---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create process mining project for security incidents

# Create process mining project for security incidents {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a project in Process Mining Workspace using the pre-build process models definitions from the content pack to scan through audit logs of security incident records and identify inefficiencies in your security incident
life cycle.

## Before you begin

Role required: sn_process_optimization_analyst and sn_si_read

## Procedure

1. Navigate to AllWorkspacesProcess Mining Workspace.
2. Select Create New Project.  
   The Step objectives page opens.
3. Enter a process mining project name in Name.
4. **Optional:** Add a short description about your project in Short Description.
5. Select Source Type as Table.
6. Select the <kbd class="ph userinput">Security Incident (sn_si_incident)</kbd> in Table.
7. Select the default template, and then select Create project.  
   The project dashboard appears with all the configured settings.
8. Select the edit (![Edit icon]()) icon corresponding to Scope of the analysis and configure the filters to set the number of records to mine.  
9. Select Select improvement opportunities and configure the improvements for your security incidents.  
   A list of improvement opportunities displays. For information about configuring improvement opportunities, see [Setting improvement opportunities](https://www.servicenow.com/docs/access?context=working-with-imp-opp&version=australia&pubname=australia-now-intelligence&ft:locale=en-US).
10. Select Review and mine and then select Mine project.
11. Select Sample mine or Full mine.
12. Select Confirm \& Mine to start the mining.  
    The mining starts and the status of mining is displayed.

*[\>]: and then


