---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security incident creation

# Security incident creation {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Security incidents can be created manually from the form, or automatically via security
events received from integrated third-party alert monitoring tools, such as Splunk.  
Important:  
The latest features in Security Incident Response are exclusively available in the Security Incident Response Workspace. Install or upgrade to the latest Security Incident Response or Security Incident Response Workspace version to access and leverage features such as Shift-Handover, Risk Score Calculator, and so on.
If you have a security role, you can use any of the following methods to manually create
security incidents.  
{#si-creation__table_b5j_jj1_ks__entry__2}

| Method | Description |
|-|-|
| [Manually created from the Security Incident list](https://servicenow-prod.fluidtopics.net/hRLl9dw7~RuP3HDYtHJlEg "In addition to automatic methods for creating security incidents, you can create them manually, as needed.") | On the Security Incident list, select New to create a new security incident. |
| [Manually created from the Security Incident Catalog](https://servicenow-prod.fluidtopics.net/pwx9erWKXRdKZ8FoyFVhbA "Users in your company can use the Security Incident Catalog to request various types of security-related analysis.") | You can create security incidents by selecting from categories of security threats defined in the security incident catalog. |
| [Incident Management](https://www.servicenow.com/docs/access?context=c_IncidentManagement&version=australia&pubname=australia-it-service-management&ft:locale=en-US) | On the Incident form in incident management, select Create Security Incident to create a new security incident. Note: You can avoid duplicate security incidents creation by enabling the `sn_si.disable_duplicate_security_incident` system property. |
| [Manually converted from a security request](https://servicenow-prod.fluidtopics.net/whCjmC2RyNgA7qFwIy9R_Q "Unlike security incidents, inbound requests are generally of a lower priority. Requests for a lookup, scan, or a new badge are examples of inbound requests.") | On the Security Request form, select Convert to Security Incident to create a new security incident. |
| [Manually created from an Event Management alert](https://servicenow-prod.fluidtopics.net/CbO7S7imdMLRYJZVmVxUWg "When Event Management is activated, you can manually create security incidents from the Alert form.") | On the Event Management Alerts form, select Create Security incident to create a new security incident from an alert. |
| [Manually created from an alert](https://www.servicenow.com/docs/access?context=t_CreateAnAlertFromAnIncident&version=australia&pubname=australia-it-service-management&ft:locale=en-US) | On the Event Management Alert form, select Create Security Incident to create a new security incident. |
| Manually converted from a vulnerability record (if the Vulnerability Response plugin is activated) | On the Vulnerability Items form, select Create Security Incident to create a new security incident. |
[Table 1. Methods for manually creating security incidents]

{#si-creation__table_b5j_jj1_ks}

## Automatic creation of security incidents {#si-creation__section_wsw_f3k_hbb}

Generally, security administrators are responsible for setting up alert rules to automatically generate security incidents.  
{#si-creation__table_kml_pqt_zs__entry__2}

| Method | Description |
|-|-|
| [Automatically created using alert rules](https://servicenow-prod.fluidtopics.net/pKdV0k93wOcBCVS~AERWvA "As events are imported from alert monitoring tools, they are first processed by Event Management and grouped into alerts. These alerts can be used to create security incidents based on customizable alert rules, or manually reviewed to select those alerts to be investigated as a security incident.") | Security incidents can be created based on alert rules defined in the [Event management in your data center](https://www.servicenow.com/docs/access?context=c_EM&version=australia&pubname=australia-it-operations-management&ft:locale=en-US) application. |
[Table 2. Security admin method for creating security incidents]

{#si-creation__table_kml_pqt_zs}

