---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a Profile for Proofpoint DLP integration

# Create a Profile for Proofpoint DLP integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an incident profile in your  ServiceNow AI Platform instance. Determine the  Proofpoint DLP incidents that are suitable for creating DLP incidents.

## Before you begin

Role required: sn_dlir.admin

## About this task

Configure the ServiceNow AI Platform to populate DLP alerts of Proofpoint. Store the alerts as DLP incidents in your ServiceNow instance.

## Procedure

1. Navigate to Proofpoint DLP integrationIncident Profile.
2. Click New.
3. On the form, fill the fields in the Name section.  
   {#create-profile-proofpoint-dlp-integration__table_jxg_fb2_ltb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the profile. This name helps you to identify the profile. Note: The name must be unique for each profile. |
   | Source | The Proofpoint DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile. |
   | Active | Option to make the profile active. When the profile is active, your ServiceNow AI Platform instance is ready to receive the incidents from Proofpoint. |
   | Description | Description to help distinguish this profile from other profiles. |
   [Table 1. Create a profile for Proofpoint DLP integration form]

   {#create-profile-proofpoint-dlp-integration__table_jxg_fb2_ltb}
4. Click Continue and move to the Filtering section.
{#create-profile-proofpoint-dlp-integration__steps_gp2_ywv_3tb}
* **[Define filters to apply for the Incident creation](https://servicenow-prod.fluidtopics.net/duShitShfo3ewEsCcxEO6A)**   
  Define and set filter conditions to filter the incoming  Proofpoint DLP  incidents. Control which DLP incidents should be created on ServiceNow®.
* **[Preview evidence files](https://servicenow-prod.fluidtopics.net/IEqzFCO1sar2Omm2bTfQvw)**   
  Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.

*[\>]: and then


