---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations enrichment data mapping

# Security Operations enrichment data
mapping {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Enrichment Data Mapping
transforms data from XML, JSON, or Properties files to
ServiceNow records. Security Operations workflows use enrichment
data maps and provide output data to security incidents.

Security Operations includes several enrichment data maps, triggered by various workflows,
for example, [Security Operations Integrations - Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/53Vtuib1JX5dIXwcI88zUw "The Security Operations Integrations - Get Network Statistics flow retrieves a list of active network connections from a host or endpoint.") and [Security Operations System Command Integration- Get Running Processes flow](https://servicenow-prod.fluidtopics.net/Fr4YbLyVSAEVhfn3kPGT9Q "The Security Operations System Command Integration - Get Running Processes flow retrieves the running processes of a configuration item when added or updated to a Windows or Unix-based security incident in the Analysis state."). Enrichment data map output from Security Operations workflows is displayed in the
Enrichment Data tab on the security incident form.
* **[Create a Security Operations enrichment data map](https://servicenow-prod.fluidtopics.net/EO8uL~baw4HtN~HvZWG9Bg)**   
  Transform data from JSON, XML, or Properties file format to ServiceNow records using enrichment data maps.

