---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Severity mapping between Symantec DLP incidents with ServiceNow incidents

# Severity mapping between Symantec DLP incidents with ServiceNow incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the severity mapping feature to configure and synchronize the mapping between Symantec incidents and ServiceNow AI Platform® incidents.

## Before you begin

Role required: sn_dlir.admin

## About this task

DLP Severity mapping allows you to map the source severity with the DLP incident severity. You can customize and define the source severity value and map it to the desired DLP incident severity value.

## Procedure

1. Navigate to Symantec DLP integrationIncident Severity Mapping.
2. Click New.
3. On the form, fill in the fields.  
   {#severity-mapping__table_dq5_sbz_2tb__entry__2}

   | Field | Description |
   |-|-|
   | Source | The configured Symantec Endpoint source from where you want to fetch the incident. |
   | Target Value | Target value is the DLP incident severity ID. The available values are Critical, High, Medium, Low, and Info (used as the info severity in Symantec). |
   | Source Value | Source value is the Symantec incident severity. |
   [Table 1. DLP Severity Mapping]

   {#severity-mapping__table_dq5_sbz_2tb}  
   Note:  
   Within the base system, there are four severity mappings that are shipped to the DLP users.
4. Click Submit.  
   Figure 1. Severity Mapping

*[\>]: and then


