---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Monitor security events

# Monitor security events {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 Minuten Lesedauer

Analyze the event metrics in your instance so that you can identify and prevent
potential security events.  
Wichtig:  
Instance Security Center (ISC) has reached the end of sales as of September 2024, and is no longer supported or available for new activation.
ServiceNow Security Center (SSC) is the recommended solution going forward. For more information, see [Instance Security Center to ServiceNow Security Center migration](https://servicenow-prod.fluidtopics.net/4Tx0M62RqvXvCc6LYr7BuA "Learn the key differences when migrating from Instance Security Center (ISC) to ServiceNow Security Center (SSC).").
In the event ribbon, which is on the Instance Security homepage, you can analyze these metrics and accompanying detail to identify potential security events in the instance.

* For each event metric, a real-time single score count appears, indicating how many times that the event occurred during the day in this instance. These single score reports are updated automatically as the corresponding events take place.
* Each event metric also contains compliance trend and graph information over a range of dates. This information updates on a daily basis when you run the performance analytics job. To learn more, see the Analyzing event trend detail section.
{#instance-sec-center-event-ribbon__ul_dhb_3dy_jhb}

## Event types {#instance-sec-center-event-ribbon__section_pn1_dnm_kfb}

You can monitor at least six of the following types of events. For more than six events,
use the left or right arrows below the event ribbon to scroll through them. To learn how to
configure the event ribbon, see [Configure the security event ribbon](https://servicenow-prod.fluidtopics.net/_jaFMz0U0VHIjZUHEJ2qoA "Configure the security event ribbon on the Instance Security Center homepage to include only those events that are relevant for tracking instance security in your operations. You can also change the order in which the security event tiles appear on the ribbon.").
{#instance-sec-center-event-ribbon__table_rpk_b5z_4lb__entry__2}

| Notification preference | Description |
|-|-|
| Admin Logins | Number of login attempts in this instance, during the calendar day, by users who have an assigned admin role. |
| Admin Users Added | Number of users with an admin role that were added in this instance during the calendar day. For example, your instance may have a security issue if the count is 10, but 4 users are known to have an assigned admin role. |
| External Incoming Email | To learn more, see [Email metrics](https://servicenow-prod.fluidtopics.net/0HSnfDpdKUtG0KUwVI3wrg "Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance."). |
| External Logins | Number of users with an assigned snc_external role who logged into this instance during the calendar day. These logins typically occur for maintenance, support, consulting, or audit purposes. Monitoring this metric enables you to verify that the external login attempts are legitimate and not potential security issues. To learn more about assigning external user roles, see [Explicit Roles](https://servicenow-prod.fluidtopics.net/Z_EOJgwu0skO_C4T0CHX6w#explicit-roles "You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users."). |
| Failed Logins | Number of attempted logins that failed in this instance during the calendar day. This metric may indicate that attempts are being made to log in and compromise your instance security. |
| Impersonations | Number of impersonation logins in this instance during the calendar day. To learn about impersonating users, see [Impersonate a user](https://www.servicenow.com/docs/access?context=c_ImpersonateAUser&version=australia&pubname=australia-platform-administration&ft:locale=en-US). |
| Quarantined Files | Number of files that were quarantined when you ran Antivirus Scanning in this instance during the calendar day. To learn more about quarantined files and Antivirus Scanning, see [Antivirus metrics](https://servicenow-prod.fluidtopics.net/D5AE~RD_6O9l7kQi2C_F2Q "If the Antivirus Scanning plugin is activated, Antivirus Scanning runs in your instance to help protect it against virus infections from attachments.") and [Antivirus Scanning](https://servicenow-prod.fluidtopics.net/9Jg1~qjwhmfUsffwm2p77w "Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories."). |
| Security Elevations | Number of times that a security administrator has elevated security for standard users by changing their assigned user role to a high privilege security role during the calendar day. These high privilege security roles include oauth_admin, admin, security_admin, and impersonator. * This metric indicates that someone might have tried to elevate the security of an unauthorized user. Do not use this metric by itself to detect a specific security compromise. Instead, treat this metric as an indication that you should check another metric to see if a security compromise has occurred. * To learn more about elevating user security, see [Elevate to a privileged role](https://servicenow-prod.fluidtopics.net/QSMW4UNBg6bevZDKAPGT2Q "The base system admin can elevate to a privileged role to have access to the features of High Security Settings.") and [Elevated privilege roles](https://servicenow-prod.fluidtopics.net/T2UNDKD6HTL92ot_vH_UCQ "Elevated privilege roles require you to manually accept the responsibility of using the role before you can access the features of the role."). {#instance-sec-center-event-ribbon__ul_iz2_3rw_nnb} |
| SNC Logins | Number of Customer Service and Support personnel who logged into this instance using the hi-hopping technique during the calendar day. These logins typically occur for maintenance, support, consulting, or audit purposes. For information on how to control ServiceNow corporate employee access, see [ServiceNow access control](https://servicenow-prod.fluidtopics.net/y14IOxjoM0cpnLgyMjHQhA "The SNC Access Control plugin (com.snc.snc_access_control) enables you to control which Customer Service and Support employees can access your instance, and when."). |
| Spam | To learn more, see [Email metrics](https://servicenow-prod.fluidtopics.net/0HSnfDpdKUtG0KUwVI3wrg "Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance."). |
| Trusted Incoming Email | To learn more, see [Email metrics](https://servicenow-prod.fluidtopics.net/0HSnfDpdKUtG0KUwVI3wrg "Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance."). |
| Untrusted Incoming Email | To learn more, see [Email metrics](https://servicenow-prod.fluidtopics.net/0HSnfDpdKUtG0KUwVI3wrg "Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance."). |
| Virus Types | Number of different types of antivirus events that occurred in this instance during the calendar day. To learn more about antivirus event types, see [Antivirus metrics](https://servicenow-prod.fluidtopics.net/D5AE~RD_6O9l7kQi2C_F2Q "If the Antivirus Scanning plugin is activated, Antivirus Scanning runs in your instance to help protect it against virus infections from attachments."). |
[ ]

{#instance-sec-center-event-ribbon__table_rpk_b5z_4lb}

## Analyzing event trend detail {#instance-sec-center-event-ribbon__section_trend_analysis}

To view trend details for an event metric, click the event count to access the Analytics
Hub page. The details that appear for the instance depend on the type of metric.  
For example, to view a listing of each failed attempt on the Security Dashboard Event Logs page:

* Select the Failed Logins metric.
* In the KPI Details page, click Show Records.
* Click one of the failed login attempts.
* The detail includes the name of the user who attempted to log in, their IP address, and the table name that they tried to access.
{#instance-sec-center-event-ribbon__ul_ggy_zl4_kjb}
You can set up event threshold triggers in the Core UI Analytics Hub or Platform Analytics KPI Details to provide alerts when a certain event occurs within a range of scores for an [indicator](https://www.servicenow.com/docs/access?context=performance-analytics-glossary&version=australia&pubname=australia-now-intelligence&section=gloss-indicator&ft:locale=en-US). You can also set targets that enable you to visualize the difference between the desired score and the actual score of an event.  
For example, you can set a threshold of <kbd class="ph userinput">10</kbd> for the Failed Logins metric. When ten or more failed login attempts occur during the day, an
alert is sent to specific security personnel. You can also set a similar target that
provides a visual highlight in the KPI Details when 10 failed logins occur during a
day.
Trend data and graphs that appear in Event ribbon tile and the KPI Details are updated after the performance analytics job executes at 02:00 local time. To learn more, see [How Daily Compliance score, trend, and graph data is refreshed](https://servicenow-prod.fluidtopics.net/i_5gVwND8aR~6vDnZ~Qe6Q "Trend and graph data in the Instance Security Center is updated after the performance analytics job executes at 02:00 local time. It appears in the Daily Compliance Score tile, in the Event ribbon tiles, and in the KPI Details page detail.").
* **[Configure the security event ribbon](https://servicenow-prod.fluidtopics.net/_jaFMz0U0VHIjZUHEJ2qoA)**   
  Configure the security event ribbon on the Instance Security Center homepage to include only those events that are relevant for tracking instance security in your operations. You can also change the order in which the security event tiles appear on the ribbon.
* **[Set preferences for security event notifications](https://servicenow-prod.fluidtopics.net/P9hnvRCt8CawX_mLAzyN6g)**   
  Configure preferences for the types of notifications you want to receive for occurrences of specific security events. For each type, you designate whether to receive notifications by email, by push notification in Now Mobile, or in third party messaging applications such as Slack or Microsoft Teams.

**Zugehörige Konzepte**   

* [Instance Security Center to ServiceNow Security Center migration](https://servicenow-prod.fluidtopics.net/4Tx0M62RqvXvCc6LYr7BuA "Learn the key differences when migrating from Instance Security Center (ISC) to ServiceNow Security Center (SSC).")
* [Check the daily compliance score and configure security property settings](https://servicenow-prod.fluidtopics.net/YyMzvDT3xTxJUGQ9CYrz7A "Review the Daily Compliance Score metric and security configuration properties to see if your instance complies with the suggested security requirements. You can affect the daily compliance score by updating non-compliant security properties in the Hardening Compliance Configurations page.")
* [Scan for incorrect security definitions](https://servicenow-prod.fluidtopics.net/qT9~wN_7ofKjid1Xw8pF7g "Run the Auditor to scan your instance and find incorrect security definitions. It provides findings you can correct to help improve the security posture of your instance.")
* [Monitor instance metrics](https://servicenow-prod.fluidtopics.net/_JPadpsZD7T5fxcvv4t7eg "Monitor user, export, authentication, email, and antivirus metrics for your instance. For example, you can monitor your email security by checking metrics for spam, external emails, and inbound emails from untrusted and trusted domains for your instance. Analyze these metrics to look for anomalous security behaviors that are related to activities that take place in your instance.")
* [Instance Security Center](https://servicenow-prod.fluidtopics.net/xpUTpZb5ScUKqSrIXf3_Yg "Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.")  
**Zugehörige Tasks**   

* [Activate the ISC Virtual Agent interface](https://servicenow-prod.fluidtopics.net/Zrpq7kYj~rVgv1k0QlLJWg "If you have the admin role, you can activate the ISC Virtual Agent Conversations plugin (com.glide.isc_virtualagent). Activating this plugin installs the Virtual Agent and Natural Language Understanding (NLU content packs, providing Virtual Agent access from the Instance Security Center.")  
**Zugehörige Informationen**   

* [Now Intelligence](https://www.servicenow.com/docs/access?context=c_performanceAnalyticsAndReporting&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)
* [Analytics Hub](https://www.servicenow.com/docs/access?context=c_UsePerformanceAnalyticsScorecards&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)
* [Performance Analytics targets and thresholds](https://www.servicenow.com/docs/access?context=pa-targets-thresholds&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)

