Incident & ITSM

Send ServiceNow alerts to on-call with CallHeim.

Event Management events / ITSM incidents via webhook. CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.

servicenowServiceNowalso accepts: service-now, snow, servicenow-em

You build the connection

ServiceNow has no native outbound webhook for this. It requires a forwarder, script or template that you set up; CallHeim provides the ingest URL and understands the payload shape once it arrives.

ServiceNow events or incidents you forward from your own instance become CallHeim alerts: repeats on the same event or incident collapse onto one incident, and the service the integration is bound to pages whoever is on call for it. This requires glue you build in ServiceNow — there is no built-in outbound webhook here. CallHeim includes a payload mapping for ServiceNow’s webhook format, built and tested against sample payloads. A ServiceNow incident opened this way is a mirror, not a synced record: later changes in ServiceNow are not written back.

How the alert reaches on-call

  1. Step 1An Event Management event lands in em_event, or an incident is created or updated.
  2. Step 2A Business Rule you write on that table calls an Outbound REST Message (RESTMessageV2) to POST a JSON body to your CallHeim ingest URL.
  3. Step 3CallHeim reads message_key (or the event's node and resource, or the incident number) as the identity signal, and maps the event's numeric severity or the incident's priority.
  4. Step 4Repeats with the same identity within five minutes collapse onto one incident.
  5. Step 5The integration's bound service selects an escalation policy, which pages the on-call tier.

Setting it up

  1. 01

    Create the ServiceNow integration in CallHeim to get an ingest URL.

  2. 02

    Build an Outbound REST Message in ServiceNow pointed at that URL.

    System Web Services > Outbound > REST Message. Define a POST method with a JSON body built from the fields you want CallHeim to read (see Field mapping).

  3. 03

    Write a Business Rule that calls it.

    On em_event insert (Event Management), or on incident insert/update, depending on which record type you want mirrored. Use RESTMessageV2 in the rule's script to send the request.

  4. 04

    Shape the body as either the flat event fields or the incident-wrapped shape.

    CallHeim's parser accepts either { source, node, type, resource, metric_name, severity, description, message_key, additional_info } for an Event Management event, or { incident: { number, short_description, priority, state } } for an ITSM incident — pick one and be consistent.

Example payloadJSON
{
  "source": "Prometheus",
  "node": "app-node-3",
  "type": "High CPU",
  "resource": "CPU",
  "severity": "1",
  "description": "CPU utilization above 95%",
  "message_key": "app-node-3:cpu",
  "additional_info": "sustained for 10m"
}
Example shape written by us, in the fields our parser reads for a ServiceNow Event Management event; check ServiceNow's own documentation for the em_event schema.

What CallHeim reads from the payload

Payload fields and what each one maps to on the incident
Payload fieldMaps toNote
incident.short_description / incident.number (ITSM shape)incident title
description / resource / metric_name (event shape)incident title
severity ("1" Critical … "5" OK/Clear) or incident.priorityseverity1→P1, 2→P2, 3 or 4→P3, 5 or 0→P4; a resolved or closed incident state also writes P4.
additional_info, or type / node / source joined togetherincident body
message_key (event shape) or incident.number (ITSM shape)identity signalServiceNow's own dedup key for the event shape.

How CallHeim processes it

Routing

Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged.

Deduplication

Repeats of the same alert collapse onto one incident while they keep arriving within five minutes of each other. A repeat that arrives after a longer quiet gap opens a new incident. Identity is message_key on the event shape, or the incident number on the ITSM shape, so a Business Rule that resends the same record's key collapses repeats onto one CallHeim incident.

Recovery

A resolved or closed state in ServiceNow does not close the CallHeim incident automatically. CallHeim downgrades the severity it records to P4 for a severity of 5 or 0, or an incident state of resolved or closed, but neither field is one CallHeim's generic close detector reads, so the incident stays open. Later state changes in ServiceNow are not synced back at all — a person resolves the CallHeim incident separately.

Troubleshooting

Common problems and how to fix them
ProblemFix
Nothing arrives.Check the Business Rule actually fires on the condition you expect (insert vs. update), and that the Outbound REST Message's endpoint matches the CallHeim ingest URL exactly.
HTTP 400 on send.The Business Rule's script built a body that is not the flat event shape or the { incident: {...} } shape CallHeim reads — check the JSON matches one of the two exactly.
A resolved incident stays open in CallHeim.Expected — see Recovery above. Resolve it by hand.
Repeats open separate incidents.message_key (or the incident number) is not stable across the events you are forwarding — check the Business Rule builds it the same way every time.
HTTP 401 once you enabled signing.RESTMessageV2 supports setting a custom header, so add X-ItOnCall-Signature in the Outbound REST Message's HTTP headers if you enable signing.

Security

CallHeim verifies an HMAC-SHA256 signature on each source’s requests once you enable signing on that integration (the sending tool must be able to sign). ServiceNow's Outbound REST Message (RESTMessageV2) supports adding a custom header, so you can add X-ItOnCall-Signature there if you enable signing. Until you do, the ingest URL itself is the credential.

Vendor documentation checked

The thresholds it passes through

Dedup window
300s
Flap threshold
4 transitions / 600s
Title correlation
similarity ≥ 0.6, same source and service
Group window default
600s

All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →

CallHeim

Point ServiceNow at CallHeim and see what it does with your alerts.

Explore the platform, connect one source, and send yourself a test page by e-mail (early access).

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required