---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Post ingestion form updates

# Security Incident Response form changes after ticket ingestion {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

After a Secureworks CTP ticket has been ingested, a security
incident is created and the corresponding updates are made to the security incident record.

## Worknotes {#secureworks-ctp-sir-changes__section_ilp_zhp_4kb}

A worknote is posted with details of the ticket that triggered the security incident.  

![Secureworks CTP: SIR Worknote]()  

Click on the ticket link to navigate to the internal Secureworks Ticket to Task record. The
Click here hyperlink takes you to the Secureworks CTP dashboard where you can view the ticket details.

If you had selected the Log work note for new ticket option in the
Ticket Aggregation Criteria as described in the Create Profile: Mapping page, a worknote is
posted when the ticket is aggregated.  

![Secureworks CTP SIR Worknote aggregated]()  

## Aggregated tickets {#secureworks-ctp-sir-changes__section_kwp_bnp_4kb}

Click Related ListsSecureworks Aggregated Tickets to view the ticket aggregated to the security incident. Click the ticket
hyperlink to view the ticket in the Secureworks CTP dashboard.  

<br />

Create security incident: Select a ticket from the list, click the
Actions menu and click Create security incident.
This option creates a new security incident for the ticket and this ticket is de-aggregated from
the parent security incident.

Delete ticket record: Select a ticket from the list, click the Actions
menu and click Delete. This option deletes the ticket record.

## Secureworks Ticket updates {#secureworks-ctp-sir-changes__section_qlm_h4p_4kb}

This shows the standard ticket fields and tracks changes to the tickets during every polling
interval. This is helpful as you can view any ticket updates directly without navigating to the
Secureworks CTP dashboard. Any changes to the values are displayed in the
Previous Value and Current Value fields.

<br />

## Secureworks Recent Events {#secureworks-ctp-sir-changes__section_i4m_wqp_4kb}

Click the Fetch Recent Secureworks Events option under the
Related Links to view the most recent Secureworks events.  

<br />

By default, a maximum number of 50 events will be displayed. You can modify this default
setting in the Secureworks Integration Settings.

