---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Schedule detection retrieval

# Schedule detection retrieval {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure a schedule to define how and when you pull detections from the CrowdStrike Next-Gen SIEM tenant.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin because the sn_si.admin role inherits the required permissions by default.

## Procedure

1. If you are not continuing from the previous section of the Filtering and Aggregation criteria, access the profile you are defining.
   1. Navigate to AllCrowdStrike Next-Gen SIEMDetection Profile.
   2. Select the profile you are continuing to define.
   3. Select Scheduling in the progress bar.
   {#schedule-retrieve-and-ingest-inc-data__substeps_qbv_p2t_zfc}
2. On the scheduling form, fill in the fields.  
   {#schedule-retrieve-and-ingest-inc-data__table_kyc_qbg_p4b__entry__2}

   | Field | Description |
   |-|-|
   | Ongoing detection ingestion | Option to set ongoing detection ingestion that the ServiceNow AI Platform instance pulls from the CrowdStrike Next-Gen SIEM tenant for new detections. Security incidents are created if triggered detections are found and the detection generation filtering criteria matches. |
   | Polling increment (minutes) | Polling frequency defined in minutes. |
   | Set detection ingestion time | Option to add Date and time for the initial ingestion. |
   | Initial detection ingestion time | Date and time that you specify for the detection ingestion. |
   | One-Time Retrieval | Option to enable one-time retrieval of historical CrowdStrike Next-Gen SIEM detections and followed by the reconciliation of the data. When processing the data, both ongoing detections and historical data are pulled. Note: The retrieved historical CrowdStrike Next-Gen SIEM detections undergo de-duplication checks to avoid any duplicates within the Security Incident Response application. |
   | Since date | The date since historical detections were ingested from CrowdStrike Next-Gen SIEM. |
   [Table 1. CrowdStrike Next-Gen SIEM Scheduling form]

   {#schedule-retrieve-and-ingest-inc-data__table_kyc_qbg_p4b}
3. Select Continue.

## What to do next

[Automate detection updates and closures](https://servicenow-prod.fluidtopics.net/vvTt66GxV7wzJxjjl9Sqvg "Automate detection updates and closures based on the Security Incident Response incident status. The CrowdStrike Next-Gen SIEM integration enables detections to create security incidents and also to update the incidents after they are created or closed.")

*[\>]: and then


