---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up instance

# Set up your ServiceNow AI Platform instance for the IBM QRadar
offense ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The following section lists the setup tasks that you are required to complete in your
ServiceNow AI Platform® instance prior to installing the application from the ServiceNow Store.

## Before you begin

Role required: sn_si.admin

## About this task

Refer to the following table and verify that you have completed all the listed tasks
before you download and install the application to ensure a smooth installation and
configuration.
{#qradar-ibm-setup-sn__table_evy_hpv_3fb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform® and Security Incident Response (SIR) roles. | The following roles are required for the installation, setup, and use of the integration in your ServiceNow AI Platform® instance. * A user with the ServiceNow AI Platform® administrator role (admin) installs the application from the ServiceNow Store and assigns the security incident administrator (sn_si.admin) role. * A user with the sn_si.admin role oversees the following tasks in the ServiceNow AI Platform®: * Names, creates, and edits offense profiles. * Selects and maps IBM QRadar offense data fields to the security incident fields. * Previews security incident details for accuracy prior to finalizing the configuration. * Schedules on-going offense ingestion. * Enables offense updates when a SIR incident is created and closed. * Assigns the security incident analyst (sn_si.analyst) role. * Users with the sn_si.analyst work with security incidents. {#qradar-ibm-setup-sn__ul_gvy_hpv_3fb} {#qradar-ibm-setup-sn__ul_fvy_hpv_3fb} For more information about roles and assigning roles to users, see Roles on the [Servicenow Product Documentation website](https://www.servicenow.com/docs). |
| Verify that you are using the following versions: * IBM QRadar version 7.3.2 or later. * IBM QRadar API version 10 or later. {#qradar-ibm-setup-sn__ul_i5l_p1v_4lb}Earlier versions are not supported. | If you have access to the IBM QRadar console, you have access to the API that is required for this integration. There is no other special setup required for the API. |
| Verify that you have installed and configured a MID Server Application. | Configured MID Server Application. A MID Server in your ServiceNow AI Platform® instance is required to connect to the IBM QRadar service if the IBM QRadar server is deployed within your corporate network. See the [ServiceNow Product Documentation website](https://www.servicenow.com/docs) for information about MID Servers. If you are using the IBM QRadar Cloud service, a MID Server is not required. |
| Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you install the application for the integration. | Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. 1. Security Incident Response 2. Event and Alert Ingestion for Security Operations: This application requires: * com.glide.hub.integration.runtime =\> ServiceNow IntegrationHub Runtime * com.glide.hub.action_step.rest =\> ServiceNow IntegrationHub Action Step - REST {#qradar-ibm-setup-sn__ul_kd4_lbn_4lb} Note: The Integration Hub components are installed along with the Event and Alert Ingestion plugin. If these are not installed, contact Customer Support for assistance. {#qradar-ibm-setup-sn__ol_qwy_vrt_fhb} For more information about installing the Security Operations core applications, see [Get entitlement for a Security Operations product or application](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
[ ]

{#qradar-ibm-setup-sn__table_evy_hpv_3fb}

## What to do next

You have successfully set up your ServiceNow AI Platform® instance for the
integration. The next step is to install the IBM QRadar application
from the ServiceNow Store for the integration.

