---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# CrowdStrike Next-Gen SIEM integration

# CrowdStrike Next-Gen SIEM integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The CrowdStrike Next-Gen SIEM integration automatically ingests detection data that may indicate potential security incidents and streamlines the creation of security incidents in the ServiceNow® Security Incident Response (SIR), ensuring timely and effective response.

## Request apps on the Store {#crowdstrike-next-gen-integration-secops__id_x5z_swn_vfc}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#crowdstrike-next-gen-integration-secops__inline-send-to-store}

## Overview of CrowdStrike Next-Gen SIEM integration {#crowdstrike-next-gen-integration-secops__id_n5s_vwn_vfc}

See the following graphic to learn how CrowdStrike Next-Gen SIEM integrates with the ServiceNow AI Platform
Security Operations applications.  

<br />

## Key features {#crowdstrike-next-gen-integration-secops__section_eqb_yxs_qpb}

Use the key features of this integration to do the following actions:

* Discover CrowdStrike Next-Gen SIEM detections that are candidates for security incidents and automate the creation of these security incidents.
* Map CrowdStrike Next-Gen SIEM defect and entity fields to SIR security incident fields.
* Filter CrowdStrike Next-Gen SIEM defects.
* Aggregate incidents to existing open security incidents so that you don't have to create duplicate security incidents.
* Automate CrowdStrike Next-Gen SIEM detection status updates for Security Incident Response so that you can create and close security incidents.  
  Note:  
  ServiceNow updates the status of CrowdStrike Next-Gen SIEM detections based on the security incident creation or closure. This update also includes comments of aggregated detections and new detections.
* Schedule detection ingestion to create security incidents periodically.
* Synchronize CrowdStrike Next-Gen SIEM detection comments with SIR Work notes.
{#crowdstrike-next-gen-integration-secops__ul_l1q_zxs_qpb}

