---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set Correlation rules

# Set Correlation rules {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

After you have created a profile for a scheduled notable event type ingestion, select
a Splunk Enterprise Security correlation rule name for this profile for which you want
to map corresponding notable events to a ServiceNow AI Platform
Security Incident Response security incident.

## Antes de Iniciar

Role required: sn_si.ingestion_profile_admin  
Nota:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## Por Que e Quando Desempenhar Esta Tarefa

View the available correlation rules in your ServiceNow AI Platform instance so you
know the notable event types for which you want to ingest and create security incidents.
Select a correlation rule. You can select one or more notable event from the list in
this form.

## Procedimento

1. If you are not continuing from the previous section of the incident profile definition process, access the profile you are defining.  
   1. Navigate to All\>Splunk ES Event Profile.
   2. Select the profile you are continuing to define.
   3. Select Notable Event Selection in the progress bar.
   {#splunk-event-ingest-alert-selection-security__ol_iqb_12g_l3c}
2. Clear All Correlation Rules Selected check box to select specific Correlation Rules.  
   Selecting this check box will retrieve all active Correlation Rules from Splunk ES.
3. In the Correlation Rules List search field, enter the Correlation Rule name created in the Splunk ES portal.
4. Select the Correlation Rule(s).
5. Use the right arrow ( \>) to move the rule(s) from Available to Selected column.  
   Nota:  
   Correlation rules must be unique across active profiles. A correlation rule associated with an active profile cannot be selected for another active profile. To reuse the rule, deactivate the profile it is currently associated with.
6. Select Continue.

## O que Fazer Depois

[Map notable events](https://servicenow-prod.fluidtopics.net/fqNz~pW74CrZRaSOzSp4yw "During the notable event field-mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.")

