Create Infrastructure Incidents
Role required: ITSM_agent or admin.
To create an infrastructure incident, complete the following steps:
- Navigate to Incident Management → New.
- Fill in the fields. Ensure that you select the Infrastructure incident checkbox.
- Click Save or Save and exit to apply the changes.
Incident form fields
The incident number has the INCXXXXXXX format and is populated automatically.
General tab
| Field | Mandatory | Description |
|---|---|---|
| Service | Y | Specify the service affected by the incident. In the dropdown list, you can select from the services whose Service type is not Request. Clicking the icon opens the Services record picker, which has a filter with the corresponding condition. You can remove this condition to display all the services and select the one you need. |
| Related CIs | N | Specify the related configuration items affected by the incident. |
| Caller | Y/N | Specify the originator of the incident. For infrastructure incidents created both manually and automatically, the field:
If the Infrastructure incident checkbox is cleared, the field is displayed, becomes mandatory, and is filled with its previous value. |
| Company | N | Specify the company to which the incident is related. |
| Contact type | Y | Select the source from which the request was received. Available options:
The incidents with the Contact type set to Monitoring can be automatically created by an integrated monitoring system via Monitoring and Event Management. When the record is created, this field becomes read-only. The field gets hidden from the incident form if the Infrastructure incident checkbox gets cleared. |
| Urgency | Y | Specify the urgency of the incident. Typically, it is evaluated based on the time remaining until the incident impacts the business. See the Priority Matrix article to learn more. If the incident is a child incident, the Urgency field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. This field is cleared in the child incident if its Parent incident field gets cleared. |
| Impact | Y | Measure the impact caused by the incident on the business processes. If the Major incident checkbox is selected, the value of this field changes to Very high. If the incident is a child incident, the Impact field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. This field is cleared in the child incident if its Parent incident field is cleared. If this child incident is not an infrastructure one, its Impact in this case may be determined based on the Impact Matrix provided that the values necessary for the calculation are specified. To enable this, the matrix should be configured. |
| Priority | N | Identifies the importance of the incident. This field is populated automatically based on the value of the Impact and Urgency fields. See the Priority Matrix article to learn more. If the incident is a child incident, the Priority field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. This field is cleared in the child incident if its Parent incident field gets cleared. |
| Subject | Y | Add a brief description of the incident. Once the incident is created, this field gets hidden. |
| Description | N | Add a detailed description of the incident. This field becomes read-only after the infrastructure incident record is created. |
| Steps to reproduce | N | Specify the steps to reproduce the incident. |
| Screenshot | N | Upload screenshots supporting the incident if there are any. |
| Assignment group | Y/N | Specify the group assigned to work on the incident. This field is non-mandatory if the Assigned user field is filled in or the State is In progress, Completed, or Closed. If the incident is a child incident and the itsm.itsm_incident.map_assigned_group_and_user_to_children system property is enabled, the Assignment group field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. This field is cleared in the child incident if its Parent incident field gets cleared. There is a dependency between the Assigned user and Assignment group fields. See the Auto Assignment article to learn more. |
| Assigned user | Y/N | Specify the user assigned to work on the incident. This field is non-mandatory if the Assignment group field is filled in and the State is not In progress, Completed, or Closed. To reassign a user or a group, use the Reassign button in the upper-right corner of the page or click the magnifier icon next to the Assigned user field and specify the new assignee. As a result, the incident state changes to Assigned. If the incident is a child incident and the itsm.itsm_incident.map_assigned_group_and_user_to_children system property is enabled, the Assigned user field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. This field is cleared in the child incident if its Parent incident field gets cleared. There is a dependency between the Assigned user and Assignment group fields. See the Auto Assignment article to learn more. |
| Infrastructure incident | N | Select this checkbox to create an infrastructure incident. Once the incident is created, this field becomes read-only. |
| Major incident | N | Select this checkbox to categorize the incident as a major incident. The field appears on the form if the Infrastructure incident checkbox is selected. If the Infrastructure incident checkbox is cleared, the Major incident checkbox is cleared and hidden. Only the assigned user, an incident manager, or an admin can edit this field. After the record is saved, this field is displayed and can be edited if the Infrastructure incident checkbox is selected. |
| Attention required | N | Select this checkbox to notify the line manager of the assigned group or user. |
| State | N | Specify the work state and progress of the incident. If the incident is a child incident, the State field becomes read-only and is automatically populated with the value from the corresponding field of the parent infrastructure incident. A child incident's state changes to Registered if its Parent incident field gets cleared. |
| Resumption of work | Y/N | Indicate the date and time when the work on the incident must be resumed. The field appears when the incident is in the Postponed state. If the record is saved in any other state, the field gets cleared and hidden from the form. The field is not available when creating an incident because the Postponed state cannot be set at that stage. |
| External company | Y/N | Specify the company that works on the incident task externally. The field appears on incidents in the External processing state and shows the last saved value. When the incident enters any state other than External processing, the field's value is saved for later use, the field becomes non-mandatory and gets hidden from the form. The field is not available when creating an incident because the External processing state cannot be set at that stage. |
| External task | Y/N | Specify a task to be processed by the external company. The field appears on incidents in the External processing state and shows the last saved value. When the incident enters any state other than External processing, the field's value is saved for later use, the field becomes non-mandatory and gets hidden from the form. The field is not available when creating an incident because the External processing state cannot be set at that stage. |
| Work notes | N/Y | Add any work notes that may be useful to you or other agents working on the incident. After the incident is created, this comment will be displayed on the Work notes tab of the Activity Feed. It will be possible to add more comments there. This field may become mandatory when changing the incident's state. |
| Followers list | N | This field is populated automatically with a list of users who follow the incident for tracking the updates. It is read-only for any users without the ITSM_agent or admin roles. |
| SLA Breached | N | By default, the field is hidden. When the time set in the SLA indication expires, the value of the field changes from false to true. |
Related Records tab
Use this tab to create relationships between incidents and other types of records. See Create Records Related to Incidents to learn more.
Note that if the incident is a child incident, the information from the parent infrastructure incident is transferred to the corresponding fields of the General tab in the current incident form. Some related records from the parent incident are also automatically added to the corresponding fields of its child incidents.
Closure Information tab
The Closure Information tab appears and becomes mandatory when the incident state is Completed or Closed. See Process Incidents to learn more.
Related lists
The External Specification and Internal Specification related lists contain Knowledge Base articles with the same Service as in the incident, for quick access to the necessary instructions. Learn more in the Service Specifications article.
The Child Incidents related list is available on the infrastructure incident form. It includes all child incidents of the current incident.