---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure

# Install and configure {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install and configure the CrowdStrike Next-Gen SIEM integration for Security Operations application from the ServiceNow Store on your ServiceNow AI Platform instance.

## Before you begin

Role required: sn_si.ingestion_profile_admin

Minimum scopes needed to configure CrowdStrike Next-Gen SIEM in ServiceNow® instance include:
{#cs-ng-siem-integration__task-prereq__entry__2}

| Action | Scope Needed |
|-|-|
| Fetch Detections | Alerts- Read |
| Update Comments/State | Alerts- Write |
| Create Search Query Job | NGSIEM- Write |
| Fetch Search Query Job | NGSIEM- Read |
| Fetch Correlation Rules | Correlation Rules- Read |
[ ]

## Procedure

1. Download the CrowdStrike Next-Gen SIEM integration from the ServiceNow Store and install it.  
   For more information, see [Download an application from the ServiceNow Store for the first time](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.")
2. Navigate to Security OperationsIntegrationsIntegration Configurations.
3. Search for the CrowdStrike Next-Gen SIEM integration tile, and select Configure.
4. On the form, fill in the fields.  
   {#cs-ng-siem-integration__table_evw_xjl_gxc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the CrowdStrike Next-Gen SIEM integration. |
   | Client ID | The client ID that you obtain from the settings section of your account profile in the CrowdStrike portal. |
   | Client Secret | The client secret key that you obtain from the settings section of your account profile in the CrowdStrike portal. |
   | Region | Data center to pull data from. Specify the Region: US-1, US-2, EU-1, US-GOV-1, US-GOV-2 By default, the field is set to US-1 |
   [Table 1. CrowdStrike Next-Gen SIEM integration form]

   {#cs-ng-siem-integration__table_evw_xjl_gxc}
5. Select Submit.  
   The configured integration tile displays.

## What to do next

[Create a detection profile](https://servicenow-prod.fluidtopics.net/yUz4qH8AwHF2wmfVlGFaaA "Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.")

*[\>]: and then


