---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Troubleshoot

# Troubleshooting ArcSight ESM event ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This section provides information on how to troubleshoot any errors that may occur
during event ingestion.

## Integration runs {#arcsight-esm-troubleshoot__section_p4s_hjc_wkb}

Navigate to Event Ingestion CommonIntegration Runs. An integration run takes place every minute and captures details regarding the events ingested during the scheduled job.

You can see the list of integration runs and status of each run (Success, Timed-out, Waiting) and the number of security incidents that were created. Select the Number link to drill down to the detailed Integration Run page.

You can view details like the number of events that were ingested, the status, which event that was transformed into a security incident, and the different tasks there were performed during the ingestion. Additionally, select
the link to view the flow execution details.

## Flow execution details {#arcsight-esm-troubleshoot__section_bpl_mlc_wkb}

Select the execution details link to see the flow associated with the event ingestion.

You can view a step by step execution of the flow detailing the various actions and subflows
that were executed as part of the flow.

*[\>]: and then


