Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a profile for Symantec DLP integration

Create an incident profile in your  ServiceNow AI Platform instance. Determine the  Symantec DLP incidents that are suitable for creating DLP incidents.

Before you begin

Role required: sn_dlir.admin

About this task

Configure the ServiceNow AI Platform® to fetch the DLP incidents from the Symantec endpoint. Store these incidents into your ServiceNow® instance as DLP incidents.

Procedure

  1. Navigate to Symantec DLP integration > Incident Profile.

  2. Click New.

  3. On the form, fill the fields in the Name section.

FieldDescription
NameName of the profile. This field helps you to identify the profile.Note: The name must be unique for each profile.
SourceSymantec DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile.
ActiveOption to indicate if the profile is active. This field can only be enabled after you click the Finish in the Scheduling section.When the profile is active, it implies that the  ServiceNow AI Platform is actively polling Symantec DLP incidents. The corresponding DLP incidents are created in  DLP  when the filtering conditions are matched based on the Scheduling parameters that you have provided.
Symantec Enforce Server TimezoneSelect the time zone for symantec enforce server in the profile so that incidents are not missed due to the time zone issues.
Consider Daylight Saving TimeSelect this check box if the enforce server follows the daylight saving time.
OrderOrder of the profile execution. The profile with the lowest order considered as the highest priority.By default, the value is 100.
DescriptionUnique description for this profile.
Image omitted: dlp-incident-profile.png
DLP incident profile

What to do next

To move to the Filtering section,  click Continue.

Parent Topic:Symantec Integration for Data Loss Prevention Incident Response