---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Configure HPE Security ArcSight ESM - Email Parser integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

HPE Security ArcSight ESM - Email Parser integration uses email notifications from
ESM to drive enrichment, and response workflows.

## Before you begin

Role required: sn_si_admin

## About this task

An HPE Security ArcSight ESM - Email Parser template is provided to use for the
integration. It must be configured and activated before the integration takes place.
Updating the parser activates it.

## Procedure

1. Navigate to AllSecurity OperationsIntegrationsIntegration Configurations.  
   The available security integrations appear as a series of cards. {#configure-arcsight-emailparser__Nav-To}
{#configure-arcsight-emailparser__Nav-To}
2. In the HPE Security ArcSight ESM - Email Parser card, select Configure.
3. In the HPE Security ArcSight ESM - Email Parser Configuration dialog box, select the Configure Email Parser link.
4. Select the ArcSight ESM link to edit the settings in the template email parser provided.  
   At a minimum, fill in the `Email is from` field. To create you own email parser, see [Create email parsers in Security Operations](https://servicenow-prod.fluidtopics.net/ad9vca3b1Z_0QW33EljMRg "Email Parsing creates Security Operations records from your email for security, vulnerability, and observables to expedite threat response and remediation.").
5. Check the Active box.
6. Select Update in the Email Parser form.  
   The email parser is active. You do not need to return to Integration Configurations.
{#configure-arcsight-emailparser__steps_gfz_1yn_vw}

*[\>]: and then


