---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set correlation rules

# Set correlation rules {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

After creating a CrowdStrike Next-Gen SIEM detection profile, select correlation rules to map corresponding detections to a security incident. Correlation rules are refreshed every time a profile is opened and new rules are
available for selection. The CrowdStrike Next-Gen SIEM integration supports multiple profiles.

## Antes de Iniciar

Role required: sn_si.ingestion_profile_admin  
Nota:  
Users with the sn_si.admin role can perform all operations available to a profile admin because the sn_si.admin role inherits the required permissions by default.

## Procedimento

1. If you are not continuing from the previous section of the detection profile definition process, access the profile you are defining.
   1. Navigate to AllCrowdStrike Next-Gen SIEMDetection Profile.
   2. Select the profile you are continuing to define.
   3. Select Correlation Rules in the progress bar.
   {#select-correlation-rules-cs-ng-siem__substeps_qbv_p2t_zfc}
2. Clear the All Correlation Rules selected check box.
3. In the Correlation Rule List search field, enter the correlation rule name created in the CrowdStrike portal.
4. Select the correlation rule.
5. Use the right arrow to move the rule from Available to the Selected column.
6. Complete this section of the detection profile definition process by selecting Continue.

## O que Fazer Depois

Map individual CrowdStrike Next-Gen SIEM detection fields to the fields on the ServiceNow AI Platform Security Incident Response security incident. For more information, see [Map detection fields](https://servicenow-prod.fluidtopics.net/CVHHMUpqNJdfIKQt7VZ4sA "Map the individual CrowdStrike Next-Gen detection fields to the fields on the SIR security incident so that you can create detections with the mapped data.").

