Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Creating an alarm profile for LogRhythm

In an alarm profile that you create and name, you specify which alarms you want to pull from the LogRhythm Client Console. You also define how they are mapped to fields on a ServiceNow AI Platform security incident.

Before you begin

Role required: sn_si.admin

About this task

Based on the Alarm Profile configured, one alarm profile can ingest all types of alarms out of the box, but you can use filter criteria to ingest specific types of alarms. Using this ServiceNow AI Platform integration, all configured alarm rules or specific ones based on the profile created are ingested. Alarm rules such as only high-risk level alarms can then be filtered to specify which alarms should create security incidents. Before security incidents are created, individual field values on the filtered alarms are mapped to corresponding fields on the ServiceNow AI Platform security incident. This configuration is done via an alarm profile within your ServiceNow AI Platform instance.

Procedure

  1. Navigate to All > LogRhythm Integration.

  2. Select the LogRhythm Alarm Profiles module to display the Alarm Profiles list.

Image omitted: logrhythm-alarm-profile.gif
Create an alarm profile
  1. To create a new alarm profile, click New.

    A new alarm profile form is displayed. At the top of the page in the progress bar, Name is selected. This bar tracks your progress during the configuration.

  2. On the form, fill the fields.

FieldDescription
NameName for the alarm profile. This name helps you identify the alarm types such as Unauthorized access \(VPN\), malware, or phishing.
Short descriptionShort text for additional information about the alarm profile, which may include the type of alarms, or an alarm category. An example description: All alarms associated with unauthorized Powershell and Sudo access attempts.
SourceSource server from the choice list. The list consists of LogRhythm configurations you have already set up, for example, `logrhythm-server-a`. See Install the plugin and configure LogRhythm.
OrderAlarm profile priority. This field indicates the order in which the alarm profiles are executed when two or more alarm profiles share the triggering conditions.
ActiveBy default this option is not selected. After you complete all alarm profile setup steps and click Finish, you are prompted to select this check box to activate the alarm profile. When the alarm profile is active, it pulls alarms from the LogRhythm Client Console automatically.
  1. Click Continue to save your data and proceed to the Mapping form.

    If the validation is successful, the page reloads and the Mapping form is displayed. You cannot proceed with the configuration until you have successfully validated your connection and credentials.

  2. Mapping
    After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.

  3. Filter alarms for LogRhythm
    Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.
  4. Previewing the security incident with mapped LogRhythm alarm values
    After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident.
  5. Schedule and retrieve LogRhythm alarms
    After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated.
  6. Additional options for LogRhythm alarms
    The LogRhythm Enterprise integration provides you the ability to automatically update or close the LogRhythm alarms based on the security incidents.

Parent Topic:LogRhythm Overview

Previous topic:Install the plugin and configure LogRhythm

Next topic:Mapping

Related topics

Mapping