Skip to main content
Version: 2.0.0

Create Incident Tickets

Creating an incident ticket is possible through the service portal and agent interface.

Depending on the role and authority of users in the system, they have access to different options for creating incidents:

Create an incident via the Self-Service Portal

tip

This procedure is available to all end users.

On the Self-Service Portal, you can create an incident ticket both manually and via the AI Assistant if it is configured.

Create an incident manually


To create an incident ticket, complete the following steps:

  1. Navigate to your Self-Service Portal main page.
  2. Click Report an incident and fill in the incident form fields.
  3. Click Save to send the ticket.
Incident form fields
FieldMandatoryDescription
UrgencyY

Specify the urgency of the request. Typically, it is evaluated based on the time remaining until the incident impacts the business.

See the Priority Matrix article to learn more.

SubjectYAdd a brief description of the incident. If the subject length is over 100 characters, the characters exceeding this limit will be cut off.
DescriptionNAdd a detailed description of the incident.
Steps to reproduceNSpecify the steps to reproduce the incident.

The caller is also asked to contact the service desk by phone if their question is urgent. The phone number displayed here is specified in the itsm.notification.contact.phone system property.

You can attach some files by using the attachment window. To add files, drag them to the attachment window, or click Upload from your device and select them on your device.

After saving the form, you will be redirected to the incident page.

You can track the work process on the Tickets page. To open the record of the incident, complete the following steps:

  1. In the header, navigate to ActivitiesTickets.
  2. Click Incidents on the left.
  3. Check the state of the created incident.

You can also view more information about the incident by clicking its number.

Create an incident via the AI Assistant


The AI Assistant offers to create an incident ticket if:

  • it categorized the user's message as an incident and did not find any relevant information among the known errors, articles, and announcements existing in the system, or
  • after it provided the relevant information, the user replied that it did not resolve their issue.

The user can also request the AI Assistant to create an incident ticket.

The AI Assistant fills out the incident's Subject, Description, Steps to reproduce, and Urgency based on the chat context, including the user's replies to its additional questions. Before the form is sent, all of its fields can be edited. Sending the ticket closes the chat.

Create an incident via the agent interface

tip

Role required: ITSM_agent or admin.

To create an incident ticket, complete the following steps:

  1. Navigate to Incident ManagementNew.
  2. Fill in the fields.
  3. Click Save or Save and exit to apply the changes.

Incident form fields

The incident number has the INCXXXXXXX format and is populated automatically.

General tab
FieldMandatoryDescription
ServiceYSpecify the service affected by the incident.

In the dropdown list, you can select from the services whose Service type is not Request. Clicking the icon opens the Services record picker, which has a filter with the corresponding condition. You can remove this condition to display all the services and select the one you need.

Related CIsNSpecify the related configuration items affected by the incident.
CallerYSpecify the originator of the incident.
Service consumerY/NSpecify the organization unit that is the service consumer. Learn more in the Task article.

The field is mandatory if the Service is specified.

The field is hidden from the form if the Infrastructure incident checkbox is selected.

Caller is consumerNSelect this checkbox if the Caller is the Service consumer. Learn more in the Task article.

The field is hidden from the form if the Infrastructure incident checkbox is selected.

CompanyNSpecify the company to which the incident is related.
UrgencyY

Specify the urgency of the incident. Typically, it is evaluated based on the time remaining until the incident impacts the business.

See the Priority Matrix article to learn more.

If the incident is a child incident, the Urgency field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

The field is cleared in the child incident if its Parent incident field gets cleared.

ImpactY/N

Measure the impact caused by the incident on the business processes.

The field is read-only if the itsm.itsm_incident.impact_matrix_is_enabled system property is set to true. In this case, the Impact is determined based on the Impact Matrix and is not a mandatory field.

If the incident is a child incident, the Impact field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

The field gets cleared in the child incident if its Parent incident field gets cleared. If the child incident is not an infrastructure one, its Impact in this case may be determined based on the Impact Matrix provided that all the values necessary for the calculation are specified. To enable this, the matrix should be configured.

PriorityN

Identifies the importance of the incident. This field is populated automatically based on the values of the Impact and Urgency fields.

See the Priority Matrix article to learn more.

If the incident is a child incident, the Priority field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

The field is cleared in the child incident if its Parent incident field gets cleared.

Event scopeYSpecify how widespread the incident's impact has been on the system, infrastructure, or users, depending on your organizational specifics. Available options:
  • Local
  • Global

The field is displayed and used for determining the Impact based on the Impact Matrix if the itsm.itsm_incident.impact_matrix_is_enabled system property is set to true.

Users with the itsm_agent role can edit the field on incident records in any state except Closed.

Service outage extentYSpecify the extent of the unplanned reduction in the quality of the provided service. Available options:
  • Partial/Degradation
  • Full

The field is displayed and used for determining the Impact based on the Impact Matrix if the itsm.itsm_incident.impact_matrix_is_enabled system property is set to true.

Users with the itsm_agent role can edit the field on incident records in any state except Closed.

SubjectYAdd a brief description of the incident. Once the incident is created, this field gets hidden.
DescriptionNAdd a detailed description of the incident.
Steps to reproduceNSpecify the steps to reproduce the incident.
ScreenshotNUpload screenshots supporting the incident if there are any.
Assignment groupY/N

Specify the group assigned to work on the incident.

This field is non-mandatory if the Assigned user field is filled in or the State is In progress, Completed, or Closed.

If the incident is a child incident and the itsm.itsm_incident.map_assigned_group_and_user_to_children system property is enabled, the Assignment group field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

The field is cleared in the child incident if its Parent incident field gets cleared.

There is a dependency between the Assigned user and Assignment group fields. See the Auto Assignment article to learn more.

Assigned userY/N

Specify the user assigned to work on the incident.

This field is non-mandatory if the Assignment group field is filled in and the State is not In progress.

To reassign a user or a group, use the Reassign button in the upper-right corner of the page or click the magnifier icon next to the Assigned user field and specify the new assignee. As a result, the incident state changes to Assigned.

If the incident is a child incident and the itsm.itsm_incident.map_assigned_group_and_user_to_children system property is enabled, the Assigned user field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

The field is cleared in the child incident if its Parent incident field gets cleared.

There is a dependency between the Assigned user and Assignment group fields. See the Auto Assignment article to learn more.

Infrastructure incidentN

Select this checkbox to mark the incident as an infrastructure one.

Once the incident is created, this field becomes read-only.

Attention requiredNSelect this checkbox to notify the line manager of the assigned group or user.
StateN

Specify the work state and progress of the incident.

If the incident is a child incident, the State field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident.

A child incident's state changes to Registered if its Parent incident field gets cleared.

Resumption of workY/N

Indicate the date and time when the work on the incident must be resumed.

The field appears when the incident is in the Postponed state. If the record is saved in any other state, the field gets cleared and hidden from the form.

The field is not available when creating an incident because the Postponed state cannot be set at that stage.

External companyY/N

Specify the company that works on the incident task externally.

The field appears on incidents in the External processing state and shows the last saved value.

When the incident enters any state other than External processing, the field's value is saved for later use, the field becomes non-mandatory and gets hidden from the form.

The field is not available when creating an incident because the External processing state cannot be set at that stage.

External taskY/N

Specify a task to be processed by the external company.

The field appears on incidents in the External processing state and shows the last saved value.

When the incident enters any state other than External processing, the field's value is saved for later use, the field becomes non-mandatory and gets hidden from the form.

The field is not available when creating an incident because the External processing state cannot be set at that stage.

DiscussionN/YEnter a comment with additional information about the incident for the caller. After the incident is created, this comment will be displayed on the Discussion tab of the Activity Feed. It will be possible to add more comments there.

This field may become mandatory when changing the incident's state.

Work notesN/YAdd any work notes that may be useful to you or other agents working on the incident. After the incident is created, this comment will be displayed on the Work notes tab of the Activity Feed. It will be possible to add more comments there.

This field may become mandatory when changing the incident's state.

Followers listNThis field is populated automatically with a list of users who follow the incident for tracking the updates. It is read-only for any users without the ITSM_agent or admin roles.
SLA BreachedNThis field is hidden by default. When the time set in the SLA indication expires, the value of the field changes from false to true.
Contact typeNThis field is hidden by default.

Select the source from which the request is received. Available options:

  • Phone
  • Email
  • Self-service

Use this tab to create relationships between incidents and other types of records. See Create Records Related to Incidents to learn more.

Note that if the incident is a child incident, the information from the parent infrastructure incident is transferred to the corresponding fields of the General tab in the current incident form. Some related records from the parent incident are also automatically added to the corresponding fields of its child incidents.

Closure Information tab

The Closure Information tab appears and becomes mandatory when the incident state is Completed or Closed. See Process Incidents to learn more.

The External Specification and Internal Specification related lists contain Knowledge Base articles with the same Service as in the incident, for quick access to the necessary instructions. Learn more in the Service Specifications article.

Access to the form fields


The read or update access to certain fields of a record can vary depending on the current user's roles.

  • The users with the ITSM_agent or incident_manager roles, other than the creator of the incident or the assigned user, can:
    • View the record.
    • Submit Work notes and Discussion comments in all states of the incident other than Closed.
    • Edit the State, Assignment group, and Assigned user field values in all states of the incident. The Work notes field becomes mandatory in this case.
    • Edit the Followers list field value.
  • The caller can:
    • View the record, except for the Work notes field.
    • Submit Discussion comments.