---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Map offense fields

# Map offense fields {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you have selected the rules, the next step is to map offense, event, or flow
fields to the fields in the security incident form.

## Overview of Mapping {#qradar-ibm-create-profile-about-mapping__section_uwl_j5p_nkb}

For the mapping step, you must first ingest sample offenses for one or more selected IBM QRadar rules. Then you must ensure that all relevant offense field data is
mapped to the appropriate place on the SIR incident form and
then visualize the SIR incident in the preview section.  
Mapping of the sample offense fields involves the following:

* Fetching and populating of the sample data: See [Ingesting the sample IBM QRadar offenses](https://servicenow-prod.fluidtopics.net/78h1C6wJW5eN1WIs9hdwkg "You can ingest sample offenses for one or more selected IBM QRadar rules.").
* Mapping the offense fields to the security incident: See [Mapping IBM QRadar offense fields to security incident response fields](https://servicenow-prod.fluidtopics.net/Go_Bih_d4nRuqw_6kxKi~g "Map individual offense, event, and flow fields to fields on a ServiceNow AI Platform SIR security incident.").
{#qradar-ibm-create-profile-about-mapping__ul_txr_n4v_wkb}

