---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Map Proofpoint DLP incidents status with ServiceNow incident status

# Map Proofpoint DLP incidents status with ServiceNow incident status {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Synchronize the status of the DLP incidents ingested on your ServiceNow instance and DLP incidents of the Proofpoint. Map the ServiceNow Incident status with the Proofpoint Incident status.

## Before you begin

Role required: sn_dlir.admin

## Procedure

1. Navigate to Proofpoint DLP integrationIncidentIncident Status Mapping.
2. Provide a Name to identify the mapping.
3. Select the Source (integration configuration) tile for which the Status Mapping should be applied.
4. Map the ServiceNow DLP incident Status with Proofpoint Incident Status.  
   {#map-proofpoint-dlp-incident-status__table_aly_j12_ltb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Placeholder for the mapping record. |
   | Source | Configured Proofpoint Endpoint source from where you want to fetch the incident status. |
   | ServiceNow Incident Status | List of Status of DLP incidents. |
   | Proofpoint Incident Status | Default mapped values for default states available in DLP incidents. For custom states, the default Proofpoint status is New. You can modify and add the required Proofpoint status in the input field. |
   [Table 1. Map Proofpoint DLP incidents status with ServiceNow incident status form]

   {#map-proofpoint-dlp-incident-status__table_aly_j12_ltb}
5. Click Submit.
{#map-proofpoint-dlp-incident-status__steps_cr5_xvv_3tb}

## Result

A record for mapping is successfully created. The statuses of the ServiceNow incidents will be synchronized with Proofpoint DLP incidents.

When you change the status of any DLP incident on your ServiceNow instance, then the status of the associated Proofpoint DLP incident will be changed on the source Proofpoint platform as per the mapping set in the record.

*[\>]: and then


