---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response form after offense ingestion

# Security Incident Response form after offense ingestion {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

After an IBM QRadar offense has been ingested, a security incident is
created and the corresponding updates are made to the security incident record.

## Worknotes {#qradar-ibm-sir-changes__section_ilp_zhp_4kb}

A worknote is posted with details of the offense that triggered the security incident.  

Click the offense link to navigate to the internal security incident record. The
Click here hyperlink takes you to the IBM QRadar
dashboard where you can view the offense details.

If you had selected the Log work note for new offense option in the
Offense Aggregation Criteria as described in the [Mapping IBM QRadar offense fields to security incident response fields](https://servicenow-prod.fluidtopics.net/Qv7CryRFnfrzMfjfD7upBQ "Map individual offense, event, and flow fields to fields on a ServiceNow AI Platform SIR security incident."),
a worknote is posted when the offense is aggregated.  

<br />

## Aggregated offenses {#qradar-ibm-sir-changes__section_kwp_bnp_4kb}

Click Related ListsAggregated IBM QRadar offenses to view the offenses aggregated to the security incident. Click the QRadar offense hyperlink to view the offense in the IBM QRadar dashboard.  

Create security incident: Select an offense from the list, click the
Actions menu, and click Create security incident.
This option creates a security incident for the offense and this offense is de-aggregated from
the parent security incident.  
Delete offense record: Select an offense from the list, click the Actions menu, and click Delete. This option deletes the offense record.  

## IBM QRadar offense updates {#qradar-ibm-sir-changes__section_qlm_h4p_4kb}

This shows the standard and custom offense fields and tracks changes to the offense during
every polling interval. This is helpful as you can view any offense updates directly without
navigating to the IBM QRadar dashboard. Any changes to the values are displayed
in the Previous value and Current value fields.

To enable the offense updates feature navigate to IBM QRadar IntegrationIBM QRadar Integration Settings and enable Set this property to activate the Offense Updates feature. By default, this setting is disabled.  

<br />

## Recent IBM QRadar events {#qradar-ibm-sir-changes__section_i4m_wqp_4kb}

Click the Fetch Recent IBM QRadar Events option under the Related Links to view the most recent IBM QRadar events.  

By default, a maximum number of 100 events are displayed. You can modify this default setting in the [Configuration settings](https://servicenow-prod.fluidtopics.net/~Zem5JTc0TjBqi8~FIvKEw "Use this option to modify the IBM QRadar ingestion integration default system properties.").  
Nota:  
The above image shows the standard event fields associated with the offense. If you have configured and mapped any custom event fields (See [Mapping IBM QRadar offense fields to security incident response fields](https://servicenow-prod.fluidtopics.net/Qv7CryRFnfrzMfjfD7upBQ "Map individual offense, event, and flow fields to fields on a ServiceNow AI Platform SIR security incident.")), you can view them in the List View by clicking the Event Name link.

<br />

## Recent IBM QRadar Flows {#qradar-ibm-sir-changes__section_wk2_qsp_4kb}

Using the Integration Hub and Flow Designer, several flows, subflows, actions are available with the IBM QRadar integration. When you click the Fetch Recent IBM QRadar Flows option under the Related Links, the most recent flows are retrieved. To view these flows, click Recent IBM QRadar Flows.  

By default, a maximum number of 100 flows are displayed. You can modify this default setting in the [Configuration settings](https://servicenow-prod.fluidtopics.net/~Zem5JTc0TjBqi8~FIvKEw "Use this option to modify the IBM QRadar ingestion integration default system properties.").  
Nota:  
The above image shows the standard flow fields associated with the offense. If you have configured and mapped any custom flow fields (See [Mapping IBM QRadar offense fields to security incident response fields](https://servicenow-prod.fluidtopics.net/Qv7CryRFnfrzMfjfD7upBQ "Map individual offense, event, and flow fields to fields on a ServiceNow AI Platform SIR security incident.")), you can view them in the List View by clicking the Flow ID link.

