Alerts were created sometime back, then all of a sudden, incidents are created for them hours/days after the alerts were created.
Due to Maintenance Rule, when an event came into ServiceNow for a CI that is in Maintenance mode, Event Management will create an alert with 'Maintenance' flag set to true. When the related CI moves out of Maintenance mode, Event Management will also uncheck the 'Maintenance' flag on the alert.
If the alert is still in open state once itself moves out of maintenance, the 'Event Management - create/resolved incidents by alerts' scheduled job will create Incident for it.
Adjust the Event Management settings to meet businesses requirements.
- Don't create alerts for CIs in maintenance.
- Auto-close alerts for CIs in Maintenance.
- Auto-close alerts when CIs moved out of maintenance.