Event rules Use event rules to generate alerts for tracking and remediation. Event rules are stored in the Event Rule [em_match_rule] table. Configure and customize event rules to manage events and alert generation. Event rules do not change the event records in the Event table. Changes to event data are stored in the ServiceNow instance memory. Use the Event rule designer to create and configure event rules. You can use the default event rules or event rules that you have created to: Apply an event rule filter to determine whether the rule applies to an event. Apply a transform with Event Match Fields and optional Event Compose Fields to format the alert text. Apply a threshold to create custom alerts for rapidly recurring events. Automatically create or close alerts. Bind alerts to CI information from the CMDB. Note: Only one rule is applied to each event, according to the filter applied to the events. Multiple event rules do not apply to an event. Create or edit an event ruleYou can create event rules to generate alerts for tracking and remediation. Use event input informationThe Event Input pane that is included in the steps to create an event rule provides a reference to the information that you can use when configuring an event rule. In the Transform and compose alert output section, you can also drag the information into the required fields to customize alert content.Filter event rulesDefine a filter to restrict to which events the event rule must apply. Configure the filter by providing a set of conditions that each event must match to be either excluded or included from applying to the event rule. Find events that are not matched to rulesFind events that are not matched to any rules, and determine if it is necessary to create event rules to manage them.View event rulesYou can view all event rules on the Event Rules list.Ignore an eventYou can configure an event rule to ignore extraneous events and prevent alert generation.Find rules that were applied to events or alertsView the rules that were applied to events and alerts to confirm how events are processed.Configure an event rule to customize alert contentYou can configure an event rule to customize alert content. You can customize the order of the fields and select which fields display. The fields in the left-hand workarea of the Transform and compose alert output section of an event rule are the fields that appear in the generated alert.Set a threshold to suppress alert generationIf Event Management receives multiple events for a device in a short period, it might indicate a serious condition, so you might want an alert to be generated. However, if events for a device are received at longer intervals, the condition might not be serious, so you might want to suppress alert generation. The threshold is the rate where Event Management generates an alert. Alert binding to CIs with event rulesWhen alerts are associated with CIs, the task of remediation is simplified. During alert generation, Event Management uses event rules and other mechanisms to automatically bind alerts to CI information from the CMDB. For tracking purposes and remediation, the alert shows information about the CI that caused the event.Custom alert fieldsYou can populate custom alert fields with data contained in Additional information field of the event. View patterns for event group creationEvent groups are sets of events that do not have a matching event rule. You can view the patterns in a group of events to learn the impact of creating a rule based on the event source and description patterns.