---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a profile for Symantec DLP integration

# Create a profile for Symantec DLP integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an incident profile in your  ServiceNow AI Platform instance. Determine the  Symantec DLP incidents that are suitable for creating DLP incidents.

## Before you begin

Role required: sn_dlir.admin

## About this task

Configure the ServiceNow AI Platform® to fetch the DLP incidents from the Symantec endpoint. Store these incidents into your ServiceNow® instance as DLP incidents.

## Procedure

1. Navigate to Symantec DLP integrationIncident Profile.
2. Click New.
3. On the form, fill the fields in the Name section.  
   {#create-profile-symantec-dlp__table_dq5_sbz_2tb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the profile. This field helps you to identify the profile. Note: The name must be unique for each profile. |
   | Source | Symantec DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile. |
   | Active | Option to indicate if the profile is active. This field can only be enabled after you click the Finish in the Scheduling section. When the profile is active, it implies that the  ServiceNow AI Platform is actively polling Symantec DLP incidents. The corresponding DLP incidents are created in  DLP  when the filtering conditions are matched based on the Scheduling parameters that you have provided. |
   | Symantec Enforce Server Timezone | Select the time zone for symantec enforce server in the profile so that incidents are not missed due to the time zone issues. |
   | Consider Daylight Saving Time | Select this check box if the enforce server follows the daylight saving time. |
   | Order | Order of the profile execution. The profile with the lowest order considered as the highest priority. By default, the value is 100. |
   | Description | Unique description for this profile. |
   [Table 1. Create a profile]

   {#create-profile-symantec-dlp__table_dq5_sbz_2tb}
{#create-profile-symantec-dlp__steps_vs4_mjf_jtb}

## What to do next

To move to the Filtering section,  click Continue.
* **[Define filters to apply for the Incident creation](https://servicenow-prod.fluidtopics.net/HB~H_9~TVB7Tb9C0rmtv_Q)**   
  Define and set filter conditions to drill down the incoming  Symantec DLP  incidents. Determine the incidents that should be created as DLP incidents in ServiceNow®.
* **[Configure evidence file storage](https://servicenow-prod.fluidtopics.net/e0dG9afwiqsV1Ndw12eWTw)**   
  Configure evidence file storage to securely store the evidence file for the DLP Incidents.
* **[Download evidence files](https://servicenow-prod.fluidtopics.net/BI1HQSApvTq8BT9bjFpJxg)**   
  Download DLP incident evidence files that violate the DLP policy on Symantec.
* **[Preview evidence files](https://servicenow-prod.fluidtopics.net/XGG72q0iDdxx4NvnxR7cMg)**   
  Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
* **[Schedule the Symantec DLP Incident Retrieval](https://servicenow-prod.fluidtopics.net/jbsOcfGS8OPWDb7mWdX94g)**   
  Set a schedule to retrieve the incident data and ingest Symantec DLP incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Symantec.
* **[Mapping Symantec DLP incident statuses with ServiceNow incident Status](https://servicenow-prod.fluidtopics.net/XPQAzGxAsgcqSfpWtHxtBA)**   
  Synchronize the status of the DLP incidents ingested on the ServiceNow with the DLP incidents of the Symantec. Map the ServiceNow Incident Status field with the Symantec Incident Status field.

*[\>]: and then


