Create a profile for Symantec DLP integration
Create an incident profile in your ServiceNow AI Platform instance. Determine the Symantec DLP incidents that are suitable for creating DLP incidents.
Before you begin
Role required: sn_dlir.admin
About this task
Configure the ServiceNow AI Platform® to fetch the DLP incidents from the Symantec endpoint. Store these incidents into your ServiceNow® instance as DLP incidents.
Procedure
Navigate to Symantec DLP integration > Incident Profile.
Click New.
On the form, fill the fields in the Name section.
| Field | Description |
|---|---|
| Name | Name of the profile. This field helps you to identify the profile.Note: The name must be unique for each profile. |
| Source | Symantec DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile. |
| Active | Option to indicate if the profile is active. This field can only be enabled after you click the Finish in the Scheduling section.When the profile is active, it implies that the ServiceNow AI Platform is actively polling Symantec DLP incidents. The corresponding DLP incidents are created in DLP when the filtering conditions are matched based on the Scheduling parameters that you have provided. |
| Symantec Enforce Server Timezone | Select the time zone for symantec enforce server in the profile so that incidents are not missed due to the time zone issues. |
| Consider Daylight Saving Time | Select this check box if the enforce server follows the daylight saving time. |
| Order | Order of the profile execution. The profile with the lowest order considered as the highest priority.By default, the value is 100. |
| Description | Unique description for this profile. |
Image omitted: dlp-incident-profile.png
DLP incident profile
DLP incident profile
What to do next
To move to the Filtering section, click Continue.
- Define filters to apply for the Incident creation
Define and set filter conditions to drill down the incoming Symantec DLP incidents. Determine the incidents that should be created as DLP incidents in ServiceNow®. - Configure evidence file storage
Configure evidence file storage to securely store the evidence file for the DLP Incidents. - Download evidence files
Download DLP incident evidence files that violate the DLP policy on Symantec. - Preview evidence files
Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace. - Schedule the Symantec DLP Incident Retrieval
Set a schedule to retrieve the incident data and ingest Symantec DLP incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Symantec. - Mapping Symantec DLP incident statuses with ServiceNow incident Status
Synchronize the status of the DLP incidents ingested on the ServiceNow with the DLP incidents of the Symantec. Map the ServiceNow Incident Status field with the Symantec Incident Status field.
Parent Topic:Symantec Integration for Data Loss Prevention Incident Response