---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Inbound integration

# Inbound Integration for Data Loss Prevention Incident Response {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

Create single or multiple DLP incidents by using the Inbound REST API.

## Create a single DLP incident {#inbound-integration-dlp__section_lsy_kch_h5b}

Role required: sn_dlir.api_integration_user.  
To create a single DLP incident, define the following parameters as necessary:{#inbound-integration-dlp__table_kcx_4ch_h5b__entry__2}

| Field | Description |
|-|-|
| HTTP Method | POST |
| URL | <kbd class="ph userinput">https://{instance}/api/now/import/sn_dlir_incident_import</kbd> |
| Request Header | Accept: :   application/json Content-Type: :   application/json |
| Sample Payload | { "application_window_title": "<value>", "assigned_to": "<value>", "attachments": "<value>", "data_owner_email": "<value>", "destination": "<value>", "dest_ip": "<value>", "dest_ip_port": "<value>", "detection_date": "<value>", "endpoint_on_corporate_net": "<value>", "files": "", "file_created": "", "file_created_by": "", "file_location": "", "file_modified_by": "", "file_name": "", "file_owner": "", "file_permissions": "", "ftp_user_name": "", "last_modified": "", "machine_ip": "", "machine_name": "", "match_count": "", "policy_id": "", "policy_name": "", "printer_name": "", "printer_type": "", "print_job_name": "", "recipients": "", "scanned_machine": "", "scan_source": "", "seen_before": "", "sender":"", "source":"", "source_file":"", "source_ip":"", "source_ip_port":"", "subject":"", "url":"", "user_justification":"" } |
| Sample Response | { "import_set": "ISET0010003", "staging_table": "sn_dlir_incident_import", "result": [ { "transform_map": "", "table": "sn_dlir_incident", "display_name": "number", "display_value": "DLP0001012", "record_link": "https://{instance}/api/now/table/sn_dlir_incident/7cda322297c2411056a43d1e6253af1f", "status": "inserted", "sys_id": "7cda322297c2411056a43d1e6253af1f" } ] } |
[ ]

{#inbound-integration-dlp__table_kcx_4ch_h5b}

## Create multiple DLP incidents {#inbound-integration-dlp__section_a4c_c2h_h5b}

Role required: sn_dlir.api_integration_user.  
To create multiple DLP incidents from the same request, define the following parameters as necessary:{#inbound-integration-dlp__table_o4d_g2h_h5b__entry__2}

| Field | Description |
|-|-|
| HTTP Method | POST |
| URL | <kbd class="ph userinput">https://{instance}/api/now/import/sn_dlir_incident_import/insertMultiple</kbd> |
| Request Header | Accept: :   application/json Content-Type: :   application/json |
| Sample Payload | { "records": [ { "file_name": "<value>", "file_modified_by": "<value>", "work_notes": "<value>", "url": "<value>", "scan_source": "<value>", "data_owner_email": "<value>", "file_created_by": "<value>", "file_owner": "<value>", "policy_name": "<value>" }, { "dest_ip": "<value>", "dest_ip_port": "<value>", "detection_date": "<value>", "endpoint_on_corporate_net": "<value>", "files": "<value>", "file_created": "<value>", "file_created_by": "<value>", "file_location": "<value>", "file_modified_by": "<value>", "file_name": "<value>", "file_owner": "<value>", } ] } |
| Sample Response | { "import_set_id": "a38f69229734dd1056a43d1e6253af75", "multi_import_set_id": "e78f69229734dd1056a43d1e6253af75" } |
[ ]

{#inbound-integration-dlp__table_o4d_g2h_h5b}  
Nota:  
By default, the transformation is asynchronous. To set synchronous transformation, create a new record in the REST Insert Multiples \[sys_rest_insert_multiple\] table, select the source table as sn_dlir_incident_import, and set the transformation to synchronous.

