---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a detection profile

# Create a detection profile {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Important:  
If no correlation rules are configured in the CrowdStrike portal, the detection profile may display a generic "No active correlation rules found. Please ensure that correlation rules are configured, activated, and published in your Crowdstrike environment" message in ServiceNow® instance. To avoid this issue, confirm that at least one correlation rule is created in the CrowdStrike portal before configuring the ingestion profile.

## Procedure

1. Navigate to AllCrowdStrike Next-Gen SIEMDetection Profile.
2. Select New.
3. On the form, fill in the fields.  
   {#create-a-profile-cs-ng-siem__table_kyc_qbg_p4b__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the profile. This name is also the default name for the security tag associated with this profile. |
   | Active | Option for making the profile active. When a profile is active, the ServiceNow AI Platform actively polls CrowdStrike Next-Gen SIEM detections and corresponding security detections are created in Security Incident Response when the filtering conditions are matched. |
   | Source | CrowdStrike tenant that you configured to ingest detections. If you have multiple tenants configured, select the appropriate tenant for the detection types you are planning to ingest for the profile. |
   | Order | Priority in which the profiles are executed when two or more profiles share triggering conditions. Priority values are usually provided as 100 (the default value), 200, 300, and so on. The profile with the lowest number has the highest priority. |
   | Description | Optional description of the profile. |
   [Table 1. CrowdStrike Next-Gen SIEM - Detection Ingestion Configuration form]

   {#create-a-profile-cs-ng-siem__table_kyc_qbg_p4b}
4. Select Update .  
   The initial detection profile is created with basic information. Saving the profile at this point enables you to continue with defining the profile in case you are interrupted.
5. **Optional:** Continue with the profile definition process immediately.
   1. On the CrowdStrike-Nextgen Detection Profiles page, select the profile you just created.
   2. In the progress bar, select Correlation Rules.
   {#create-a-profile-cs-ng-siem__substeps_gd3_rct_zfc}

## What to do next

[Set correlation rules](https://servicenow-prod.fluidtopics.net/4Q_dd54jyCW53MLsXB3~Ug "After creating a CrowdStrike Next-Gen SIEM detection profile, select correlation rules to map corresponding detections to a security incident. Correlation rules are refreshed every time a profile is opened and new rules are available for selection. The CrowdStrike Next-Gen SIEM integration supports multiple profiles.")

*[\>]: and then


