---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Copy an event profile

# Copy an event profile for the Splunk Enterprise Security Event Ingestion
integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Copy an existing profile and its associated settings instead of creating new profiles.
If you are creating multiple profiles, and you want to reuse the settings of an existing
profile, you may prefer to copy alarm profiles to save time.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## About this task

If you copy a profile, the profile name is initially modified to avoid duplicate
profiles. In addition, the copied profile is deactivated (false) so it is not activated
accidentally prior to completing the configuration. Copy profiles and use existing maps
for security incidents that you have already previewed and verified.

## Procedure

1. Navigate to AllSplunk IntegrationSplunk Event Profile.
2. In the Splunk Event Profiles list that is displayed, select a profile that you want to copy, and, from the Actions on selected rows choice list, click Copy.  
   The profile is copied and displayed on the list. The copy has all the settings of the original profile including the mapping and scheduling configuration. The name of the profile contains copy. Although the original profile is activated (true), the copy is disabled at this point (false). You may prefer to edit values of the copied profile and rename it so the configuration settings apply to the new profile as required.

   You have successfully copied the settings from an existing profile to a new profile.
{#splunk-event-ingest-copy-a-profile-security__steps_nb3_4r1_zfb}

## What to do next

You are prompted to activate (enable) the new profile after you complete the
configuration step.

*[\>]: and then


