event Management — Close Threshold AlertsClose threshold alerts. Runs every 2 minutes.
Event Management — Evaluate Scoped Alert Rules Management0Execute alert management rules. Two separate jobs run to ease the load on the system.Runs every 11 seconds.
Event Management — Evaluate Scoped Alert Rules Management1
Event Management — Filter Services for Impact - Queue HandlerProcess changes from em\_impact\_inclusion\_class and em\_impact\_filter\_service.Runs every minute.
Event Management — Impact Tree BuilderHandles all services with changes from the em\_impact\_changes table and rebuilds their impact trees.Runs every 11 seconds.
Event Management — Insert Health MonitorJob to produce the ServiceNow Event Management application services. Runs once every hour.
Event Management — Maintenance CalculatorCalculate the maintenance for CIs. Runs every minute.
Event Management — Node CountCalculate license usage. Runs once every hour.
Event Management — Populate Impacted Services TableScan cmdb\_ci\_service\_auto and copy all services to em\_impacted\_service, along with all related classes to em\_impact\_inclusion\_class.Runs once after upgrade.
Event Management — Process EventsJob that runs and processes each Ready event \(apply event rule, mapping rule, and create or update alert\)Runs every 5 seconds.
Event Management — Process Metric BindingProcess metric binding.Runs every 5 seconds.
Event Management — Process Records in em\_extra\_data\_jsonCreates events for log analytics anomalies.Runs every 13 seconds.
Event Management — Queue Connector ProcessorBi-directional functionality. Processes all pending alerts in the Update Queue and sends them to the MID Server. By default, this dequeue process is performed in batches of 1,000 alerts. Runs every 30 seconds.
Event Management — Recalculate Impact for GroupsBy default, this job is not active. Can be run on demand to correct the impact on service groups.Runs on demand.
Event Management — Recover Stuck EventsHandle all events that are in queued state and switch back to Ready to handle events from the beginning.Runs at system startup.
Event Management — Update Health MonitorUpdate the ServiceNow Event Management application services. Runs once every hour.
Event Management — Update SLA Configuration ResultSynchronizes the CIs that match the SLA configuration filter with the Event Management SLA \[em\_ci\_severity\_task\] table. Runs every 10 minutes.
Event Management — Update SLA SeverityUpdates Event Management SLA \[em\_ci\_severity\_task\] table with the new severity. Runs once every minute.
Event Management — Convert IT ServiceRun this property on demand to convert manual services to application services.Runs every 30 minutes.
Event Management — Collect xmlstatsCollect event processing statistics. Runs once every minute.
Event Management — Impact Calculator for Alert Groups and SLACalculates the effect of alerts on alert group services.
Event Management — Manual Impact Calculator TriggerManually trigger of Impact Calculation on all operational Services.
4x Event Management — Impact Calculator for BS\_0Calculates the impact of alerts on application services, and builds the impact tree on the Event Management dashboard. Four separate jobs run to ease the load on the system.
4x Event Management — Impact Calculator for BS\_1
4x Event Management — Impact Calculator for BS\_2
4x Event Management — Impact Calculator for BS\_3
Event Management — Backfill Alert History tableLocates redundant records in the em\_alert\_history table and cancels them.
Event Management — Backfill Impact Status tableLocates redundant records in the em\_impact\_status table and cancels them.
Event Management — Impact for GroupsCalculates the impact of alerts on service groups.
Event Management — Clean Alert History TableCleans the Alert History (em_alert_history) table by removing records more than 90 days old.You can customize the amount of time after which alerts are removed by configuring evt_mgmt.impact_calculation.cleanup_age_seconds.em_alert_history in the sys_properties.list table.
Event Management — Clean Impact Status TableCleans the Impact Status (em_impact_status) table by removing records more than 90 days old.You can customize the amount of time after which alerts are removed by configuring evt_mgmt.impact_calculation.cleanup_age_seconds.em_impact_status in the sys_properties.list table.

Event Management adds the following scheduled jobs to support alert aggregation and RCA.

NameDescription
Service Analytics Purge Old Observation Data — DailyCleans the staging data.
Service Analytics Prepare RCA Learner Input Data — DailyPrepares RCA input data. Stores and probes MID Server to learn statistical information about alerts.
Service Analytics group alerts using RCA/Alert AggregationApplies RCA and alert aggregation to open alerts and prepares automated alert groups.
Service Analytics Alert Aggregation Learner — DailyLearns information about existing alerts and groups new open alerts.
Service Analytics RCA ConfigurationConfigures root cause analysis.
Service Analytics Check File System Space on Analytics MID — DailyChecks disk usage on the dedicated MID Server, and generates an event if it exceeds the threshold set in the sa_analytics.rca.mid_max_allowed_space property.
Service Analytics Gather Value Report Data — DailyGathers data for the Value Report.
Service Analytics — Update virtual alerts for aggregation groupsUpdate the virtual alerts that were created to represent alert aggregation groups, with any changes to alerts belonging to that group. Runs every minute.
Service Analytics Attribute Populator for Historical AlertsPopulate attributes used in feature identifier for historical alert data using event rules. Runs on demand.
Event Management - Analytics Alert SyncerGathers alert data that is used by grouping job.

Domain separation properties for Event Management connectors

Properties provide the metadata to identify the domain.

You can change the values if you want to use any other table or fields for domain identification but make sure that the table is domain separated.

Note: When personalizing domain separation for event management connectors, all the properties can be overridden at the connector level as well.

There are three caches maintained for personalizing domain separation (main, user_access, missing_domain). You can create a few system properties to control them.

PropertyDescription
PropertyDescription
evt\_mgmt. connector\_domain\_info\_table\_name

The table where you store domain information for personalizing domain separation.

  • Type: string
  • Default value: core_company
evt\_mgmt. connector\_domain\_info\_column\_nameThe field name in the table to identify the provided domain for personalizing domain separation.- Type: string - Default value: name
evt\_mgmt. connector\_domain\_id\_column\_nameThe field to get domain ID from for personalizing domain separation.- Type: string - Default value: sys_domain
evt\_mgmt. connector\_domain\_path\_column\_nameThe field to get the domain path from for personalizing domain separation.- Type: string - Default value: sys_domain_path
evt\_mgmt.connector\_custom\_domain\_sep\_cache\_expire\_in\_secondsFor personalizing domain separation, if you don’t want your main cache to expire every week.
evt\_mgmt.connector\_custom\_domain\_sep\_user\_access\_on\_domain\_cache\_sizeFor personalizing domain separation, if you want to increase the size of the user access cache.
evt\_mgmt.connector\_custom\_domain\_sep\_missing\_domain\_cache\_expire\_in\_secondsFor personalizing domain separation, if you want to increase the expire time for cache storing information regarding the missing domain.
evt\_mgmt.connector\_custom\_domain\_sep\_cache\_sizeFor personalizing domain separation, if you need more main cache size for storing domain information.

Tables installed with Event Management

Tables that are provided when Event Management is activated.

Event Management adds these tables.

TableDescription
Alert \[em\_alert\]Alerts that Event Management manage.
Alert Correlation Rule \[em\_alert\_correlation\_rule\]Rules specifying primary and secondary correlated alerts.
Alert Aggregation Group Alerts\[em\_agg\_group\_alert\]Stores alerts associated with aggregated alert groups.
Alert Aggregation Group\[em\_agg\_group\]Relationships between aggregated groups and primary alerts.
Alerts History\[em\_alert\_history\]History of alerts. Used for impact calculation.
Alert Rule \[em\_alert\_rule\]Mappings of alert fields to the Incident \[incident\] table.
Alert Template\[em\_alert\_template\]Alert templates. This table extends the Template \[sys\_template\] table.
Event Management SLA \[em\_ci\_severity\_task\]Event Management SLA tasks for CIs and services.
Connector Definition \[em\_connector\_definition\]Settings for gathering events from external event sources.
Connector Instance \[em\_connector\_instance\]Connection details for external event sources.
MID Server to Connector Instance\[em\_connector\_instance\_to\_mid\]Mappings of MID Servers to connector instances.
Event Management License Usage\[em\_unique\_nodes\]When events are received by ITOM AIOps, an entry is added or updated in this table based on the monitored target specified in the received message. The entry links to its corresponding CMDB CI. If none is found, the entry is assigned Type = Unknown.
Event \[em\_event\]Events received by Event Management.
Event Filter \[em\_event\_filter\]Storage for defined event filters.
Event Match Rule \[em\_match\_rule\]Updated events for alert processing. Used by event rules.
Event Match Field \[em\_match\_field\]Mappings of event fields to alert fields. Simple mapping. Used by Event Rules.
Event Compose Field\[em\_compose\_field\]Mappings of event fields to alert fields. Composite mapping. Used by Event Rules.
Event Mapping Rule \[em\_mapping\_rule\]Updated event fields for alert processing.
Event Processing Statistics \[em\_event\_stats\]Statistics on Event Management performance.
Event Type \[em\_event\_type\]Event types.
Task Template \[em\_incident\_template\]Templates that define how to populate new tasks. For example, how fields of an incident that is being created from an alert, must be populated. This table extends the Template \[sys\_template\] table.
Registered Nodes \[em\_registered\_nodes\]Registered nodes data.
Threshold Rule \[em\_threshold\_rule\]Alert threshold rules.
Binding Device Map \[Em\_binding\_device\_map\]Event binding to network paths and storage paths.
Process to CI Type Mappings \[Em\_binding\_process\_map\]Event binding to specific processes.
CI Remediation \[em\_ci\_remediation\]Remediation rule definitions.
Impact Graph \[em\_impact\_graph\]Impact tree of CIs containing CI hierarchy and impact rules to be used for impact calculation.
Impact Graph History \[em\_impact\_graph\_history\]History of changes in impact tree.
Impact Rule Definitions \[em\_impact\_rule\_definition\]Definition of rules used for impact calculation.
Impact Rule instance \[em\_impact\_rule\]Rules based on impact rule definitions.
Impact Inclusion Classes\[em\_impact\_inclusion\_class\]Specifies the classes to be used for impact calculation.
Impact Filter Services\[em\_impact\_filter\_service\]Specifies services to be included or excluded from impact calculation.
Infrastructure Relations \[em\_impact\_infra\_rel\_def\]Child-parent pairs or CI types. CIs matching these definitions are added to impact trees.
Impact Maintenance CIs \[em\_impact\_maint\_ci\]CIs that are in maintenance and therefore are excluded from impact calculation.
Impact Status \[em\_impact\_status\]Calculated status of CIs and services to be displayed in the dashboard and service maps for dynamic CI groups.
SLA Configuration \[em\_sla\_configuration\]SLA configuration records that identify the CIs that SLAs can run on.
Service Analytics Metric Type Registration\[sa\_metric\_registration\]Source registration details for processing raw data.
Health monitor scripts\[em\_monitor\_scripts\]These scripts determine how to monitor or check, for example, when using the Connectors Monitor script. You can create customized script to monitor a device or an entity. The scripts provided with the base instance are:- Check delay in event processing - Connectors Monitor - Get Event Processing state - MID Server Threshold Alerts
Monitoring configuration\[em\_monitor\_conf\]

Use this table to configure what to monitor according to the scripts that are listed.Configure how often to run each script. If a script has a threshold, it determines what alert severity to display. Threshold values are in units of minutes and specify the delay time. Navigate to Event Management > Settings > Self-Health configuration to see the list of Monitoring Configurations or to create a new one. Use this script to test Data Center Monitoring.

The scripts provided with the base instance are:- Connector's idle state monitoring-monitor to verify whether any of the connectors was in idle state that surpassed the threshold [in minutes] that was configured. - Connectors Status- monitor to track the active status of the connectors. - Delay in event processing-monitor to track the duration [in minutes] of events that remained in 'ready' state and were not processed. - Event Processing job-monitors the state of the event processing jobs. - MID Server Threshold Alert-monitors MID Server health.

Monitoring Event Management Jobs\[em\_monitor\_jobs\_state\]

Monitor Event Management jobs by adding the relevant jobs to the table. Note: The following jobs are not monitored by this table:

  • Event Management - Process Events
  • Event Management - Impact Tree Builder
  • Event Management - Recover Stuck Events
  • Event Processing
Monitoring state\[em\_monitor\_state\]Use this table to set the threshold for each connector. When there is a value above the threshold, an alert is generated.
EM XMLStats Data\[em\_xmlstats\_data\]Self-health statistics and diagnostic details for Metric Intelligence and Event Management, which are used to produce the XMLStats page.

Event Management adds the following tables to support alert aggregation and RCA.

TableDescription
SA RCA Status \[sa\_rca\_status\]Information \(such as IDs\) for the latest messages that were sent to the ECC Queue for a service during RCA.
SA RCA Output\[sa\_rca\_output \]RCA learner output data.
SA RCA Group\[sa\_rca\_group\]Automated alert groups for the RCA query.
SA Analytics Alert Staging\[sa\_analytics\_alert \]Staging table for alerts used for analytics.
SA RCA Input\[sa\_rca\_input\]Input data for the RCA learner.
SA Analytics Status\[sa\_analytics\_status\]Last run information to be used for alert aggregation and RCA.
SA RCA Group Alert\[sa\_rca\_group\_alert \]Alerts associated with automated alert groups.
SA RCA Service Configuration Item Association\[sa\_rca\_svc\_ci\_assoc\]Associations between CIs and services.
SA Alert Aggregation Learned Pattern \[sa\_agg\_pattern\]Learned patterns from alert aggregation.
SA Alert Aggregation Learned Pattern Elements\[sa\_agg\_pattern\_element\]CI/Metric Name pairs associated with learned patterns.
SA Alert Aggregation Query Group Patterns\[sa\_agg\_group\_pattern\]Relationships between groups discovered in alert aggregation queries and patterns found in learning.
SA Alert Aggregation Query -- Staged \(Recent\) Alerts\[sa\_agg\_group\_alert\_staging\]A staging table for alerts that have not yet been associated with any aggregated alert group.
SA Agg Pattern Attribute\[sa\_agg\_pattern\_attribute table\]CI/alert attributes to be used for finding patterns for alert aggregation.
SA Alert Attribute Populator Status \[sa\_alert\_attribute\_populator\_status table\]State and statistics for attribute populator job.
SA Alert Aggregation Learned Pattern Elements Pair wise Mutual Information and Joint Probability \[sa\_agg\_pattern\_element\_pair\]Pairwise probabilities for pattern elements.
EM Agg Group Prediction\[em\_agg\_group\_prediction\]Alert predictions for alert groups.