logo

NJP

What’s new in the November '23 Store Release: ITOM Health

Import · Nov 08, 2023 · video

hi everyone I hope you are having a good day or a good morning wherever you are um I'm just going to be turning on my webcam right now so I hope you can see me for a bit but my name is Victoria low and I am an outbound product manager for itom health and today I will be going through what's new in the November 2023 store release for itom health so I hope you are looking forward to the content that I'll be showing you today and if you have any questions please put them in the Q&A and I'll repeat that in a few slides when I go over some housekeeping items but since everyone in the chat is talking about where exactly they're coming from I am coming from Toronto Canada so if anyone is in Toronto right now or Canada it's kind of getting cold um it hit about minus5 today and I had to take out my winter jacket which is always kind of a sad thing to do but any other Canadians out there who understand Celsius because I am very bad of converting to Fahrenheit you will understand me and sorry for anyone who works in Fahrenheit because I don't remember the conversion admittedly but on that note um with the theme of me being cold because it's Canada I'm not feeling the best but I will carry on with this presentation but I will be turning on my turning off my camera after the agenda um and yeah winter winter definitely is coming um but yeah let's get started so we're going to be keeping this presentation kind of short and sweet at this point um because we have some new things but not too many new things but I'm sure that you're going to find this useful to you so I just want to start off with a safe harbor notice for forward-looking statement since we will be talking a little little bit about some road map items or one road map item item specifically about what we want to do with generative Ai and itom that being said um because this is kind of a forward-looking statement we don't want to commit to anything because sometimes plans change um road maps change and all that stuff so just wanted to kick off the presentation with this um and I also wanted to let you know about joining us at Future webinar um exchanges so if you want to see the schedule of other webinars that are happening please scan this QR code right here there's also a link in the chat about how you can also sign up for future webinars and yeah definitely keep an eye out for future itom what's new sessions not just for health but also for visibility so definitely keep your eye out on this list and some housekeeping right before we get started so there is definitely going to be time at the end for Q&A so if you have any questions um keep them in the Q&A um if any questions I see coming a lot in out of specific time I may answer them during the session just because um we don't have too many items to cover for this quarter so just keep that in mind um so that we can also if we happen to miss your question we could always get back to you at the end of the recording that happens today and on the topic of recordings the presentation will also be recorded and shared out on the service now community so if you have any team members who may have missed this presentation you know they want to attend they can attend by or rewatch the recording on the service now community and after the event you will also be prompted to fill a short survey and please do because we would love your feedback and since this is our first what's new session for itom we want to know how we can make these sessions better for you so you can get more out of them and learn as much as you need for yourself and I also just want to knowe if you have any team members in Asia Europe or anywhere or mostly Asia um we do have a session later today or it would be early tomorrow for them local time where they could attend well not staying up super late if they also want to hear from our other team member a Cho um and hear and present the same content that I'm presenting to you today live and yeah now moving on to the agenda for today I will be going through the product Evolution then the overview of the major new features and enhancements an overview of the minor new features and enhancements as well as covering what's going to be end of life and sense up capabilities to help prepare you for any steps you may need to take as we approach these timelines as well as some major feature and minor feature overviews which is just more information on the overview of the features that I'm going to talk about in two slides from now so looking here we can see the product Evolution we're showing Quebec to Vancouver Utah was a pretty big year or pretty big release that was earlier this year where we had a lot of enhancements and new features surrounding alerts as you can see we just introduced alert tags which if you haven't already gone into alert tag definitely something should look into I'm working on a Blog article on it right now so you can learn a bit more hopefully in the next week or so about them as well as updates to metric intelligence and our extension of itom Health which is Health do analytics while in Vancouver the main focus was the aiops experience so if you haven't already heard of the aiops experience it is a intuitive set of capabilities that we've come up with in itom in order to to help and improve the proficiency oh not proficiency efficiency um and productivity of operators who need to manage alerts manage Integrations as well as looking at dashboards without having to have many out of the box dashboards which is not ideal we've also had some more enhancements around alert tags which I just mentioned um and we started looking into how we can integrate generative AI into the um Suite of itom specifically itom Health but for this specific presentation we'll be going over through event sync which is also referred to as the now on now connector the Improvement to HLA scale which we're calling HLA 2.0 as well as giving you some insight into what we're planning on doing with generative AI in itom health as well as covering some AC CM enhancement specifically for an Azure check and the enhancements to the advanced promotion engine which was introduced earlier this year as well and I'll explain a bit more about each of these topics later in case some of these may be new to you so an overview of these features that I was talking about is first off event sync so event sync which I'll elaborate more on later is a way to be able to connect the event between the multiple instances that you may have on your environment without having to necessarily redeploy these connectors on every single instance that you have so this enables easier testing of different scenarios without having to redeploy an integration on every single non-production server that you have of course there are other use cases but this is something that we thought would be very useful specifically for these scenarios but don't feel Boxed In by the use case that we are talking about mostly today as well as generative Ai and how we are going to be using it to enrich a learning and in terms of health log analytics 2.0 scale we're going to start using kubernetes enable to enable um in order sorry to enable a higher throughput of logs and I'll explain a bit more how we're doing that later as well as we've had some new enhancements to the advanced promotion engine which directly relates to metric intell if you're using it and we have a new Azure accm check to basically reduce the amount of checks that you would have to do previously in order to monitor your Azure environment and here's an overview of the end of life capabilities as well as Sunset so Sunset means that the capabilities are still supported until end of life but end of life has not yet approached so right now we have operator workspace um if you're using operator workspace in your organization currently by the time it is Washington it'll stop being supported so if you have any issues with the operator workspace when this is released in q1 of next year um at this point we'll no longer be supporting any requests for this as well as the event management mobile app for the timing of zanadoo which is the end of next year in Q3 of 2024 in terms of end of life capabilities which are capabilities that are just not supported anymore some of you may still be on Utah or a previous release and in that case if you're using Advanced insights Explorer by the time you pass through your Utah upgrade if you're not already there it'll no longer be supported as well as the metrics intelligence um connectors specifically for scum but we are working on a new scom connector coming soon or just in the future so keep a look out for that um and in terms of the event management mobile app we are looking to come up with a replacement for that sometime next year as well so starting off with event sync we have the now on now connector and this connector that we have come up with is a way to push and pull events from other from one service now instance to as many other service now instance as you want to this enables you to again test and evaluate features that you want to in your sub production environment for example if you want to see how exactly your events are being processed using new rules that you may not want to implement yet into your production environment or see how exactly your event processing would um react to a unpopulated cmdb in that case and you want to experiment with that this enables you to do that without having to redeploy the Integrations for all your different monitoring tools on each individual other service now instance apart from your production instance and the process is really simple for setting this up and I'll be going over this in the next few slides and also um just in terms of actually getting access to this feature you should be updating your event management store um event management connector Store app so if you're not on the latest version which came out on November 2nd so just six days ago um you won't have this feature so just keep that in mind but it's a pretty easy upgrade so I do suggest you do that so in terms of the setup for event sync we can see right here on this page and I'll be showing you a short demo right after all this but all you have to do is go into the event sync configuration list and when you do you'll be prompted when you create a new events sying configuration to input the URL the credentials Market is active and make sure to test the connection and then when you're done submitting the connection and at the point that you have all your connectors set up you can then see that there's going to be a new schedule job available in the scheduled job list where where it is called the event management event sync job and there you can change the interval or change the runtime of the specific event sync configuration that we have just introduced so you can change it to a minute which we see in the screenshot or you can change it to five minutes or whatever time you'd like to specifically and again this is the new job in the schedule jobs table as you can see in the screenshot right here and at the point that you do set this up um please trust that these are two separate instances I just didn't want to share the URLs because that's kind of weird but in the case where you do actually set up the instances we can see right here that the screenshot was actually taken at the exact same time but I just split it so it looks a bit cleaner but in the original instance where we originally set up all the connectors directly connecting to the specific instance I set up an event connector and connected it to this instance right here and at the point where I made sure to refresh both the lists we can see that the exact same alerts down to time description Source node have been transferred over to the Target instance right over here and you may notice that there's also these two alerts or sorry events that haven't been um transferred over boed to the secondary instance and that is because of the one time one minute interval so at the point when about a minute passes then these two events will start showing up in the Target instance as well but to make this a bit more clear I'll be showing you a demo in two slides from now but as a fact sheet and just a way to just get all the information that you need to be able to even use this or sell that you want to use this in your own environments we added it so that it can drive faster time to value for your organization when testing and playing with any events in your environment without having to impact your production environment and anyone who would use this could be anyone in your teams that operate and have to set up all the Integrations in your environments and to activate it again you have to activate the newest version of the event management connector in the service now store and the required role in able to be able to set up the credentials and send these alerts off or events sorry off into the target instance is that the target instance needs a user with the role of event management integration so just keep that in mind and then in terms of accessing the table for event sync it can be accessed through this line right here in case you're having issues with that and this won't require any additional licenses to your current licensing structure for iton and yeah that's about it so without further Ado let's get into a demo of event sync so now I have two instances opened um the original instance where I'll be setting up everything on the now and now connector and the target instance where I'm setting all the instances too so this is just the current events that we have coming in so starting off from the event sync configuration we first just have to have probably read the blue box if you're doing this for the first time but that being said we just need to input the instance URL and then the credentials and then once we do this we just need to test the connection to make sure that it actually is able to connect to this target instance and also make sure to mark it as active because if you don't mark it as active the configuration for the connector won't be actually running so once we have all this information and we save it it's going to look more like this where we can see all the names and the target instan is already in the specific connector and speaking about scheduled jobs now you can see that the event sync job is a new scheduled job that's available under system definition and once we click into it we can see that we can change the interval as to when exactly or how often exactly you want to be able to run this configuration the events in configuration between each of these um instances that you have set up and you can also change the run time how often it runs or if it's just a oneoff run and you can obviously manually execute it if you'd like to and then now since we've set it up um with the interval of 1 minute there's always going to be about a 1 minute leg between all these events but let's see what we have right now so again this is one instance and we've linked it to this target instance right here and in the most smooth oh okay great didn't require too much staring this time we can see that right now there haven't been really any of events that have come in on the original instance so we can see that basically exactly these three zabic events have been synced with this second instance right here where all the fields are the same including the time so time of event um description node but if I were to refresh this and now we have some new itom agent um events coming in you can see that it's still running at a 1 minute interval of synchronization because it's not yet reached the target instance because it's been less than one minute since this new event has come in or these new sets of events have come in so at the same time if you do have oh and here they all are now because it's been about a minute and at the same time if you do have actual connectors deployed on this target instance obviously all these events from this target instance will still be populated in the event table as well um so that is it for my demo of event syncs and thanks for listening to my demo that I pre-recorded I hope you didn't mind that but that basically demonstrates what exactly event sync is and how easy it is to set up and I see that we got a question in the chat um about event sync and how to set it up so in the case that you want to set up a event sync you need to ensure that the event management connector the latest version is on the instance where you are sending the alerts from so the original instance not the target instance because it just leverages an API that's existed on service now and event management for quite some time so we just need to make sure that all the capabilities are at least available on the original instance side and I will just hit answer live so I don't potentially reans answer this um question again but yeah um if you have a follow-up question to that Amy please feel free to ask again in the Q&A and I'll be sure to answer and yeah that's just a reminder for anyone else if you have any questions please feel free to put in the Q&A and I'll answer it either at the end of the session or if we're running good on time I'll answer it during each um section that I'll be going through so yeah next up we are be going to be talking about generative Ai and how we are going to be using it to inrich alerts so often right now when you get alerts in they're directly processed from your events and there can be a lot of random codes that most um operators may not be able to understand um where you likely have to be a subject matter expert in the area of what you're monitoring to necessarily understand what the code is that you're getting and what it means and how it actually impacts your system so through using generative AI we want to be able to enrich alerts to make them more comprehensible and make the description more usable for a wider array of operators who may be managing your alerts so this is enabling the shift left of support where you no longer necessarily always have to rely on the subject matter experts you're able to then empower the other levels of support to resolve these alerts earlier and without having to escalate driving up the meantime to resolution and hopefully also reducing the number of incidents that are even open as a result of receiving some Al so we can see right here in the screenshot that in our coming soon release of the phase one of generative AI we are going to first summarize the alerts with a um um improved description as well as a suggested root cause and suggested remediation actions that you can take and at the point when you read these as the operator or whoever is looking at the express list table will be able to rate the comment and tell the large language model which is also just our generative AI model if what we provided you we being the model um was actually useful in helping you resolve and close the specific alert that it was generated for and I just want to note that also the specific feature that we will be coming out with soon will be in Express list specifically so if you aren't already on Express list this may be some gentle encouragement to start trying to use it um it's very easy to set up and as long as you have alerts coming in you'll be able to already see the live alert list be populated and right now we can see that this is basically the flow of resolutions explained or just how events are processed as well as logs and metrics right now where we analyze the events coming in we're also looking at the logs and metrics and they get directly processed into alerts and through some correlation we have our multiple correlation techniques such as cmvb alert rules um alert tags and so on we then group the alerts and then we enrich the alerts with any additional information for example if you do any event field mapping or all that stuff and linking it to previous um incidents and again any potential change requests that may have impacted it so that's the current flow of the solve and in our first version of generative AI being implemented in itom health is that at the point of going from grouped alerts and alerts to enriched alerts instead of enriching it with only the information that we have within the instance itself historical information for example we're going to be using our internal generative AI model so again it's going to be an internal large language model where it'll be fed by the alerts that we have coming in and over time it'll learn and understand what issues are occurring and how exactly the model can suggest how you can resolve it and understand the root cause most effectively and at the point when you receive all this information from the model then there are user annotation so that's providing feedback to the model to learn more and improve over time so that is the first version and stay tuned to learn more about what we'll have coming out for generative AI in the future but just wanted to put this on your radar of what we will be coming up with soon for itom health and next up I will be talking about the health log analytics otherwise known as HLA 2.0 scale update so previously our architecture supported 60k logs per second but with this new architecture update we now support 240,000 which is a lot logs per second while simultaneously increasing efficiency and resilience and to do this we're now leveraging kubernetes where we have the itom Gateway which is leveraging again kubernetes where instead of directly passing the logs into a load balancer and then into the AI engine which we also call occultist we're leveraging catha as a cue in order to use all the queue up all the logs and throw them into the AI engines as there is capacity for so by being able to have multiple AI engines now and using capka as a queuing method we're able to increase the scale by fourfold or threefold sorry I think it was 80k logs per seconds previously um and by leveraging kubernetes this also improves the reliability of H in general otherwise the side where you're inputting the logs through push or pull connectors as well as the log storage and Metric base and the UI on your side will be the same but for organizations that may require this larger scale it is now something that we are able to support ourselves for customers potentially like you who need a larger scale and next up we have have the advanced promotion engine enhancements so if you don't already know what Advanced promotion engine is Advanced promotion engine is a feature of metric intelligence where you're able to set specific conditions for metrics that you have coming into your instance that should be promoted to it alerts so there are two separate types of alerts in this case there are anomaly alerts where through metric intelligence we've noticed some spikes or some unusual behavior in the typical behavior of the specific metrics of ACI that you have coming in and in the case where you know if it reaches these specific conditions and the specific an anomaly alert gets triggered then you want it to be promoted to an actual it alert so these are the typical alerts that you see in your alert list currently or if you're already using Express list you would see it in your Express list so that is what Advanced promotion engine is basically just setting up the um conditions in order to promote any of your metric anomalies to regular it alerts and currently we're looking at it from the perspective where we would always assume that the anomaly warning or the um criticality would automatically be promoted into the IT alert but now we're making it so that instead of automatically assigning the criticality and priority to the promoted it alert we're putting it in the work notes instead of putting it in the description itself as well as previously in the case when some anomaly alerts were triggered sometimes the it alert that would be promoted from the alert anomaly would then disappear at the time once it was resolved but now now we made it so that if you want to do some further investigation after the fact that an anomaly alert is resolved after it's promoted to an IT alert you can go back and that information will still be available to you as to what it alert was related to that specifically specific anomaly alert if it was open in the first place and if you are using Advanced promotion engine and you wanted to get these new features um or if you just want to start using Advanced promotion engine at all please look at the um metric intelligence Store app and make sure that you are on the newest version and that is how you can get access to Advanced promotion engine and its enhancements that have come up recently definitely something you should look into if you are using metric intelligence and last but not least I'll be talking about the accm Azure check um specifically a performance enhancement for this so previously you would have to perform multiple background checks for your Azure VMS but now with our new check that we have for accm we're able to monitor thousands of azure VMS using a single agent as opposed to running several thousand checks which is not ideal and not efficient at all and to do this we're utilizing a Azure batch API where Azure VMS can effectively be monitored and so this makes it so that um it's a lot more efficient for users who are setting up accm and you don't have to worry about going through all of your individual Azure VMS anymore and if you are more interested in the technical details um we're also able to do this by using the resource ID from cloud Discovery and again um if you want to get this new feature please update your men intelligence Store app and if while you're doing this you didn't realize that you didn't have advanced promotion engine yet it's a great time to start using it um but on that note that is it for what's new in itom for this quarter thank you all for listening um for me for the past half hour wow a half hour of me talking um I hope it was of interest to you and it was useful for you

View original source

https://www.youtube.com/watch?v=0guH8pLmUE0