---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a relationship graph for an incident

# Create a relationship graph for an incident {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related
information.

## Before you begin

Role required: sn_si.analyst

## About this task

For information about how to create a customized relationship graph rather than using a predefined graph, see [Customize a relationship graph](https://servicenow-prod.fluidtopics.net/xkQz27gjvxd266Qq3C4P8g "Visualize and analyze security incidents and their associated data in a relationship graph.").  
Note:  
Changes to the relationship graph aren't saved automatically.

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Open a security incident.
3. Select the Relationship Graph tab.
4. In the relationship graph, select and hold (or right-click) the parent node, and then select Add Nodes.
5. Select one or more category nodes to display in the relationship graph, such as Related users, Affected CIs, similar security incidents (SIRs), or Affected Users.  
   Note:  
   You can select multiple category nodes.
6. Select and hold (or right-click) a category node and select Link Nodes to add data associated with the category node.  
   Note:  
   You can apply filters to reduce the number of items in the list.  
   A list of all related records for the selected category node appears. For example, if you select Affected Users from the node category, a list of all the users affected by this incident displays.
7. Select the desired records from the list and select Add.
8. Select Add.
9. **Optional:** Clear changes if necessary by selecting Refresh.
10. Select Save.  
    Note:  
    Changes to filters are also saved when you save the relationship graph.
11. **Optional:** Display the details of a subnode.
    1. Select a subnode.
    2. Select Show Details.
    {#create-relationship-graph-sir__substeps_m4w_f1j_mfc}
12. **Optional:** Download the map to your system.
    1. If only a portion of the map is visible on the screen and you want the whole screen to be included in the PDF, select the Fit to screen icon (![Fit to screen icon]()).  
       Note:  
       Only the portion of the map that appears on the screen is included in the PDF file.
    2. Select the export map icon (![Export relationship graph icon]()).
    {#create-relationship-graph-sir__substeps_av4_2z3_mfc}

## Video showing how to edit a relationship graph to add category nodes and subnodes {#create-relationship-graph-sir__example_pm3_pqg_vfc}

*[\>]: and then


