---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Filter alarms for LogRhythm

# Filter alarms for LogRhythm {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Setting filtering criteria for alarms after you have mapped fields helps you
determine which alarms should be ingested into the SIR application. Filtering alarms helps
you significantly reduce the number of alarms you ingest when the alarm profile is
activated.

## Before you begin

Role required: sn_si.admin

## About this task

Use the filtering conditions at the bottom of the mapping form to filter out specific alarms or limit ingestion to only alarms that meet certain field-level criteria. Filtering significantly reduces the number of alarms you ingest once the alarm profile is activated. Use filtering to ingest a manageable quantity of alarms that your Security Operations Center (SOC) staff can support.  
Note:  
The following example shows a default filter setting in which Alarm status-does-not-contain-Closed is the default setting. This filter only pulls active alarms, and this setting reduces the number of pulled alarms. The following steps illustrate how to add another useful filter which includes only alarms with the highest severity or priority values.

## Procedure

1. To edit the filtering criteria, select the Filter based on conditions check box.  
2. To the right of the Filter conditions field, click OR or AND.
3. In the new line that is displayed, select the filtering conditions from the choice lists.  
   The following image shows an additional filter added to the criteria in which
   risk-based priority (RBP max) is greater than
   50. With this filter setting, only LogRhythm alarms with
   a risk-based priority value that is greater than 50 are pulled.
4. After you have verified that all critical LogRhythm alarm fields are mapped to the ServiceNow AI Platform security incident, and you have set filtering criteria to limit alarm ingestion, choose one to continue the configuration.

   | Option | Description |
   | Continue or Preview | The Preview form of the security incident with your mapping configuration is displayed. Preview is selected on the progress bar. The next step is to view the security incident with your mapped alarms. |
   | Update | Save your data and return to the Alarm Profiles list. |
   | Previous | The alarm profile record is displayed. |
   | Delete | Delete this alarm profile and the Alarm Profiles list is displayed. |
   |-|-|

   {#filter-alarms-logrhythm__choicetable_r4p_krl_f2b}

## What to do next

The next step is to preview your mapped fields on the security incident. See [Previewing the security incident with mapped LogRhythm alarm values](https://servicenow-prod.fluidtopics.net/T4QRClEUt6W5BKWKgZ3P5w "After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident.").

