How can we help?

Configure ServiceNow ticketing for all in-scope devices with Alerts 2.0

Follow

Auvik creates ServiceNow incidents when an associated alert changes state, such as when a device transitions from Up to Down. The devices that can generate ServiceNow incidents are determined by the scope of the Auvik alert definitions.

There is no separate setting to monitor every device in ServiceNow. To create incidents for all applicable devices, configure the Auvik alert definitions to include the required sites and devices, then associate the ServiceNow notification channel with those alerts.

Prerequisites

Before configuring the integration, confirm that:

  • A ServiceNow instance is available.
  • The Auvik ServiceNow integration has been installed and configured.
  • The ServiceNow integration user has the permissions required to create and update incidents.
  • The Auvik ServiceNow integration has passed its connection test.
  • Auvik alert definitions exist for the conditions that should create ServiceNow incidents.
  • The required Auvik sites and devices are included in those alert definitions.

ServiceNow installation, integration-user permissions, incident-field mapping, CMDB configuration, and ServiceNow business rules must be managed by a ServiceNow administrator.

Configure the ServiceNow integration

  1. From the Auvik global dashboard, go to Integrations.
  2. Add or edit the ServiceNow integration.
  3. Enter the ServiceNow instance URL, username, and password.
  4. Click Test Connection.
  5. Confirm that the connection test succeeds.
  6. Save the integration.

Auvik supports one ServiceNow integration and one ServiceNow notification channel.

For detailed setup requirements, see Integrating Auvik with ServiceNow ITSM.

Associate ServiceNow with Alerts 2.0 definitions

  1. Go to Manage Alerts > Alerts 2.0.
  2. Open the alert definition that should create ServiceNow incidents.
  3. Confirm that the alert is enabled.
  4. Confirm that the alert applies to the required sites.
  5. Under device or entity selection, choose All Devices or define the specific device types, tags, or entities that should be monitored.
  6. Add the ServiceNow notification channel.
  7. Save the alert definition.

Repeat these steps for each alert definition that should create ServiceNow incidents. For example, you might associate the ServiceNow channel with device-offline, interface, performance, or hardware alerts.

A device will create a ServiceNow incident only when:

  • The device is included in the alert definition’s scope.
  • The alert condition is met.
  • The alert is enabled.
  • The ServiceNow notification channel is associated with the alert.
  • The alert is not prevented from sending by a maintenance window, suppression rule, or other notification setting.

Applying alerts across multiple sites

To apply an alert definition across the account hierarchy, create or edit it from the appropriate global or parent multi-site level and select the required child sites.

To apply an alert only to selected sites, choose the specific organizations when configuring the alert definition.

Review inherited and site-specific alert definitions carefully. A child-site alert definition or notification-channel configuration may differ from the parent configuration.

See Creating Alerts using Alerts 2.0.

Confirm the ServiceNow incident

Use a non-production device or an existing safe alert condition to validate the integration.

  1. Confirm that the test device is included in the alert definition.
  2. Confirm that the ServiceNow notification channel is associated with the alert.
  3. Trigger the alert using a safe, non-disruptive test method where possible.
  4. Confirm that the incident appears in ServiceNow.
  5. Confirm that the incident contains the expected alert, device, site, severity, timestamp, and state information.
  6. Confirm that the alert-clear event updates or closes the incident according to the ServiceNow integration configuration.

Do not interrupt a production interface or block monitoring traffic solely to test the integration.

ServiceNow configuration and CI linking

Auvik sends alert information to ServiceNow through the ServiceNow integration. The way ServiceNow maps that information to Incident fields and Configuration Items is controlled by the ServiceNow integration and CMDB configuration.

If incidents are created without a Configuration Item, ask a ServiceNow administrator to verify:

  • The device exists in the ServiceNow CMDB.
  • The device identifiers are synchronized correctly.
  • The applicable CI identification rules are enabled.
  • The ServiceNow integration has permission to locate and associate the CI.

See How to integrate Auvik with ServiceNow CMDB.

If no ServiceNow incident is created

Check the following:

  • The alert condition actually triggered in Auvik.
  • The affected device is included in the alert definition.
  • The alert definition is enabled.
  • The ServiceNow notification channel is associated with the alert.
  • The alert was not affected by a maintenance window or suppression rule.
  • The ServiceNow integration connection test succeeds.
  • The ServiceNow integration user still has permission to create incidents.
  • ServiceNow business rules or duplicate-suppression rules are not preventing incident creation.

If the alert appears in Auvik but no incident is created, see New Auvik alerts aren’t being sent to ServiceNow.

Related articles

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

Auvik System Status

Check system status