Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a Profile for Proofpoint DLP integration

Create an incident profile in your  ServiceNow AI Platform instance. Determine the  Proofpoint DLP incidents that are suitable for creating DLP incidents.

Before you begin

Role required: sn_dlir.admin

About this task

Configure the ServiceNow AI Platform to populate DLP alerts of Proofpoint. Store the alerts as DLP incidents in your ServiceNow instance.

Procedure

  1. Navigate to Proofpoint DLP integration > Incident Profile.

  2. Click New.

  3. On the form, fill the fields in the Name section.

FieldDescription
NameName of the profile. This name helps you to identify the profile.Note: The name must be unique for each profile.
SourceThe Proofpoint DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile.
ActiveOption to make the profile active.When the profile is active, your ServiceNow AI Platform instance is ready to receive the incidents from Proofpoint.
DescriptionDescription to help distinguish this profile from other profiles.
Image omitted: dlp-proofpoint-name.gif
Create a profile for Proofpoint DLP integration.
  1. Click Continue and move to the Filtering section.

  2. Define filters to apply for the Incident creation
    Define and set filter conditions to filter the incoming  Proofpoint DLP  incidents. Control which DLP incidents should be created on ServiceNow®.

  3. Preview evidence files
    Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.

Parent Topic:Data Loss Prevention Incident Response Integration with Proofpoint