Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Set up a profile for scheduled notable event ingestion

Depending on the profile defined, Splunk ES notable events are automatically ingested into the Security Operations environment of your ServiceNow AI Platform instance.

The following table shows the list of tasks you need to follow to set up a profile for scheduled ingestion of notable events:

TaskSection
Create an event profileSee Create a profile
Select notable events based on correlation search nameSee Set Correlation rules
Map notable event fieldsSee Explore Mapping
Create custom mappingsSee Map notable events
Preview the security incidentSee Preview security incident
Schedule and retrieve new and updated notable eventsSee Schedule and retrieve notable events
Automate notable event updates and closure based on SIR incident statusSee Automate notable event updates and closures