---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure profile settings

# Configure profiles and security incidents for the CrowdStrike Falcon Insight integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Configure your profile settings so that the profile triggers only under the
conditions that you set.

## Before you begin

Role required: sn_si.admin

## About this task

Define the conditions that automatically trigger the CrowdStrike Falcon Insight capabilities that you selected for the profile. You can also select an alternate input field for the Configuration Item (CI) field. In this alternate field, you can set filtering conditions so that only those security incidents that are related to your triggering event automatically trigger the profile.  
Note:  
Navigate to the Profile Configuration page only after you enter the profile details. For more information, see [Create a capability profile for the CrowdStrike Falcon Insight integration](https://servicenow-prod.fluidtopics.net/QWjHK852PDfbxcf4ihuf3A "Create a profile and select the CrowdStrike Falcon Insight capabilities that you want the profile to run.").

## Procedure

1. In the Profile Configuration page, review and configure the following sections:  
   Define Incident Criteria (Automation)

   Define the security incident conditions that automatically trigger the CrowdStrike Falcon Insight capabilities for the profile. If you don't select the Define Incident Criteria option, the capabilities are invoked manually from the security
   incident.
   1. Select the Define Incident Criteria option.
   2. To define the conditions, in the Filter Conditions section, select a field and its corresponding requirement.
   3. In the New Criteria field, enter the new criteria and then define the OR or the AND condition.

   {#configure-profiles-and-security-incidents-for-the-crowdstrike-falcon-insight-integration__substeps_rrw_b1n_p4b}  
   Approvals

   To provide an extra level of control when you're using the CrowdStrike Falcon Insight capabilities, select the Require Approval option. The approvals option in the profile configuration appears only
   for the Isolate Host and Remove Host Isolation capabilities.  
   Note:  
   The approval authority is assigned to the user with the sn_si.admin role. You can also reassign this approval authority to an approval group. For more information, see [set up an approval group](https://servicenow-prod.fluidtopics.net/~OB0buAF7cvw6hTKaYLS_A "Create an approval group for the CrowdStrike Falcon Insight for Security Operations integration that can approve requests for isolating host machines, restoring them to the network, and initiating sightings searches.").

   Additional Configuration

   Select an alternate field on the security incident to display any matching CI data that you find while scanning your assets. By default, the integration uses the Configuration Item (CI) field on the security incident.
   1. Select the Define Alternative Field option.
   2. In the Alternate CI Trigger Field, select an input field.  
      Note:  
      For more information, see [Understand how trigger conditions work with a configuration item for a profile](https://servicenow-prod.fluidtopics.net/tEcPscjHWYmidgWOKTFjrw "You can configure the profile settings so that a profile runs only when a set of specific conditions is met or you can set up a profile to search for specific field values on a security incident.").

   Tags  
   To tag security incidents with the CrowdStrike Falcon Insight Capabilities- Initiated, and Capabilities-Completed, and Capabilities-Failed tags, select the Display Tags option. By default, this option is disabled for all profiles.  
   Note:  
   These tags are provided with the base system. You can create your own tags if required.

2. Click Done.

