---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up instance

# Set up your ServiceNow AI Platform instance for the ArcSight ESM
event ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

The following section lists the setup tasks that you are required to complete in your
ServiceNow AI Platform® instance prior to installing the application from the ServiceNow Store.

## Before you begin

Role required: admin

## About this task

Refer to the following table and verify that you have completed all the listed tasks
before you download and install the application to ensure a smooth installation and
configuration.
{#arcsight-esm-setup-sn__table_evy_hpv_3fb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform® and Security Incident Response (SIR) roles. | The following roles are required for the installation, setup, and use of the integration in your ServiceNow AI Platform® instance. * A user with the ServiceNow AI Platform® administrator role (admin) installs the application from the ServiceNow Store and assigns the security incident administrator (sn_si.admin) role. * A user with the sn_si.admin role oversees the following tasks in the ServiceNow AI Platform®: * Names, creates, and edits event profiles. * Selects and maps values from ArcSight ESM correlation events to security incidents. * Previews security incident details for accuracy prior to finalizing the configuration. * Schedules on-going correlated event ingestion. * Enables correlated event updates when a SIR incident is created and closed. * Assigns the security incident analyst (sn_si.analyst) role. * Users with the sn_si.analyst work with security incidents. {#arcsight-esm-setup-sn__ul_gvy_hpv_3fb} {#arcsight-esm-setup-sn__ul_fvy_hpv_3fb} For more information about roles and assigning roles to users, see Roles on the [Servicenow Product Documentation website](https://www.servicenow.com/docs). |
| Verify that you are using version 7.0.0.2436 or later of the ArcSight ESM Manager. Earlier versions are not supported. | If you have access to the ArcSight ESM Query Viewer, you have access to the API that is required for this integration. There is no other special setup required for the API. |
| Set up the Query Viewer in ArcSight ESM. | Before you can ingest correlation events, you must configure the Query Viewer in the ArcSight ESM console. See [Set up the ArcSight ESM Query Viewer](https://servicenow-prod.fluidtopics.net/BF8v719D9DpAVfSC2Xx62Q "Create a query viewer and define filters that will include recently created correlation events that will be ingested ServiceNow.") for details. |
| Optional Create custom stages in ArcSight ESM for correlation event updates. | A correlation event goes through many stages in its life cycle before it is closed. ArcSight ESM provides default stages like Initial, Monitoring, Queued, and Closed. Some of these stages require user inputs but other stages are automatically applied to the event without any user intervention (the User Required field is unchecked in the ArcSight ESM console). You can create custom stages that do not require any user intervention and use them in your ServiceNow AI Platform® instance. See [Additional options: Automate correlated event updates and closure based on SIR incident status](https://servicenow-prod.fluidtopics.net/egJlgjms~Pn7BZB9sWnKhA "The ArcSight ESM integration has a bi-directional interface that allows for both correlation events to create security incidents, as well as an ability to update the correlation events once the security incident is created and/or closed with relevant incident details such as security incident number, assignment group, SIR incident URL, and so on.") for details. |
| Verify that you have installed and configured a MID Server Application. | Configured MID Server Application A MID Server in your ServiceNow AI Platform® instance is required to connect to the ArcSight ESM service if the ArcSight ESM server is deployed within your corporate network. See [Install and configure the ServiceNow application for the ArcSight ESM Event Ingestion integration](https://servicenow-prod.fluidtopics.net/iiYdbjASiQ5mhvdQsTLW6A "Before you run the integration on your ServiceNow AI Platform instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.") for instructions on how to configure a MID Server Application. See the [MID Server](https://www.servicenow.com/docs/access?context=mid-server-landing&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US) for information about MID Servers. If you are using a hosted or cloud service, that is Internet accessible, a MID Server is not required. |
| Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you install the application for the integration. | Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. 1. Security Incident Response 2. Security Integration Framework 3. Security Support Common 4. Event and Alert Ingestion for Security Operations: This application requires: * com.glide.hub.integration.runtime =\> ServiceNow IntegrationHub Runtime * com.glide.hub.action_step.rest =\> ServiceNow IntegrationHub Action Step - REST {#arcsight-esm-setup-sn__ul_scy_whl_xkb} 5. Threat Core {#arcsight-esm-setup-sn__ol_qwy_vrt_fhb} For more information about installing the Security Operations core applications, see [Get entitlement for a Security Operations product or application](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
[ ]

{#arcsight-esm-setup-sn__table_evy_hpv_3fb}

## What to do next

You have successfully set up your ServiceNow AI Platform® instance for the
integration. The next step is to install the ArcSight ESM Security
Event Ingestion for Security Operations application from the ServiceNow Store for the integration.

