IT Service Management

Incident Management

Incident Management is the process that kicks in when something breaks or stops working in your IT environment. It's used by help desk agents, IT support teams, and service managers to log problems, figure out who should fix them, track progress, and make sure they get resolved quickly. Every time an employee reports that email is down, a server crashes, or an application won't load, Incident Management provides the framework to handle it systematically instead of through frantic phone calls and scattered emails. In ServiceNow, Incident Management becomes the central hub where all service disruptions get tracked from start to finish. It automatically assigns tickets based on your rules, escalates urgent issues, tracks time against service level agreements, and gives everyone visibility into what's broken and who's working on it. Once in place, your IT team can respond faster to outages, spot recurring problems, and prove they're meeting their commitments to the business.

Key Capabilities

Automatic ticket creation and routing

When someone reports a problem via email, phone, or self-service portal, ServiceNow creates an incident ticket and routes it to the right team automatically. This eliminates the manual step of figuring out who should handle what type of issue.

Priority and urgency calculation

The system automatically calculates how critical an incident is based on who's affected and what service is impacted. High-priority incidents get immediate attention while routine requests follow normal queues.

Service level agreement tracking

Built-in timers track how long incidents take to resolve against your promised response times. You get early warnings when tickets are at risk of missing their deadlines, so you can escalate before customers start complaining.

Major incident management workflows

When something big breaks that affects many users, special workflows kick in to notify executives, coordinate response teams, and manage communications. This prevents chaos during your worst outages.

Alert correlation from monitoring tools

Server monitoring alerts and application errors automatically create incident tickets instead of just sending emails that get lost. Multiple alerts about the same problem get grouped together so you're not working the same issue twice.

Knowledge base integration

Agents can search for solutions while working on tickets, and successful resolutions get captured as knowledge articles. Over time, your team builds a searchable library of fixes for common problems.

How It Works

An incident starts when someone reports a problem or when a monitoring system detects an issue and automatically creates a ticket. ServiceNow looks at what's broken and who's affected, then calculates priority and assigns it to the appropriate support team based on your assignment rules. The assigned technician gets the ticket, works on resolving it, and updates the ticket with their progress and final solution. Throughout this process, the system tracks time against service level agreements, sends notifications to keep people informed, and captures the resolution details for future reference.

Who Uses It and How

Healthcare system

When their electronic medical records system goes down, ServiceNow automatically creates a major incident, notifies the CIO and application support team within minutes, and starts a conference bridge for coordinating the response. All communication and status updates flow through the incident ticket so there's a complete record of what happened.

Result: They reduced average resolution time for critical outages from 4 hours to 90 minutes.

Financial services company

Trading floor users report application slowness by calling the help desk, which logs incidents that get automatically assigned to the right application team based on the affected system. The team can see all related incidents in one view to identify if it's a widespread issue or isolated problems.

Result: They now catch and resolve performance issues before they impact trading operations 80% of the time.

Manufacturing plant

When production line systems fail, plant floor supervisors use mobile devices to report incidents that immediately notify both IT and operational technology teams. The system tracks which production lines are affected and calculates business impact in real-time.

Result: They reduced average downtime per incident from 45 minutes to 15 minutes by improving response coordination.

University IT department

Students and faculty report issues through an online portal that creates incidents automatically categorized by service type. During busy periods like registration, the system identifies when multiple people report the same problem and creates a single major incident instead of dozens of duplicate tickets.

Result: They handle 300% more incidents during peak periods with the same staff size.

Sourdough
Chrome Extension

Sourdough: ServiceNow Monitoring and Analytics

A Chrome extension for ServiceNow Admins and Developers with essential tools, analytics, graphs and monitoring features.

Instance HealthGraphs & ChartsAPI HealthDeveloper ToolsQuick SearchInstance Switcher
Add to Chrome

Free to install. Pro $5/month after a 14-day no-card trial.
Pro requires the ServiceNow admin role. Upgrade inside the extension.

Overview
Tasks
CMDB
API
Metrics
Monitor
Internals
Instance:sourdoughdev·Version:Yokohama
Instance StateONLINE
System StatusFully Operational
Session Timeout90 minutes
Logged-In Sessions2 (20 active)
Build Nameyokohama-12-18-2024_p1
IP Address10.159.128.43
Instance HealthHealth Score: 90%
🔥 5dSourdough (Chrome Plugin)Dark Mode

Implementation: What to Know

Plan to involve your help desk team, major application support groups, and whoever manages your monitoring tools from day one since they'll be the primary users. A typical rollout takes 3-6 months depending on how many integrations you need with existing tools and how much you want to customize assignment rules. You'll need an updated list of your services, support groups, and current service level commitments before you start configuring anything. Most implementations stall when teams try to recreate their exact current process instead of adapting to ServiceNow's standard workflow, which usually works better than whatever you're doing now.

Common Use Cases

Help desk agent resolving a password reset request

An employee calls saying they can't log into their laptop after returning from vacation. The agent creates an incident ticket, sees similar recent issues in the knowledge base, and follows the documented steps to reset the password and unlock the account.

Server monitoring alert creating an automatic incident

A database server starts running out of disk space at 2 AM and sends an alert to ServiceNow. The system creates a high-priority incident and pages the database team, who can start working on it before users even notice a problem.

Major incident response for email outage

The corporate email system goes down affecting 5000 users. ServiceNow automatically escalates this as a major incident, creates a war room, notifies executives, and coordinates the response between network, server, and application teams until service is restored.

Manager tracking team performance against service commitments

An IT manager uses incident reports to see that their team is missing response time targets for printer issues. They can drill down to see which technicians need help and which locations have the most problems.

Recurring problem identification and improvement

The same application keeps having memory issues every few weeks. ServiceNow's reporting shows the pattern, and the team creates a problem record to investigate the root cause and implement a permanent fix.

Key Tables

Best Practices

  • Set up your assignment rules to route 90% of incidents automatically, but always have a default catch-all group so nothing gets lost in limbo
  • Create separate categories for requests versus actual broken things, because a password reset should not be treated the same as a server outage
  • Train your help desk to update incidents with what they actually did to fix things, not just mark them resolved, so other agents can learn from the solutions
  • Use business services in your configuration management database to calculate impact automatically rather than asking agents to guess how important something is
  • Set up major incident thresholds based on number of affected users or specific critical services, not just severity levels that people interpret differently
  • Build escalation rules that notify managers when incidents sit too long, but give technicians reasonable time to work before the escalation kicks in

Common Pitfalls

Creating too many custom fields that agents have to fill out when logging incidents

Start with the out-of-the-box fields and only add customs ones after you prove you actually need the data for reporting or routing.

Making every incident high priority because everything feels urgent

Define clear priority criteria based on business impact and stick to them, even when managers complain about their favorite application being marked as low priority.

Setting up assignment rules that create loops where incidents bounce between groups

Test your assignment rules with real scenarios and always designate one group as the final owner who cannot reassign without manager approval.

Requiring too much information upfront that prevents people from reporting incidents quickly

Let people create incidents with just a short description, then gather additional details during the resolution process when needed.

Not training end users how to report incidents properly through self-service

Create simple how-to guides and promote the self-service portal actively, because phone calls will always be more expensive than online ticket submission.

Frequently Asked Questions

What's the difference between an incident and a service request?

An incident is something broken that needs to be fixed, like email being down or an application crashing. A service request is asking for something new or different, like requesting software installation or access to a system. They follow different workflows because fixing something broken is usually more urgent than fulfilling a request.

Do I need the configuration management database set up before implementing Incident Management?

You can start without it, but you'll miss out on automatic impact calculation and service mapping features. At minimum, load your key business services and applications into the configuration management database so ServiceNow can help determine incident priority and routing.

How do major incidents work differently from regular incidents?

Major incidents follow special workflows that immediately notify executives, create communication plans, and coordinate multiple support teams. They're designed for situations where lots of users are affected or critical business services are down. Regular incidents just go to the assigned support group.

Can incidents be created automatically from monitoring tools?

Yes, ServiceNow integrates with most monitoring systems to create incidents automatically when alerts fire. The system can also correlate multiple alerts about the same problem into a single incident, so you don't end up working duplicate tickets.

What happens if an incident misses its service level agreement deadline?

ServiceNow tracks all service level agreement breaches automatically and can send notifications to managers or escalate the incident to senior staff. You get reports showing which incidents missed their targets and why, so you can identify process improvements.

How do I prevent duplicate incidents when multiple people report the same problem?

Use ServiceNow's duplicate detection rules that compare new incidents against recent ones based on similar descriptions or affected services. You can also train your help desk to search for existing incidents before creating new ones.

Can users track the status of their reported incidents?

Yes, users get email notifications when their incidents are updated, and they can log into the self-service portal to see current status and any work notes the technician has added. This reduces follow-up calls asking for status updates.

Related Modules

Test Your Knowledge

Quick 3-question quiz — see how your ServiceNow skills stack up.

Question 1 of 3Performance

A list view on a table with millions of records is slow. Best fix?

Select an answer to continue