Create a Profile for Netskope DLP integration
Create an incident profile in your ServiceNow AI Platform instance.
Before you begin
Role required: sn_dlir.admin
About this task
Configure ServiceNow AI Platform to retrieve the DLP incidents from the Netskope endpoint. Store the incidents into your ServiceNow instance as DLP incidents.
Procedure
Navigate to Netskope DLP integration > Incident Profile.
Click New.
On the form, fill in the fields.
| Field | Description |
|---|---|
| Name | Name of the profile. The name must be unique for each profile. This name helps you to identify the profile. |
| Source | Netskope DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile.Note: Only one active profile is allowed per source. |
| Active | Indicator that the profile is active.Note: This field is available only after you click Finish in the last Scheduling section. When the profile is active, your ServiceNow AI Platform instance is actively polling Netskope DLP incidents. Corresponding DLP incidents are created as ServiceNow DLP incidents when the filtering conditions are matched based on the Scheduling parameters you have provided. |
| Order | Order of the profile execution. The profile with the lowest order considered as the highest priority.By default, the value is 100. |
| Description | Description to help you distinguish this profile from other profiles. |
Click Continue and move to the Filtering section.
Define Filters to apply for the Incident creation
Define and set filter conditions to filter the incoming Netskope DLP incidents. Control which of these incidents should be created as DLP incidents on your ServiceNow instance.- Schedule the Netskope DLP incidents retrieval
Set a schedule to retrieve Netskope DLP incidents that match the criteria in the profile.
Parent Topic:Data Loss Prevention Incident Response Integration with Netskope