---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Tag security incidents with the Sandbox submission status

# Tag security incidents with the Sandbox submission status {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Tag security incidents with the Submission Initiated and Submission Complete tags.

When you select the Display tags option in the [Sandbox submission configuration](https://servicenow-prod.fluidtopics.net/q3Fhm5wlm9xMwFA04RFclQ "Set up the Sandbox configuration to define the analysis environment and runtime options for your security incident record submissions for the malware analysis."), tags are displayed to provide the status of a file or URL submission. Checking the status this way is useful because the sandbox analysis
may take several minutes to process.

The display tags are called submission initiated, submission completed, and submission failed.  
The following example shows a security incident where the submission has been initiated. Figure 1. Submission Initiated- Security Incident  
The following example shows a security incident where the submission has been completed.Figure 2. Submission Completed- Security Incident

