Learn about Now Assist for ITOM - our Generative AI Offering
so hi everyone thank you for joining me on my webinar today I will be covering learn about nasis for itom and just to introduce myself my name is Victoria low and I am one of the outbound product managers for itom and I specifically focus on AI Ops so today I will be presenting to you and I have Jason Smith also on the call today to help support the webinar through Q&A so if you have any questions just to ensure that they get answered or at least we can keep track of them if you could please put them in the Q&A section of the zoom webinar we would really appreciate it so let's get started so first off I want to put in a safe harbor notice for any forward looking statements I may have because I may slip up and mention some things that are more forward looking that I should and again if if I do happen to say something that's a bit more forward-looking they're still based off of what I know best at this moment and anything that I can say may come in the future still may change so please just keep that in mind throughout this presentation and in the case where you like joining these webinars and you're interested in joining future webinars like the learn about what's new in itom AI Ops or what's new in itom visibility for the xanado do Q3 releases you can scan this QR code right here or access the same page through this link that I'm posting in the chat right now so that you can see all the other webinars that are available for itom as well as the other product areas as well and some general housekeeping before I get started with the actual presentation is that we've saved time at the end as in I have saved time in the end for Q&A but otherwise um if we do have time throughout the presentation I will be looking at the Q&A section as well to try to answer any questions on the Fly that would relate to what I'm showing in the moment as well as this presentation will be recorded and shared online on the service now Community YouTube page and there also be a post event survey after this webinar so if you could please fill that out we would really appreciate it as well now for the agenda today I will be covering what is now assist in general then I will be going more into depth about what is now sis for itom and the current capabilities as of the August store release which just happened a week ago and I will show you a demo of our current capabilities of alert analysis and what's next well that's pretty mysterious and you'll have to stick to the end to learn more um then I'll also be providing some resources to learn more including some blogs some articles and some documentation that you could look at if you're interested in learning more and then like I said there's time at the end for Q&A so please put your questions in the Q&A module in Zoom otherwise we will wait till the end to answer them either live or through the chat so for any of you who may not know yet and hopefully do already know but in case you don't what is nowy so nowy is how service noun fuses AI into every corner of your business across it which includes itom HR customer and app delivery and automation to help maximize productivity and creativity across developers and admins operators analysts and business owners and most importantly your customers and employees and these capabilities are already available to you today and I will be talking today specifically about the itom capabilities for nowy obviously and now we understand that building your own gen capabilities can be costly and intensive before having the outcomes that you even want but service now is building geni into our own platform and products to help you realize value faster for Gen and with NIS for service now you can get your own specific package configure it and deploy your desired capabilities as needed this makes it so much easier for you to get to Value quicker with AI in days or weeks instead of months or years and AI as you know is only as good as the platform it's built on which is why service now's approach to ai ai starts with our platform that many of you are already familiar with now here are some resources also if you'd like to learn a bit more about Now assistant general and I will put them in the chat again so that was just a quick overview on what nowy is if you weren't already aware but now I will go into more about what nowy for iom is looking like in Q3 of 2024 so so our first capability for analysis for itom is alert analysis it is our way of helping operators understand alerts faster with the help of generative AI using the now llm service where we provide a briefing of the alert itself as well as a further analysis of the alert making rather hard to understand alert descriptions easier to understand through the brief briefing through a bullet pointed summary of what exactly is happening in the alert and then a further analysis of the alert providing you probable root cause information as well as potential remediation actions that you can take in order to fix the issue that's being raised and we are not only including this as part of the operator experience but we're also extending it beyond the alert making it available for any incidents that are open directly from alerts so that the alert analysis that has been triggered can be shown in both the alert form itself and incident form itself and we even further provide even more information for alert groups where we're not only looking at the individual alert at hand but also analyzing each of the individual alerts that have been grouped as part of the alert group itself and I'll talk a bit more about that in my slides coming up and if you're curious about the timeline for analysis for itom specifically looking at the aops capabilities we currently have or well we're currently at Q3 right over here but prior to this we first release and went GA with alert analysis in q1 of 2024 where we first looked at summarizing the individual alerts themselves as well as providing the analysis that I mentioned already and in Q2 of our early schedule so back in June we then released the enhancement for alert group simplification so then we were able to provide even further analysis taking into account all the individual alerts within an alert group making it easier for you to understand the impact of an alert group without manually having to analyze each and every single one of those alerts that have been grouped whether it's two alerts three alerts maybe even like 10 alerts that could be a lot for you to do and drive up the time to meantime to resolution which is not ideal and then most recently just about a week ago on August 1st we came out with our Q3 store release of alert analysis which supports the alert analysis information on the incident forms themselves so reduces the switching between the two forms making it a lot easier for users to get the power of alert analysis while still using incident forms if that's what they were using and going more into depth about each of these features we can see here that in this alert analysis in our q1 version of this is that we're focused on just empowering The Operators making it easier for them to deal with issues on their own and not making them so dependent whether they're less experienced or maybe just new to the team on other people on their team in order for them to acquire the knowledge that a subject matter expert would otherwise have but now they have that knowledge at their fingertips through alert analysis making it easier for them to learn while on the job while other users and their other teammates can stay focused on their own responsibilities and as a result everyone's happy and you can also resolve issues a lot faster with all this information whether you are experienced or maybe you are less experienced as well because sometimes there could be a new alert that an experienced operator has never seen an alert analysis could be something that could come in very handy for them in those situations not requiring them to go to Google for example or some other search engine to try troubleshooting on the Fly and going on maybe an endless search of figuring out what the issue may be because it may be new to them and then in the Q2 release we can see now that the alert analysis has gotten a lot bigger between these two slides and that is because for the alert analysis of alert groups we're taking all the contextual information of all the alerts in our group as well as sending any relevant information any other relevant information as to why the groups were grouped together whether it's cmdb tag based or HLA based alert groups as well as the relevant CI information of each of those individual alerts um as well as impacted Services probable root cause information as well as the individual alert descriptions of each of those group um of each of those alerts in that group and we're sending all this information to our llm so that I can understand all the contextual information of the order of which these alerts were opened together and what that could signify as a result of those alerts being ordered open in that specific order as well as greater contextual impact on what has been impacted as a result of this alert group and then in the analysis itself we still provide probable root cause but powered by the greater contextual knowledge of the cmdb through the CIS and impacted Services providing you a more robust analysis of the alert group as opposed to trying to analyze each of the individual alerts in this group and trying to put it all together yourself this provides you a lot more information in just a click of a button versus having to take a lot more time to analyze all these individual alerts which could otherwise drive more impact to your business with a longer outage or longer downtime which is what you ultimately do not want and if in the Q3 store release that's just come out in August 1st we started supporting alert analysis information to be available on the incident forms as well where you can not only have an incident open directly from an alert with now assis automatically triggered you're also able to trigger an alert analysis prior and then open an alert I mean open an incident later and still have that same information populated in the incident from the alert itself with the alert analysis so whether you work from alerts or you work from incidents or you work with both we are reducing the clicks between the two forms to improve the operator experience in another way where you can easily access all the information from alert analysis without having to go back to the alert form itself or go back to express list to gather all the information at hand and this can also be configured in the alert management rules itself I'll be showing that to you in the demo but out of the box when you have alert analysis through analysis for itom this is automatically active as an alert Rule now I'll be going over the general facts of alert analysis that are true as of Q3 of 2024 for so these are very subject to change over time but this is what's most up to date right now so as of today alert analysis is supported only in English for the alert analysis generation as for data security the exchanges of data are encrypted and any data in transit is protected with TLS 1.2 and the input and output data is not cached or stored on the regional data center the data is used for training the now llm service with personally identifying information stripped prior to the training using that data but this can also be opted out of and Analysis for itom as a feature itself is available through the store app now just for it operations management but you must be properly licensed for this before you can install it from the store and for technical information the llm needed for anasis for itom is provided by the service now llm service so you do not need to have your own llm in order to use this capability and for the newest version of nasus for itom the requirements are currently Washington patch 4 or zanado do once it is released in September but you can also see the requirements for earlier releases of nais for itom in the store listing if you'd like to see that as well now if you would like to use nysis for itom it's going to be available through the itom Pro Plus or Enterprise skes or I sorry I mean Enterprise Plus skes which requires the existing licensing for either iton professional or itom Enterprise as well sorry um and how do assists work so I just want to give a quick overview on how Assist work specifically for analysis for itom as of today so for alert analysis each analysis consumes one assist per analysis so in the case where you may be refreshing an alert analysis which would generate a new alert analysis sorry I'm saying alert analysis a lot that would consume another assist so that is how um the assists are relevant right now for analysis for ION with respect to alert analysis as of Q3 of 2024 so that's just some general information on the capabilities and the fact sheet for analysis for iom specifically alert analysis because that is the only capability available right now and please put any questions again if you have them in the Q&A but for now I will move on to the demo portion of this webinar now we are in the service operations workspace because the service operations workspace is the only place that you can trigger alert and analysis for alerts specifically you can trigger alert analysis in Express list which is a live alert list by clicking any of the alerts and having the side panel open up and then clicking analyze to analyze whatever alert that you'd like to analyze here we can see after I pressed analyze there is a briefing on the alert itself as well as an analysis providing more information as to the problem root cause of the alert as well as future actions you can take in order to remediate or prevent this issue from happening again and then in the case if you already in an alert and you want to see more information in the alert record itself you can also analyze the alert directly from within the alert form see here here we can see a briefing for the specific alert as well and a further analysis of the alert and so far I have only shown you the analysis of individual alerts but for grouped alerts you can get a much more robust analysis because it not only considers the alert descriptions of all the alerts that have been grouped together but it also considers all the impacted Services CIS as well as contextual information on the alerts that have been grouped together such as the timing of the alerts being opened as well now that I've pressed analyze you can see a very robust analysis of this alert group and easily I can expand the side panel so that it's easier for me to read the summary as well as analysis and here we can see a detailed summary considering all the information from all six of the alerts that have been grouped together including what CIS have been impacted in what way the fact that some services are not running on the host and examples of the services that aren't running and the contextual information as to how all the alerts were triggered within a 5 minute Spin and the analysis provides more information as to the probable root cause of all these alerts being grouped together then followed up by more information on the potential cause and the next steps to take in order to resolve the issue being raised by this entire alert group and so this alert analysis of a group of alerts is extremely important because it allows you to more quickly understand the impact of the alert group without having to manually analyze each of the individual alerts to understand the impact of each single alert that has been grouped together now in the case where you haven't yet analyzed a group but you know that you want to create an incident directly from it you can easily create an incident with nysis for itom by clicking this remediation action right here so now I have the option to run the remediation action and all I have to do is Click run and as a result of this we can see that an incident will be opened from this alert with automatic alert analysis triggered for this incident and so now you can see here in the incident form that the summary has been populated with a analysis is generated by alert analysis providing the information about a briefing of the alert and then the analysis in the description itself now this information being available in both the alert form and incident form reduces switching between the two forms streamlining the analysis process whether you're working from an incident standpoint or an alert standpoint and if you would like to activate or deactivate the ability to auto automatically trigger analysis for when opening an incident you can do so in the alert management rules and here we can see the new alert management rule that is created out of the box when you have now assis for itom which will be active as default but you can easily deactivate it by unchecking this box right here and clicking up update and that wraps up my demo of analysis for itom alert analysis now I'll be going back to my presentation so thanks for watching that quick presentation I also just realized that in case any of you may not be familiar with event management in general or how service now works with itom AI Ops I just also want to give a quick overview on the alert group simplification and go a bit more into depth about this topic so for alert group simplification alert groups are created through various methods such as in this context cmdb based grouping so relating CIS tag based grouping so the alert tags that can be created in order to enrich alerts further with more information and as well as HLA alert groups which is alert grouping that can be created through correlation identified through health log analytics which is avail through itom aops Enterprise SK so the alerts that have been grouped together have been automatically grouped together through understanding the correlation between these whether it may have been rules themselves or understanding the relationships between these alerts through the related CIS or the rules that you could have created in order to automatically group together alerts that have similar tags for example as well and using all this information these groups were automatically created through event management and these weren't manually done so that I did not have to manually select all these alerts themselves and so as a result of this and as a result of the grouping it further reduces the noise in the express list so that instead of seeing five alerts or even 403 alerts that are related but you may not know it they've all been automatically grouped together grouped together under a primary alert so that you can easily understand the alerts and not be flooded with alerts that are all related to each other when they could have easily been correlated and grouped together to reduce that noise providing a lot easier and of experience for operators to analyze alerts in general so that's just a quick overview on that so in terms of the alert group simplification using these alert groups specifically cmdb based alert groups tag based alert groups or HLA based alert groups instead of having to analyze each of these individual alerts yourself while whether it's manually or triggering alert analysis for each of them you can just use the primary alert that was created in order to group all the real alerts and run the alert analysis on that to get all the information generated from using all the information from the IND individual alerts that have been grouped together right here so instead of having an alert analysis trigger for each one of these five in this case we just had to trigger one and it pulled all the information and sent it all to the llm so that I could understand what is happening in the situation without wasting more of your time and in terms of whether alert analysis is available in an inst ENT if it was not created from an alert it would not be because there would be no link between alert alerts themselves which are part of itom versus itsm which is what deals with incidents themselves because these are two separate products so it have to be created from the alert in order to get information from alert analysis which can only be generated off alerts themselves and in terms of what's next so I showed you what has come out in q1 Q2 and Q3 of 2024 so far and you may be wondering what are we going to be releasing next what maybe we're releasing for some of our other product areas in itom for nowy and while I cannot share those with you on this call because I cannot speak about road map at this time we do speak about road map in our upcoming workshops that we have coming so we have several workshops coming up very soon one next week on August 15th in Denver in the US and we have several workshops coming up in Europe as well as one more in Canada in October um the date specifically is to be determined for that still but I will provide the links right here for you to learn more about these workshops if you may want to register as a customer or if you also want to sign up for the what's new webinar that we have coming up um towards the end of the year actually no not towards the end of the year um in the later half of September where we'll cover what's new not only in itom AI Ops but we'll also be covering what's new in other product areas like visibility Cloud accelerate 2 you can easily sign up for those webinars as well and we'll also be hosting this specific webinar again for times that are better suited to APAC so if you want to share it with your team members who may be in the Asia region or any other region Pacific region as well as well as we will also be hosting a session in Japanese in case you wanted to um show this to any of your team members who may primarily speak Japanese which would be very useful to them so all that information is available here and in terms of resources to learn more I have written several blog articles explaining much of what I've talked about today in blog article format instead of listening to my voice so I will be pasting all these resources for the product documentation the FAQ for analysis for itom getting started how to set up analysis for itom as well as the store listing for analysis for itom itself but in the case where you are interested in learning more and getting more experience with nysis for iom as a customer please speak to your account teams to learn more about that because I unfortunately cannot do that on this call today but here somewhere where you can get started to learn more before you speak to your account teams if you want to go about it in that way and in terms of content for today that wraps up my presentation please feel free to stay on the call if you have any more questions um otherwise thank you for attending and I hope you have a great day or night wherever you may be
https://www.youtube.com/watch?v=awzYzNmklIA