Review and update a post incident report
Review a post incident report (PIR) using the Post Incident Report tab. A PIR helps you review and understand the cause of the major incident and the actions taken by the teams to resolve the incident. This helps prevent the issue in the future.
Before you begin
The major incident must be in the Resolved state. For more information, see Resolve and close a major incident.
Role required:
- For PIR review: sn_incident_read or sn_incident_write
- For PIR update, generate and download: major_incident_manager, incident_write (added as co-contributors) or admin
About this task
Reviewing the post incident report (PIR) also provides an opportunity to evaluate the incident response process and identify areas for improvement. The PIR can be reviewed and updated during the review process before it's shared with stakeholders.
After you resolve a major incident, you must publish the PIR for the major incident and share it with the stakeholders within a specified time duration as defined in the SLA. You can configure the SLA by specifying the value in hours in the PIR publish hours (sn_sow_inc.pir.publish.hours) system property.
Tip: For guidelines on customizing the Post Incident Report layout and content, search the ServiceNow Community for customize post incident review report.
The following events are captured in the timeline of the PIR:
- Incident created
- Incident proposed as major incident
- Incident accepted as major incident
- Incident resolved
- Incident closed
- Custom events
- Incident task created
- Incident task closed
Procedure
Open a major incident record that is in the Resolved state.
Select the Post incident report tab.
On the Incident Response Timing section, review the time duration for the following fields.
| Field | Description |
|---|---|
| Time to identify | Duration of time taken to identify an incident as major incident.The Time to identify field is displayed based on this calculation: or |
| Time to response | Duration of time taken to respond to the proposed major incident.The Time to response field is displayed based on this calculation: |
| Time to resolve | Duration of time taken to resolve the major incident.The Time to resolve field is displayed based on this calculation: |
On the Contributors section, add users to help with creating and publishing the PIR.
- Select the Edit Co-contributors (
Edit\) icon to add users as contributors.
2. In the **Co-contributors** field, enter users or user groups.
3. Select the **Save Co-contributors** \(
Save\) icon to save the changes.
On the Incident summary section, review the incident summary information and edit as needed.
Note:
By default, this section retrieves the incident summary information from the Overview tab. You can modify the values.
- Select the Edit report (
Edit\) icon to edit the incident summary field of this section.
2. Edit the following information.
- Summary
- Impact
- Resolution
3. Select the **Save report** \(
Save\) icon to save the changes.
On the Timeline section, review the incident events timeline and edit as needed.
- Select the Edit Timeline (
Edit\) icon to edit the event timeline.
2. Select the **Add event** option, enter the following information, and then select **Add** to add a new event to the timeline.
|Field|Description|
|-----|-----------|
|Select date and time of the event|Date and time of the event.|
|Enter short description of the event|Brief description of the event.|
3. Edit the event timeline with the following setting options.
| Options | Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hide | Select the Hide ( Image omitted: mim-hide-icon.png ShowHide) icon to hide an event from the timeline.</td></tr><tr><td> | Select the Show ( Image omitted: mim-show-icon.png EditShow) icon to show a hidden event on the timeline.</td></tr><tr><td> | Select the Edit ( Image omitted: mim-edit-icon.png DeleteEdit) icon to edit the description or the date and time of an event. This option is available only for the events added using the <strong>Add event</strong> option.</td></tr><tr><td> | Select the Delete ( Image omitted: mim-delete-icon.png Order of eventsDelete) icon to delete an event from the event timeline. This option is available only for the events added using the <strong>Add event</strong> option.</td></tr><tr><td> | Option to set the chronological order of events. Possible options: - Ascending – The event that occurred first is placed at the top, and the event that occurred last is placed at the bottom. - Descending – The event that occurred last is placed at the top, and the event that occurred first is placed at the bottom. | |||||||||
| Event Grouping | Option to enable the grouping of the events that occur within a specified time duration. | |||||||||||||
| Group events with--of each other | Time duration that groups events if the events occur within this value. | |||||||||||||
| Visibility settings | ||||||||||||||
| Show hidden events in edit view | Option to show the events that are hidden when the Edit Timeline ( Image omitted: mim-edit-icon.png Show manually events in edit viewEdit) icon is selected.</td></tr><tr><td> | Option to show the events that are added manually when the Edit Timeline ( Image omitted: mim-edit-icon.png Show time line events in edit viewEdit) icon is selected.</td></tr><tr><td> | Option to show the timeline events when the Edit Timeline ( Image omitted: mim-edit-icon.png Reset settingsEdit) icon is selected.</td></tr><tr><td> | Select the Reset settings ( Image omitted: mim-refresh-icon.png Reset settings) icon to reset the settings back to the default settings.</td></tr></tbody> Image omitted: mim-save-icon.png Save\) icon to save the changes.
ResultThe post incident report is downloaded to your system in PDF format. You can send the PDF file to the required stakeholders. Parent Topic:Managing a major incident record | ||||||||||