Implementing ServiceNow Event Management - Best Practices & Guide (ITOM)
Einar & Partners
·
Feb 13, 2022
·
video
[Music] will do thank you alex well hello everybody and uh i'm so happy to see so many of you here today a warm welcome to all of you uh and completely uh overwhelmed um well then welcome to the our to our master class implementing event management successfully today you will hear from our experts alex and hannes and i will be your moderator for today my name is nermina and i'm a senior i.t operations and content specialists at einer and partners uh maybe just before we start we should maybe just uh take care of a couple of things right in the beginning here regarding the recording of the webinar uh yes it will be recorded and it will be available on the youtube channel of final partners uh the second thing is also that the uh topic of today's webinar is also a white paper that will be delivered to you via email by monday also containing the link for the youtube video the third thing to mention is that you can see there is a q a function available here and through the entirety of the webinar and this session you can ask questions and we shall try to address them at the very end at the very end of the session here if there's maybe no more time to address your questions uh our experts will contact you on one on one session to clarify those things um yeah that that could be all uh in the la yep on the last on the very last uh slide of this presentation you will see a qr code that you can scan and uh you will get the emails of our uh panelists for today uh now over to you guys uh alex please awesome thanks so much serena um so i'll go ahead first here um just like nermeen i explained i am super excited to see so many people today and like we said in the beginning hannes i think we're breaking a record here so over 700 people have signed up for today's masterclass and yeah that just makes me so happy to see um nice yeah super cool but with that being said we only have one hour here and what we're going to discuss is indeed about event management so very very fun topic um it's something which i am very passionate about and my name my name is alexander youngster i'm currently working as the managing director at nrm partners and just some very brief background about me um i have worked with event management since the absolute first release in servicenow so that was in the fuji release if i'm not mistaken so quite a long time now like almost six seven years um i used previously to work at servicenow in their item team but these days um i am leading then the company and partners and what we are doing we are focusing only on servicenow item and the strategy around that so obviously i'm very passionate about this um but i'm also very happy that i'm not only alone here today but that i have my good colleague and friend hannes with me so hannes who are you hi guys so yeah i'm honest here with kalia i come from the cloud people company i'm based in my my basement today in helsinki normally i travel around a bit more to see customers but yeah i'm one of the the founders a managing partner here at the cloud people and we focus on on kind of getting the value of the servicenow platform whether it be in event management or other topics to our customers so we implement we support we can resell et cetera et cetera we've been in the service now business quite some time and of course in event management as well i think our first customers um in servicenow came at 2009 when when servicenow was just basically starting so that that's a long time ago now i feel old uh and in event management space in particular you know we've done event management or built event management solutions on top of servicenow platform even before the event management solutions existed so a long-standing experience uh with event management as a topic and also servicenow is the platform and uh yeah we are a company from from northern europe currently 200 people um and they're growing very rapidly and i'm really happy to be here today alex with you and uh yeah looking at a record crowd so let's do this let's do this indeed super cool guys all right so um there is a large audience here today and some of you in the audience you will have you know different level of experience when it comes to event management so we try to put the balance somewhere in the middle and for those of you who are absolute beginners then this will be useful to learn about the capabilities of event management what it actually can do for you then for those of you who maybe are a consultant maybe you're working as a project manager product owner solution architect etc you're probably sitting here today curious about how can we realistically implement event management what are some some tips and tricks we we should think about when we scale event management so i will speak a little bit around that and then obviously johannes here with your experience especially around the business related areas building business cases etc you will give some guidance there and i believe you also have a real life case with you with some kpis that we're going to present in the end so exactly yes yes excellent excellent um and just like nermeena said in the beginning should there be any questions meanwhile use the q a function um i just want to clarify one thing before we get started so who will the master class target i mentioned a few roles here um but when we speak about event management we can essentially categorize it in two ways and today primarily we are referring to the more let's say traditional monitoring setups and what i mean with that is if you are a company who are using nagios scom subix assure alerting sap systems etc the more kind of traditional monitoring then this is a good master class for you often it could be that maybe you have a network operator um yeah network operation center maybe you're on msp so you have a lot of customers and you're doing a lot of monitoring or maybe you're just a traditional enterprise with a lot of different monitoring teams the webinar today is not about if you're sitting here wondering about devops observability site reliability engineering application performance monitoring etc we've actually covered this topic also together with the cloud people before and there are recordings available for that so with that being said for those of you who genuinely are interested in the real life implementation journey then this is the the master class for you as well as the business sides and the return on investment aspects so i just want to set these expectations right now so some of you who yeah who maybe we're on the more the right side here don't get too disappointed um also i'd like to clarify what we will not cover because there are already a lot of videos about how you configure event management and you know the technical aspects and of course we will touch upon some of them but i will not go into the nitty-gritty details today about best practice around configuring event rules for example but um that is a separate discussion and i will also not speak about the rest of the item health parts so much so namely health log analytics and metric intelligence an additional i also assume here that the audience at least know the very core basic concepts of event management because that way then yeah we can simply generate more value here today i think um so with that being said let's jump in here and start a little bit speaking around the capabilities of event management because just like i explained before we're not gonna cover like the most basic technical details today about how you configure event management and the reason for this is when we are implementing event management there is often a bigger picture in mind that is neglected so i will speak more about that later but first for those of you who are a little bit new to the topic or maybe for those of you who just want to brush up your knowledge let's look at the capabilities and what can one expect from the product so as i mentioned before then me personally i love event management like it's one of the greatest products in the item suite in my opinion at least because it's quite straightforward um it really gives good roi and it's very very tangible if you compare to like discovery maybe or a cmdb that's typically something which not always give an immediate value which you can measure but event management is very tangible when it comes to roi and kpis and measuring things and that is one of the reasons i like it so much um and here's the thing with event management that like hannah said in the beginning the cloud people have worked with it since 2009 i have worked with a long time as well so event management has been around for quite a long time and what i like about the product is that we now start seeing the products basically on steroids when it comes to the innovation of it so to the very left side here that's where we started like around seven years ago then in the beginning event management it was mostly meant for kind of being the manager of managers where you really consolidate all the monitoring tools and you get this single pane of glass type of thing and you also had things like groupings and correlations and this was in the beginning in the already fuji release helsinki release and so forth then around five years ago we started seeing something interesting which was more around the metrics and the machine learning parts so that's when we really started being able to do more predictive monitoring and doing predictions and looking into the future so anomaly detection metric base etc um but only now the past two years we have seen huge huge innovations in event management um or in the item health suite in general so for example we can now connect logs we can connect analytics to it and now as of lately i think only two three releases almost we actually have the capacity to not only consolidate event tools or event sources but we can actually use event management as a standalone monitoring tool itself and honest i believe you have some practical examples of this later from a customer but this for me makes it a very very fun product to work with looking at just how rapid it is developing yeah very true so i'll touch upon that subject later on with with one customer example um i i wouldn't like to say that it came as a surprise but it was a positive effect that the new agent-based stuff from servicenow actually is is pretty mature so so we'll touch upon that later later at this presentation yeah exactly exactly um so alice speaking of this agent and so forth maybe you could high level go through of some of the business drivers so what are the typical reasons why people choose to start with event management what have you heard based on your experience yeah that that's a good question so i think in all of what we do in iit a business case or or a calculation of benefits is is something that drives the investments so so we need to have a at least a clear vision of kind of what do we want to achieve uh when going into any particular initiative and today's question around item health or or event management for that question it needs to have a calculated business case and it can be from a strategic perspective you know servicenow fox talks a lot about their 3-0 strategy which basically means zero physical footprint zero outages zero incidents uh the business drivers can be on a strategic level or then coming down to a more tactical or operational level um reducing mean time to repair or improving root cause analysis so it depends very much on kind of where the customer is and what the day-to-day situation is so do we need or do we have a lot of outages do we need to reduce that amount of outages or do we want to save time when improving the restoration of services so it is a case by case but we are here to help we've seen a lot of these initiatives starting and of course finishing as well so we're here to help calculating basically on the kpis calculating on the business drivers and helping you you voice your aspirations internally in organizations as well when it comes to calculating a business case but uh kind of what i want to state here and highlight is that the situation is always different there are some strategic level drivers and and we're here to help you pick out the best ones that fit your organization that's very interesting so if i understand you correctly understand basically there are multiple layers like strategic ones tactical ones operational ones where there are all different business drivers and i think we will touch upon those a little bit more later if i'm not mistaken sure that's true yeah okay super cool um so these are these are obviously some of the business drivers um but what i'd like to do now is because of course especially maybe for some of you on the call here today um you might have worked with event management for a long time or you you have read a lot about it and it's not the first time you hear about these these concepts of noise reduction what i mentioned before a single pane of glass so these are all familiarized concepts for a lot of people and you can find it on the documentation website you can find it on the website of servicenow etc so i would like to now go in a little bit to the capabilities of event management and i'm gonna focus on an area which i have seen is often not really highlighted as much as it should be so for me the true power if we speak about the capabilities of event management the true power lies in connecting data points and this is especially true when it comes to in anything in it operations cmdb the servicenow platform and so forth but i would like to break this down and show practical examples um of how this actually looks when we are connecting data points with the help of event management um so this is a capability blueprint that we have of event management and in the very bottom here so that would be considered like the infrastructure layer right so that is where we have the monitoring tools situation and in our infrastructure landscape then we have typically a lot of different monitoring tools there was you know a research done by i believe forester group and they identified that they they asked a lot of enterprises and i think that over 25 of enterprises were using 40 or more monitoring tools so you know it's quite a lot of monitoring tools if you're a sizeable company um but then what we tend to do with event management is that we put out maybe already know this but we put out these mint servers in the network or in the cloud or in the on-prem systems or whatever it might be and these mid servers is typically where we send the events from the monitoring tools and all of these mid servers they can then receive monitoring data it could be from different environments it could be from different customers or it could be from different monitoring sources like nagios scom etc here we have servicenow and when we speak about capabilities i'm going now to split it up into or slice it into four different sections so i want people to be aware of these capabilities and of course there are much much many more than this but this is the simplified version so why should we use event management essentially the first thing is when we have set up all the all these different monitoring tools they are typically segregated from each other individually they are very very good at what they're doing so if you have solar winds or cisco ise or something like that it's very good at monitoring network equipment if you have scom it's very good at monitoring the windows servers and so forth and so on but the truth is that often there is a cause and effect in play and this is what is difficult to see when monitoring tools are separated from each other because think about it like if if you have a core switch which dies then there will for sure be a domino effect in other monitoring tools and this is one of the main reasons why we are consolidating them to the servicenow platform because when we're connecting it all to the same event management platform we can then really start grouping alerts from different monitoring tools together and now you might be wondering well alex how does that actually work how does that take place well it takes place from three perspectives primarily the first is if you have a good cmdb you can correlate different data points from different monitoring tools to the same type of infrastructure and configuration item so a practical example let's say you have a server and on that server you have sql instances and maybe you have two different monitoring tools one for the sql instances and another one for the servers typically these monitoring tools are separated but because we have a cmdb here the cmdb is kind of the link in the middle and then we also have things like relationships in the cmdb or relationships with service mapping which also can be used to group things and correlate things and finally in the last release in the san diego release we also have tag-based clustering where you can actually look at text patterns from different monitoring tools and based on that you can group them together so all of these factors combined can create really solid groups of alerts that are typically completely discollected from each other and give a more accurate picture and here comes the the cool stuff so when we speak about rca or root cause analysis so if you in service low also have changes you have incidents maybe you are also using logs and you are using discovery to find configuration files maybe you are using the knowledge base all of these things can then be connected to the event management parts so when you get an alert you could potentially see okay was it due to a change happening somewhere and what was the domino effect there or was it due to an incident do we have a p1 open that was causing these alerts and so forth and so on um so there's a lot of data which is being generated and that's where the machine learning and analytics parts come into play from service now so this is very out of the box you don't need to tweak these things but basically the machine learning elements they they are put as a wrapper around all of these aspects here and then in the very top when you do your analysis uh when you are investigating maybe you are working in a network operations center or maybe you are in a help desk and you have an alert you're using all of these different data points together then finally you decide to take action so maybe you create an incident or maybe you trigger a flow of some sort which reboots a server or grabs a file or whatever it might be but i just wanted to highlight these things because when we speak about capability this is the bigger picture that i have seen people often fail to communicate to other monitoring teams and this is where the true value lies when we speak about event management um all right so i'm not gonna go through this now but if there are some people on the call who are now sitting and maybe the first time hearing about event management you should just be aware about the high level concepts here very very simplified that we have payloads coming in to the the event management tool from different monitoring tools then we have an event created then based on that event we might or might not create an alert and based on the alert we might or might not create an incident or take action or whatever it might be so obviously i'm not gonna go through these things now because they're quite fundamental and basic but if you're curious about them then go ahead and read the documentation website and the reason i was mentioning them is because i'm going to speak about some of these concepts now when we come to actually implementing event management then so as i mentioned before i'm not sitting here today speaking about implementing event management of this is how you should configure it or this is the the settings that you should use for your mid servers or something like that when we truly speak about succeeding with scaling event management there are other factors that comes into play so i'm gonna tell you a story and this is a story that i often see repeating itself keep in mind that we have worked with probably 20 25 major enterprises and looked at event management i've been speaking to so many people who are using event management so what i'm telling here is like it's very common thing um and what tends to happen in some cases is that event management is bought for whatever reason maybe you are in the process of buying servicenow item and you get like a sweet license deal from service low and they say like well add event management for just a small increase in cost you get all of these extra features or maybe you're like a product owner or platform owner with somebody and you buy event management okay great and what i often have seen is that there might exist a core team who is very enthusiastic about event management maybe this service now team some people configuring it it looks really cool and on paper it has all of these great features of machine learning of grouping things together all of these things that i just explained but yet the rate of adoption is low and this is something i often see repeating that despite the fact that event management exists we have all of these technical baselines then people don't use it and this is the situation that we'd like to avoid and this is a situation that i often see repeating itself and this is largely what i'm going to speak about now today how do we avoid this and how do we really scale event management i'm not speaking scaling from a technical perspective but scaling from a usage perspective really embedding it into the dna of an organization so that is for me what it is about and that is what often is difficult for people to do and let's look at it because i'm not making this up um this is some statistics this is some research so at the inland partners we have a research unit where we often try to benchmark things we try to look at yeah how do the things work in real life and we did a questionnaire we went out to a number of customers and people who are using event management and in the very top here actually only six percent of the people we asked they claimed that the technical aspects of event management was the primary challenge so only six percent said that the configuration was like where they struggle the most and that for me is very interesting so despite being like a rather technical area obviously it's a very very small minority who find that being the primary challenge um for the people who were successful with event management that actually succeeded with rolling it out eight out of ten of those they said that event management gave the quickest results compared to any other item module that they had implemented so if you succeed with event management if you follow these tips and guidelines the time to value can be quite fast actually and this for me is pretty cool and when we looked at the cases that had rather poor return on investment for whatever reason it turned out that over 72 percent of those cases it was simply due to a lack of buy-in so that low adoption rate that i spoke about before so the point i'm trying to make here is that when we are speaking about scaling event management and implementing event management there are other factors to consider than simply doing a kick-ass technical baseline and that's what i'm going to speak about a little bit right now um so of course harness you too if if you um feel that you want to contribute with some of your experiences feel free to jump in um but let's start with the baseline here so when we start with event management what i have seen is that it typically starts from one of two viewpoints the first one is mandated by policy so basically there is a necessity to to transform and the other one is what i call the convincing game that's where you actually need to create organizational buying and depending on where you are in this spectrum here the way you implement event management and the way you succeed with it will vary differently so if there is a policy driven mandate to transform it often means that there has been like a centralized decision to use event management for example if you are an msp then okay we are going to change out a tool or we're really going to start with event management and there is no questions asked about it everyone is going to do it you don't need to convince people it's a fact and the same is if it comes from the i.t leadership and it's mandated there that we have to transform there is no other option so it's not up for debate basically um and what we often here also see is that in these situations it tends to be a rather big spread of like legacy monitoring tools that are disconnected so you know scum subjects nagios these type of things the political volume it tends to exist already in a certain extent at least so you don't need to convince monitoring teams and whatnot but everyone is on board from the beginning and often event management might actually be the first true modernization in quite a while that the organization had done so if you are on the left side here then implementing event management goes rather fast and on the right side here which is what i will speak a lot about today this is what i call the convincing game so often the reason we have developed management then is because maybe a product owner with budget they have bought event management but there is still like a lot of work done to really embed it into the company and if you look at the perspective from monitoring teams what i have seen from personal experience is that yes they agree the tools they might be disconnected but individually the monitoring teams they don't really consider themselves that they're struggling as such they're pretty happy with their tools and like well why do i need this you know so this means that the buy-in it really needs to be created or it only exists in like isolated pockets here and there and these type of on the right side here often we also see that modern monitoring tools tend to exist in one degree or another so like dialer trace or maybe there is some tool for anomaly detection etc um but i just want to mention here that this is a spectrum it's not like one or the other it can be quite a mixture here but try to to understand where you are on this spectrum because depending on where as i said things will look differently when you embed event management um all right so let's look at embedding event management then in an organization because truth is people are most afraid of change when they are not part of it so what i'm going to speak about now is how can you really convince monitoring teams to start using event management and why should you do so all right so here are some tips the first tip here is immediately from the start speak the same language so when you approach monitoring teams there needs to be an absolute clarity about how do we define a metric how do we define an event and how do we define an alert and how do we define an incident the reason for this is because different monitoring tools call these things differently or they define them differently so if you're working in let's say nagios an alert might be known as a notification and if you work in subjects maybe when you're speaking about an event you're actually referring to an alert and so forth and so on and actually i have seen this create a huge amount of confusion when you approach different monitoring teams and you start speaking about events and alerts so point being really create good definitions of what do we mean when we speak about these different concepts and another very important reason for this is because when we integrate with monitoring tools then the question is will we integrate the events from the monitoring tools or will we integrate the already filtered events aka the alerts into servicenow event management so have some clarity about the definitions when you approach the monitoring teams um another thing which i often see being a mistake is that there is not really a super clear value defined so basically when you approach monitoring teams when you're gonna start onboarding different sources of development management it should be crystal clear in which way does it help other people in the organization if they share their data with service law with servicenow event management i mean and in which way could it help them if they share their data with servicenow event management so really have well-defined use cases of how will the value be generated and how they spoke about it before on a strategic on a tactical level on an operational level but really draw up this use cases because i have often seen monitoring teams sitting and they're saying well i'm not really sure how this will help me you know no maybe it won't but with them sharing the data it will help a lot of other people maybe the help desk maybe in the network operations center whatever it might be um and that brings me to the next part here another classic mistake that i often have seen is that who will actually use event management it feels like a pretty rudimentary question to ask but knowing the target audience the user personas of realistically who will sit and look at the alerts who will sit and look at this events coming into service now every day there needs to be someone we're doing all of this for and that should be crystal clear and those are the people that we should create all the processes for as well and last but not least this will be a very big thing when you're gonna scale event management thresholds and filterings so when you approach different monitoring teams when you have different sources what assumptions can we make when it comes to the filtering and the thresholds can we assume that all the events that they are sending to service now they should instantly become an alert for example because they are critical or they are high severity or something like that so things like that what assumptions can we make about the data that is being generated and sent to servicenow another important thing where will the filtering take place so where are the filtering being applied and where are the thresholds defined in a lot of cases it will be in the monitoring tools that you're integrating with because they already have defined thresholds since before and they don't want to recreate all the thresholds in the service now even though you could if you wanted to of course um but this is this is important because i have seen a lot of monitoring teams create a huge amount of resistance and being quite protective about their tools so essentially have a very clear consensus on where are the thresholds and where are the logic being placed so the logic for creating incidents and groupings etc it will be in service now but the basic thresholds and filterings and whatnot it will be in the monitoring source so that's just one example but this is hugely important and something which i often see being neglected or not addressed enough okay so rollout models what have we seen here there are two common rollout models um the first one is a source based rollout model all right and this one is basically where you identify the different event sources that exist and you approach them one by one so maybe you have 20 different event sources okay then you take them one by one you reach out to the individual stakeholders you explain what event management is how it can help them how it can help the organization etc and then you start creating event rules you actually connect the source you set it into production and you launch it so in other words you approach it source per source the good thing with this is that it has a rather large impact because you're doing it on a source per source basis the bad thing is it takes a lot of preparation so be aware of that then we have this approach what i call the wave based approach and this can happen either per site or it can happen per customer or maybe per network segment or maybe per critical application or whatever it might be but in a wave based approach typically you take for example these are our most critical applications you identify what objects are being monitored and then you do a delta and see okay do we have all of these objects in our cmdb do we need to create tags etc etc and then you start allowing the incoming events so this is a more gradual expansion but this often assumes that you have the sources already connected and that you are slowly kind of allowing more and more data to flow in to service now based on customers based on the sites based on the critical applications or whatever it is so it's a more iterative process with gradual expansion basically um so stick to one of these two rollout models and it's it's rather successful um approaching the end here we have also the the short and long-term vision which is often uh being neglected a little bit that people want to run very fast so how can we plan for long-term development and embedding um this is a typical journey that i have seen being successful so start with the core all right stick to it without the box groupings correlations etc then after that we can look at remediation areas so connecting into itsm change management incident management etc but the purpose here is to have a baseline of people using it and not only until that is done is when we really start optimizing things so this is where we start creating like custom groupings and correlations maybe we start receiving events on levels of microservices and devops like kubernetes docker etc and that's really the second stage where we start innovating for real but the point is set up a baseline and once that is done then we can start looking at ai and logs and so forth so some of the goals that could clearly be defined in a roadmap is things like noise reduction maybe by a certain number we should working on group level of alerts instead of individual alerts maybe we should do direct cost savings maybe we should optimize mean time to resolve and so forth and so on um so have that roadmap in mind and then now finally before i hand over to hannes what are some pillars for a successful rollout so these are like some tips that that i have seen so use these tips um and it can be more successful than you imagine first don't get stuck in custom groupings and correlations too early in the project go with the 80 20 approach all right try to cover 80 percent of everything and then you approach the final 20 later not everything will be perfect from day one but a lot is good already which brings me to the next point that out of the box capacity for event management will probably cover like above 90 percent of all the needs when it comes to like groupings and correlations etc there is one exception here which is for domain separation um leverage pilot groups this is hugely efficient i have seen that you create pilot groups where you have a few enthusiastic individuals and you create champions from these pilot groups and these people can help really spread event management in an organic fashion a huge part of event management is about noise reduction so know where to measure that noise reduction is the noise reduction in amount of alerts is the noise reduction in amount of incidence is it in the amount of critical incidents etc etc but really know where to pinpoint these things and start measuring that noise reduction so you know you're on the right track um also i always advocate challenge the constant need for bi-directional flows of data i often see every monitoring team almost always saying can we get this bi-directional um yes you maybe can in theory but one of the primary purpose with event management is that we want event management to be the driver so you don't always need bi-directional flows of events and alerts at least be aware of that and challenge it sometimes and finally monitoring people and subject matter experts they love their own tools so they will not want to switch to event management always and what i always do is i don't go into technical debates one mistake i often see is people just telling about all of these cool features but people are used to the way they are used to working so rather focus on communicating the big picture that i explained before and that typically made monitoring teams more willing to share their data and involve themselves in the process um so i've been talking a lot right now but harness based on that um tell us what are some business drivers and business cases and you also have a customer case with you i believe so so basically we now heard um around the concept of event management and where does it benefit the you guys the customers the users the business stakeholders if we take a step back so so kind of if you're not interested in invent event management what can we do uh to get you guys started and these are some practical real life examples we've seen uh what was the decision making process what did we kind of figure out as we went along in different customer implementations so i think my first tip here is is look inside so so if you've now kind of made a decision that event management from from servicenow or item health for that matter looks very interesting i think we should start looking at insights of what are the tools and the capabilities and the people and the processes we have around event management so what do we have there more often than not uh when we start an event management program we actually gradually start finding out that you know this tool also uh has plays a part in event management so we we kind of uh get to not not a surprising effect but you know the the tool landscape is not that black and white or clear-cut from the day one but it's more of a gradual learning curve so look inside that's that's our first tip or my first tip um then keep the the goal uh clearly in mind so event management will apply a habitual change so i think the good implication alex mentioned it in in his previous lives but the concrete implication there is that the moving away from a let's call it a server-based approach to a more service-based approach on monitoring or events that is what is going to happen so if you have that plan and the goals and the kpis that we've discussed previously if you have those in mind just understand that there's going to be change there's going to be innovation and there's going to be adoption during this program cmdb in in our view or in my view is is integral um it is time to brush up the cmdb during an event management implementation and of course one one good implication of it is moving from a purely a ci based or a server based approach to more of a service based approach so it's not there's a question in the chat as well it's not a prerequisite in my opinion to starting an event management program but be aware that cmdb is going to become an issue during the program or during the implementation of it and that's one part of the innovation and kind of going forward after event management first phase is that cmdb is going to be looked upon or it's going to be in the center of things and then service mapping or sorry road mapping service now has a lot of good capabilities or good functionality that can help around event management and it's good to understand what that capability is i think alex mentioned it a couple of slides back the new agent-based stuff from servicenow so it's good to be aware of what is there and what's also coming so that we can plan an internal roadmap to be aligned with the servicenow's event management roadmap in general so going forward um if you take the next slide thanks alex there we go um a few tips and tricks on on how do we start to calculate the the business case so keeping in mind the the lessons learned from the previous slide so of course the business case is around money it's around effort it's around what do we improve so it very often starts looking internally so looking at the current monitoring tool landscape identifying the capabilities of these tools provide different element managers that you might find different provisioning tools there are several tools out there that do event management do some monitoring capabilities but also do some some provisioning capabilities so it's important to understand the landscape of it so what are we talking about what are we here to to integrate what are we here to replace what are we here to improve then it goes down to the nitty-gritty which you basically need to do with with your finance department or your legal department with with looking at agreements so what is it costing us so what are we currently spending on this space uh it's not a hundred percent accurate analysis all the time but it's it's important to get the baseline or but kind of get a good picture of the running costs uh so that we're able to create the baseline of it and that involves of course software maintenance costs people and time used time worked so it's not an exact science but it's clear to to kind of or it's good to get a clear understanding of what the the generic level of costs are then it's time to move on to to more of a people perspective so talk to the teams talk to the different event management teams or monitoring teams or or teams in general that that where is their time spent is it around uh you know getting the services up and running is it time around root cause analysis is it around uh getting getting the stuff back into to operation where do you spend the time and that gives us then of course a view on kind of where do we start to pinpoint and where we start the event management implementation or the journey of it then of course talk to management uh get feel of the urgency so once again getting back to the kpis and kind of the strategic part of the kpis what is the urgency of event management uh is is there a kind of a burning flag or a burning ship that we need to fix what are the priorities and when we start the roadmap what do we need to fix first so it's all around uh kind of getting the the uh the basic information in place then i think it's time to to look outside uh talk to your trusted advisor talk to your partners talk to servicenow um and get a feel of what is there what's the actual effort how much does it take to implement this what would be the license cost uh what would be the training cost uh just getting a solid feel of the investment that how do we how do we get about it and what's what's what's the monetary penalty basically what do we need to put on the table uh scoping and roadmapping is very important so talk to your advisor talk to your partner talk to servicenow there's there's a lot of stuff available on how other organizations have done this journey where they started what were the pain points so there's a lot of lessons to be learned from from other people already adapting event management and then kind of approaching uh implementation project time is of course choose the kpis uh choose the kpis to focus on and that basically gives us the the plan to success so what are the actual metrics whether they're on a strategic level or more of an operational level what are we there to improve so that should give a good baseline of kind of uh what do we need to spend where are we spending it and what are we actually improving it and kind of once you have all of these bullets in your head it's it's then time to uh you know to start the work yeah yeah this is a really awesome summary on this i really yeah i think you know putting it in a journey like this makes total sense from a business perspective so you guys obviously have been working with a case like this so maybe you know we could spend here three four minutes yes high level to speak what are some of the main benefits that that you sell is that the cloud people with implementing this sure yeah i i took one example from our our event management customers and um it's one of those those really nice examples of course that where we get a huge cost avoidance or cost reduction so this customer in the telecommunications area was looking at a lot of legacy tools a lot of event management tools that had kind of duplicate capabilities and there were a lot of these tools basically on top of each other and then with the new functionality of item health from servicenow and especially with the agent-based stuff in item health there was a lot of capability that we could just reap and replace so that kind of incurred a lot of dramatic cost reduction when it came to licensing cost that's not always the case but in this case i think we were lucky together with the customer that we were actually getting an immediate return on investment on reducing license costs but in this case uh as well as as in all the other cases i think the mind change or the the the change in operations or modus operandi is more important so we are moving from uh basically looking at individual cis or individual servers sending in alerts uh or sending in events more to more of a service-based approach and if you look at the very bottom of the slide so uh that should give you a little bit of a picture of the scope of it so there are around 6000 devices generating 1 million plus events at any 24 hour time period and what we've managed to accomplish is that out of those 1 million events the alerts are going to be in the hundreds only so not thousands but in the hundreds and then that leads on to two different incidents um at the pace that we haven't yet actually calculated but it's a it's a good testament that we are actually reducing the noise quite a lot um and then only creating hundreds of alerts but i think you know this case being um very much focused on on rapid implementation and a huge cost reduction i think that's just phase one uh the the important part is the journey that we've started together and the journey that you know alex's team and our teams are helping our customers uh in in advising in kind of planning for the journey that's the more important part but a good case we can open uh it in more detail uh in when one to one sessions so um we're not going into customer names but um yeah it is a testament to why event management actually is a good investment in our view yeah yeah and what i really thought was um so cool with this case is that we instant or you guys instantly started using the new uh agent-based um so that's you know it's it's very beneficial of course yeah that was yeah that was also actually a lucky shot that it came from servicenow at that point so sometimes you know a lot can be involved in these cases but it's a good learning lesson we can take it from that and then we can apply it to different other customers as well so it's really cool yeah that's right that's right with that being said there is always a lot of things to speak about when it comes to these sort of topics we've been sitting here more than one hour now almost um i see there is a lot of really great questions coming in here and what you mentioned is before about one question which i like to highlight from the audience is around is it a necessity to have that perfect cmdb i would say it's not a necessity um there is a fallacy even of having that always chasing of that perfect cmdb with event management don't let that become a showstopper but yeah like you said before honest using event management as an incentive to let's improve the cmdb is a great driver but it's not a necessity as such exactly exactly yeah so it is a good question and and luckily we had the slides to prove it but yeah it is going to come under the radar or under the magnifying glass but yeah as alex said it's not a necessity so don't wait for that to start event management you can go ahead with it so a very good question thanks for that yeah um a final question which i saw is a more technical oriented one but i'm happy to answer it um so chandrich is asking are there any scenarios where we can use event management as one of the sources to populate the cmdb i find this a rather interesting question actually i would say you will get very little data from just using event management to populate the cmdb from it in that case i would rather seriously consider either integrating things or using the agent-based approach using event management as a source in itself for the cmdb i i would not think so but nonetheless everyone with that being said there are more questions but we will get back to you individually as we said we have now sat here for one hour and i'd like to thank everyone so much i thought this was great fun i don't know about you alice and there will be really brilliant fun absolutely and for some next steps here um keep in the loop about alarm partners and the cloud people follow us on linkedin we will do more source of these master classes as nermeen i mentioned in the beginning all of those of you attended you will receive a white paper sent out about event management so kind of a guidebook on how you can implement it yourself um and you can always reach out to either me or alice if you are curious about these aspects so check out the website all the cloud people check out the website of us and yeah let's be in touch for the future everyone so thank you so much thank you guys thank you bye [Music] you
https://www.youtube.com/watch?v=9YT9Mzoj0Rw