---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Worknotes

# Security incident Response form after alert ingestion {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After a Microsoft Graph Security API alert has been ingested, a security
incident is created and the corresponding updates are made to the security incident record.

## Worknotes {#ms-graph-sir-changes__section_ilp_zhp_4kb}

If you had selected the Log work note for new alert option in the alert
Aggregation Criteria as described in the [Mapping alerts to security incident response fields](https://servicenow-prod.fluidtopics.net/vPbJI4ItshIqU~ObNMGqsQ "Map individual alert fields from triggered alerts to fields on a ServiceNow AI Platform security incident."), a
worknote is posted when the alert is aggregated.

Select the alert link to navigate to the internal alert import record that contains raw alert data.

## Aggregated alerts {#ms-graph-sir-changes__section_kwp_bnp_4kb}

Select Related ListsAggregated Microsoft Graph Security alerts to view the alerts aggregated to the security incident.

* Create security incident: Select an alert from the list, select the Actions menu and select Create security incident. This option creates a new security incident for the alert and this alert is de-aggregated from the parent security incident.
* Delete alert record: Select an alert from the list, select the Actions menu and select Delete. This option deletes the alert record.
{#ms-graph-sir-changes__ul_hsp_grs_llb}

*[\>]: and then


