Certified Implementation Specialist - Event Management (CIS-EM) Delta Exam Study Guide


Version: Maintenance Exam (Delta) 2026

 

 Audience

All Learners

Overview

Use this study guide when completing your delta exam in ServiceNow University. The content presented in this knowledge article is the exam content you will be tested on to maintain your certification. In addition, we always encourage you to review ServiceNow's Product Documentation.

Delta Exam Study Guide Content

 

New features
Mixed alert grouping

Combine CMDB-based and tag-based alert grouping strategies into cohesive groups that reduce noise, enabling faster and more effective response.

 

Mixed Grouping method combines alerts using multiple grouping strategies, such as CMDB-based grouping and tag-based grouping, into a single, cohesive group. It leverages the strengths of each strategy to reduce alert noise, improve alert correlation, and highlight the true root cause of incidents.

AIOps 360 overview dashboard

Gain actionable insights with a 360-degree dashboard that showcases product value, tracks operational efficiency, and highlights automation impact. Monitor alert handling, service health, and AIOps outcomes to drive smarter, faster decisions across IT operations.

 

The AIOps 360 Overview dashboard offers a unified view of value and performance across IT operations, helping teams track efficiency, monitor alert handling, and assess automation outcomes. It enhances visibility into AIOps impact, supports informed decisions, and drives faster, smarter operations.

 

To open the dashboard, navigate to Workspaces > Service Operations Workspace and select the AIOps Dashboards icon (AIOps Dashboards icon.), then, from the AIOps Operational drop-down menu, select AIOps 360 overview.

 

Use filters such as Date and Assignment Group to customize the dashboard view and focus on specific time periods and teams. This helps you pinpoint trends, identify areas for improvement, and make data-driven decisions tailored to your operational needs.

 

The Value Overview section highlights the overall impact of AIOps on operational efficiency. It showcases how much manual effort has been reduced through automation and intelligent alert grouping. It also reflects noise reduction levels, outage history, and overall workload savings—giving a clear picture of time and cost benefits realized.

 

The Performance Overview section focuses on how effectively alerts and incidents are being handled. It includes metrics like resolution times across groups, trends in detection and response, automation usage, and the distribution of resolution ownership. It helps identify performance gaps, track improvements, and optimize response strategies across the organization.

Mixed alert grouping in Service Operations Workspace

Choose how you want to group alerts from the Criteria Type field. Use the Related CIs option to combine CMDB-based and tag-based alert grouping.

 

Grouping of this method is most useful when alerts share common data or tags, such as a node or location. You can use fields or tags populated via an enrich automation. It’s the best way to group alerts when your CMDB or service maps are immature. This complements other grouping algorithms, including alert correlation rules, CMDB, ML, and text-based grouping. Alerts are grouped with their first match, and you can control the priority order of these algorithms via system property.

 

Alert automation also provides a simulation feature allowing you to test how many alert groups would be formed, how many are left ungrouped, and the compression rate. A higher compression rate means your team will be more productive and may be able to identify root causes faster. However, consider whether the groups are accurate, operationally correct, and assigned to the right teams. You may adjust the group criteria until you are satisfied with the resulting groups.

 

For users familiar with the classic Event Management experience, this feature offers an easier interface with improved team support for creating tag-based alert clustering definitions.

Application services for impact calculation

Filter the application services to be considered in impact calculation for focused and accurate results.

 

Impact calculation shows the magnitude of an outage on CIs, services, alerts, and alert groups. The system uses factors such as impact rules and CI relationships to calculate the severity of a generated alert. The severity appears on the impact tree, application services maps, and dashboards.

Impact calculations are available for application services alert groups. The following factors are used to calculate the overall impact of an outage.


By default, impact is calculated for all operational application services. However, the system allows you to filter impact calculation by service class or by individual application service. For more information, see Add CMDB tables or classes for impact calculation and Add application services for impact calculation.

Metric connector in Integrations Launchpad

Configure metric pull connectors to automate data retrieval and seamlessly integrate external metrics for efficient monitoring.

 

Configure metric pull connectors that require a script, connector definition, and connector instance to pull metrics from external sources. These connectors automate the data retrieval process, ensuring the seamless integration of external metrics into your system for efficient monitoring and performance analysis.

View links between alerts in new alert groups in Express List®.

Starting in version 26.9.0, investigate alert group details and visualize connections through Link View in Express List®, now available for log analytics-based alert groups and mixed alert groups.

 

Gain a better understanding of the relationships between alerts in alert groups in the Express List by using Link View. Link View offers a visual representation of the relationships between the alerts in a group.

 

When Event Management generates an alert group, Link View shows how the attributes of the alerts in the group are linked. The colored tags represent configuration items (CIs) and other environment items in relation to the alerts.

 

The information shown in Link View is available without the need for a populated Configuration Management Database (CMDB). However, when the CMDB is populated, Link View offers additional value by providing the probable cause of the alerts and the service that the alert group impacts.

Anomaly information for log analytic based alerts and metric intelligence alerts in preview panel in Express List.

Starting in version 26.9.0, review visualizations for anomaly information in log analytic-based alerts and metric intelligence alerts in the preview panel in Express List[var.express-reg-tm].

 

View visualizations for Health Log Analytics anomaly alerts on the Express List preview panel, to identify periods of behavior that deviate from expected ranges.

Configure new property for automatic resume of the live list updates following a pause, and configure time ranges in Express List.

Starting in version 26.9.0, admins can configure the amount of time until the live list updates resume after being paused in Express List. Admins can also customize the time range options displayed in Express List, such as the default time range.

 

Default time ranges can be defined by your administrator using the system property sn_sow_em.evt_mgmt.express_list.all_time_days.

MID Server support for running synthetic monitors

Run synthetic monitors from your MID Server.

 

Synthetic monitors can be hosted from:

 

You can create as many locations as needed, but you must have at least one location to create a synthetic monitor.

HTTP endpoint creation directly in synthetic monitoring

Create HTTP endpoints for your monitors without leaving the SOW.

Support groups for synthetic monitor-based alerts

Assign a support group to a monitor, and then any raised alerts follow the associated alert automation rules.

Deprecations

NOTE: Feedback or comments should address article content only; for access issues or other support needs, please submit a ServiceNow University case for faster resolution. 

Back to Top