FAQ for Incident Management in SOW
Frequently Asked Questions
Basic understanding of Incident Management
What is Incident Management?
An incident represents an unplanned interruption or a reduction in the quality of service - Incidents can include failures or degradation of services reported by users, technical staff, third-party suppliers, and partners, or identified automatically from monitoring and event management tools. Incident Management helps restore normal service operations as quickly as possible after an unplanned interruption and minimize the impact to your business. Incident Management also ensures communication with the end user community throughout the life of the incident. Users can record an incident and track it through the entire incident life cycle until service is restored and the issue is resolved. Reports are used to monitor, track, and analyze service levels and improvement.
Refer more details for incident Management in ITSM here.
Incident Management in Service Operations Workspace (SOW)
What is Incident Management in SOW?
Introduced in San Diego, Service Operations Workspace provides agents and operators with a single-pane-of-glass view to easily manage an incident through its entire lifecycle. Starting from a simple and intuitive overview page, agents can see the incident summary, affected CIs, impacted services, potential causes, and resolution, if available. Additionally, customers licensed with ITSM Pro can leverage the Investigation Framework to help streamline incident resolution through surfacing relevant metrics within the context of the incident and the ability to execute remedial action playbooks to accelerate incident resolution. Incidents responders can access contextual recommendations and configured on-call experts to reach a faster resolution. We continue to invest and innovate on the Service Operations Workspace Incident Management experience - check out our product docs and product updates for more information.
How does Incident Management in SOW differ from the UI16 Incident Management experience?
Incident Management in Service Operations Workspace has feature parity with the UI16 Incident Management experience but does so in a modern and intuitive user interface that enhances usability and simplifies the process of creating and managing incidents. SOW provides a more streamlined and organized approach, allowing agents to access relevant information and take necessary actions without the need to swivel chair between applications. Like legacy Incident Management, SOW Incident Management can take advantage of advanced automation capabilities (e.g., automated assignment, smart categorization, recommended actions based on historical data) powered by AI/ML. Moreover, the Service Operations Workspace provides enhanced collaboration tools, through integrations with Twilio, telephony, Microsoft Teams and more, enabling streamlined communication and coordination among support teams and stakeholders.
How can I make the SOW workspace configurable according to my needs?
SOW workspace is built to be a highly configurable unified interface for all users. The UI Builder provides base system components that you can use to build workspace pages. You can build a pin-able/pop-over navigation experience with an extensible top menu system that enables agents and operators to graphically organize work. You can personalize agents’ instance and set user preferences. You can navigate to NOW Experience Framework > UI builder to start customizing your workspace.
Check-out UI builder product docs for more information.
Check out more about Next Experience UI here.
Check out more about Workspace resources here.
What features are available for Incident Management in SOW?
As of Utah release, you can manage E2E incident lifecycle in SOW, where the overview page summarizes the affected CIs. The landing page allows the incident response teams to have visibility into work assigned to them or their team and also check the unassigned incidents. You can leverage SOW side panel functionality for additional capabilities such as Recommendations, Record Info, Agent Assist, Experts on-call, On-call Escalations, Templates, and more.
Check out the product docs for more information.
What are the latest feature releases for Incident Management in SOW?
There have been multiple feature updates with the Utah release for Incident Management in SOW. Check out our product updates document for details*.*
What are some of the plugins and store applications I can download for incident management in SOW?
To get started with incident Management in SOW, you need to install Service Operations Workspace ITSM Applications application (sn-sow-itsm-cont), which includes multiple user roles, plugins, and store applications that help in fully utilizing the potential of Service Operations Workspace. Store applications for incident management are:
- Incident Management for Service Operations Workspace [sn_sow_inc]
- On Call Scheduling for Service Operations Workspace[sn_sow_on_call]
- Recommendations for Incident Management [sn_sow_incident_rf]
- Agent Client Collector for Investigation (sn_acc_adapter)
- Microsoft Endpoint Configuration Manager for Investigation (sn_mecm_adapter)
Refer here for more info.
Note: Recommendations will require a ITSM Pro. License.
What are the licensing requirements for using Incident Management features in SOW?
You can access the baseline incident management features with your ITSM Standard license. Advanced features like Investigation Framework, Remedial Actions, Recommendations and Escalations would need a ITSM Pro license.
How is an Incident populated in SOW?
An Incident can be created in ServiceNow via different channels such as the web application, self-service form, integrations, chat, inbound email, walk-up experience, and change. You can configure the incident form to capture relevant information regardless of the channel.
How do I configure the Incident form in SOW?
To configure the incident form, see Configure a task record form in Service Operations Workspace. You can configure this via Edit Incident form view in Now platform user interface.
Where can I configure prioritization look up rules?
Prioritization is an important aspect of logging an incident as this determines how the incident is handled by support groups and drives service level agreements. Priority is determined by impact (effect an incident has on business) and urgency (the extent to which the resolution of the incident can bear delay). To edit or update the priority calculation, see Define priority lookup rules.
In the UI Builder view you can configure this via: Priority lookup rules.
How do I configure fields to categorize an incident?
Incidents can be categorized either automatically by using the existing machine learning solution definitions or by an agent using the Service, CI, and Category fields of the incident. You can use the category and subcategory fields to categorize an incident. The CMDB (CI fields) such as Service, Service offering, and Configuration item can also be used to categorize an incident. For more information, see Predictive Intelligence for Incident Management.
Can Agents collaborate with their peers as well as requestors to resolve incidents?
As of the Utah release, collaboration using Microsoft Teams is available for Incident, Problem, Change, Request, and Interaction task records. Agents can easily view the history of a chat, initiate a new chat, or import existing messages directly into the workspace.
Investigation Framework in Incident Management in SOW
Is there a license requirement to use the Investigation Framework in SOW?
Yes, ITSM Pro is required to activate the Investigation Framework and see the investigation tab in your incident records in SOW.
What roles can benefit from Investigation Framework in SOW?
ServiceNow Admins, IT Service Desk Agents (L1, L2, L3)
What integrations are supported with Investigation Framework?
As of Utah release, Investigation supports integrations with ServiceNow ACC and Microsoft Endpoint Configuration Manager (MECM) to fetch and display relevant metrics in the context of the incident. The associated plugins would be:
- Service Operations Workspace Core
- Agent Client Collector for Investigation (sn_acc_adapter)
- Investigation Framework
- Metrics Collector Framework
- Investigation Framework
- Microsoft Endpoint Configuration Manager
- Microsoft Endpoint Configuration Manager Spoke (sn_ms_epcfgmgr_spk)
- Microsoft Endpoint Configuration Manager for Investigation (sn_mecm_adapter)
- Microsoft Endpoint Configuration Manager Spoke (sn_ms_epcfgmgr_spk)
Reference docs for ACC set-up. Requires ITSM Pro license.
Reference docs for MECM set-up.
What are some of the CI metrics visible on the Investigation tab?
The Investigation tab displays CI metrics information along with various options. Use the options and the metrics information to view the data which helps to resolve the CI related issues.
As of Utah release, the metrics data includes the following information:
- Overview
- System information
- Asset utilization
- Memory utilization
- Disk utilization
- CPU utilization
- Uptime
- Memory utilization
- Top processes by CPU
- Top processes by memory
- Logged in users
- Installed applications
Note: Most of the metrics are color-coded based on the threshold values. However, you can customize all these values, if required. For more detailed information on features see product docs.
What configuration is required for ACC to start getting metrics on a CI?
An ACC agent must be configured on a CI to support investigation for it. Check more information here.
What do I check if the ACC is not working?
- Verify the agent status from the Agents table (sn_agent_cmdb_ci_agent) for the respective agent.
- Open the agent record and check the logs using ‘Grab agent log’ UI related link.
What do I do if the ACC data collection is showing paused?
- Verify the agent’s ‘Data collection status’ from the Agents table (sn_agent_cmdb_ci_agent) for the respective agent.
- Contact admin to resume the data collection if it is paused.
How do I troubleshoot the MID server?
- MID server is not working.
- Open the MID server record for the respective CI and use the ‘Logs’, ‘MID Server Issues’ related list to troubleshoot why it is down.
- MID server is showing paused.
- Contact admin to resume the MID server if it is paused.
How do the remedial actions and playbooks work in incident management in SOW?
Remedial actions use playbooks to resolve CI issues. Playbooks provide you with an interactive UI to guide and execute the remedial actions step by step. With a playbook, you can control every execution step of the remediation process. Playbooks are available on the contextual side panel of the Incident record page. When any remedial action is performed, that remediation process is added to a playbook. Check more information here.
What are the enhancements for Remedial Actions in Investigation Framework in Utah?
In this release, investigate is being enhanced to support a configurable and extensible Remedial Actions framework that enables agents to execute remedial actions automatically (via playbooks) all with the context of the incident and relevant CI metrics in SOW. In this release, laptop computer and server CI classes will be supported with OOTB Remedial Actions playbooks, but customers can add new/edit existing Remedial Actions. For more information check out our product update document.
What store applications do I need to download for Remedial Actions for Investigation in SOW?
You need to install the store application - Remedial Actions Framework (com.snc.sn_reacf) application to proceed with setting up your Playbooks. OOTB Remedial Actions support laptop devices and servers only. Playbooks for laptops and servers have different processes for each- laptops will default to requestor approval to execute remedial action, server will initiate change request to execute remedial action.
How can I enable Remedial actions in incident management in SOW?
These remedial actions are available on the Investigation tab only if the following conditions are met:
Which type of remedial actions are available on the Investigation Tab?
The Investigation tab includes the following types of remedial action to resolve CI-related issues as a OOB feature:
- End process
- Restart service
What plugins are needed to enable the Playbooks?
Playbooks are available only if both the Remedial Action Framework [com.snc.sn_reacf] application and the Investigation Framework [sn_invest_fwk] application are installed and configured. The remedial actions must also be triggered. For more information on playbooks, see Set up Playbook Experiences.
Escalation Management in Incident Management in SOW
Which table supports escalation tracking feature OOB?
As of Utah release, Incident table supports escalation tracking feature in the out of the box installation.
Escalation tracking feature in SOW comes as part of which store app?
On-Call Scheduling store app for Service Operations Workspace contains the feature escalation tracking feature.
Which system property needs to be enabled to collect and view escalation data?
- com.snc.on_call_rotation.log_escalations
Which role(s) are needed to edit above property?
Recommendations in Incident Management in SOW
What’s planned for Recommendation Framework in upcoming releases?
With Vancouver release, Recommendation Framework will be deprecated to the replaced by a much friendlier “Recommended Actions”. Existing recommendations will be migrated to Recommended Actions to deliver curated recommendations for incident response.
Given the deprecation plan, should I enable recommendation framework?
We suggest you to not to enable recommendation framework, but rather go for Recommended Actions which will be available with the Vancouver Release.
General Questions
How do I update the Donuts like “Incidents Assigned to me” in Service Operations Workspace?
As of Tokyo release, you will be able to make the query as you like. The query is in 'SowIncidentLandingPageUtilsSNC' script (located at sys_ux_client_script_include) as an encoded query string, you can override the query in 'SowIncidentLandingPageUtils'. Depending on which version your SOW is the code is a bit different.
https://www.servicenow.com/community/service-operations-workspace/faq-for-incident-management-in-sow/ta-p/2627389