---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Mapping

# Mapping {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After selecting the LogRhythm source that you want to ingest, you need to
map individual LogRhythm alarm fields to the ServiceNow AI Platform security
incident fields.  
Mapping alarms includes the following tasks:

* Map LogRhythm alarms. For this task, you list and ingest (Pull) sample alarms using the alarm IDs or most recent alarms from the LogRhythm client console.
* The Sample Alarm fields are categorized into three groups:
  * Alarm fields: The alarm fields that are available and their corresponding values are displayed.
  * Event fields: The event fields that are available and their corresponding values are displayed.
  * DrillDownLog fields: The drilldown log fields that are available and their corresponding values are displayed.
  {#mapping-logrhythm__ul_btr_rct_1tb}
* Each Alarm ID that you pulled is displayed as a tab. On the Alarm ID tabs, verify that all critical alarm fields from the Alarm Sample Ingestion section on the left of the form are mapped to the SIR Incident Field Mapping section on the right of the form.
* After you map the alarms to the SIR Incident Field Mapping field, you can see the alarm category also being display in the Input Expression field. For example, <kbd class="ph userinput">${Alarm: alarmid}$</kbd>.
* You can modify the configuration by adding or removing fields on the security incident. Track overlooked or duplicated fields with the color coding that is provided.
* You can filter alarms to specify which alarms are ingested into the SIR application. You can either filter the alarms directly or use the alarm categories to drill down your search based on Alarms, Events, or DrillDownLogs.
* Use the script editor if you want to format values for the Priority and Category fields on the security incident.
{#mapping-logrhythm__ul_knq_43l_f2b}

The next step is to [Map LogRhythm alarm fields to security incident fields](https://servicenow-prod.fluidtopics.net/w6gd1PMXgjjqSTtmEQ8O~g "You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.").
* **[Map LogRhythm alarm fields to security incident fields](https://servicenow-prod.fluidtopics.net/w6gd1PMXgjjqSTtmEQ8O~g)**   
  You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.

**Related tasks**   

* [Map LogRhythm alarm fields to security incident fields](https://servicenow-prod.fluidtopics.net/w6gd1PMXgjjqSTtmEQ8O~g "You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.")
* [Use the script editor to format LogRhythm values](https://servicenow-prod.fluidtopics.net/FU~SHnefTHeZOyl2RXy0Gg "In addition to the directly mapped fields from the pulled alarm values, and the alarm values you enter manually, you can use the script editor to format field values on the security incident during the mapping step which is optional.")
* [Filter alarms for LogRhythm](https://servicenow-prod.fluidtopics.net/4fL2GQ1Am7OIz6jV1j_EkQ "Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.")

