---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Smart Response Rules

# Configure Smart Response Rules {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure the Symantec smart response rule(s) to perform response actions on the ingested Symantec DLP Incidents.

## Before you begin

Role required: sn_dlir.admin

## About this task

Verify that the Symantec user that you are configuring for ServiceNow Symantec DLP integration must have those Smart Response Rules selected under the Roles configuration page. For more information, see
Actions section available on [Configuring Roles](https://techdocs.broadcom.com/us/en/symantec-security-software/information-security/data-loss-prevention/16-0-1/Manage-the-Enforce-Server/managing-users-and-rules/configuring-roles-id-sf0b0167317a-d297e3139.html) document.

For the fetched smart response rule(s), DLP admin can create the Incident Response Option Rule(s) and Response Option Mappings to configure the response action(s) to be performed on ingested Symantec DLP Incidents.

## Procedure

1. Navigate to AllSymantec DLP IntegrationSmart Response Rules.  
   You can see all the available smart response options for each configured integration configuration. For more information see, [Install and configure the Symantec DLP integration for Data Loss Prevention](https://servicenow-prod.fluidtopics.net/txaLJORVFWrVWOSP_rfTrg "Install and configure the  Symantec DLP integration from the  ServiceNow Store on your  ServiceNow AI Platform instance. Start investigating DLP incidents using the  Symantec DLP incident data.") and follow the procedure explained configure Symantec integration configuration source if not configured)
2. Click on any of the Smart Response Rules to open its form view.  
   Follow [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.") to create Incident Response Option Rules and Response Option Mappings to display this smart response rule on Respond modal of DLP workspace.
3. Create the approval rules for the Smart Response Rule using the Approval Rules tab in the related list or by following procedure explained in the Configure Approval Rules section.  
   Approval Rules for each Smart Response Rules will be visible in the Approval Rules related list.
4. After creating the Incident Response Option Rule(s), you can see the record in the related list of the Smart Response Rule record.
5. Use the Refresh Smart Response Rule button in the list view to manually update the source.  
   The smart response rules will add, update, or delete automatically each day for every source.
{#config-smart-response-rules__steps_hwc_rpg_jcc}

*[\>]: and then


