---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Preview security incident

# Preview security incident for the Splunk Enterprise Event Ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform®
Security Incident Response (SIR) security incident.
This preview step permits you to verify that you have mapped all the alert fields that you
want displayed on the security incident.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## About this task

Preview a security incident and edit the mapping again as required to fix fields with
errors or to populate any missing data. If the preview is not successfully completed,
you cannot proceed to the scheduling step. Previews of SIR security incidents are not saved as actual incidents
in the SIR product.

## Procedure

1. If the security incident preview is not displayed, select Preview in the progress bar.
2. Select the Alert Name and then select an item from the Sample Alert IDs list.  
   The security incident is displayed. Do not change any information in the fields.
   This view is a read-only view, and a record of this security incident is not
   saved.
3. Review the field mapping of the alert values on the security incident.  

   The preceding image is an example of a preview with a mapping error. In this example, a field on the security incident does not exist for a value, or the field does not support the value that you mapped.
4. To resolve this error, select Mapping in the progress bar.
5. Edit the mapping to fix incorrect values or populate any missing data.
6. Preview the mapping again and continue to fix any errors that are described in error messages.  
   The following figure is an example of the Incident Details tab on the bottom half
   of a SIR security incident after all error
   messages are resolved. For this example, the Description and Work notes fields
   were mapped, and these fields are populated with the values from the value pairs
   pulled from the Splunk Enterprise console. The first Work notes
   field has no value. This field was left empty on the mapping grid during the
   mapping step. The additional Work Note fields that have values were added to the
   mapping grid during the mapping step.  
   Note:  
   The Profile Preview section displays related items for Unmatched Affected User and Unmatched Configuration Item when matching CMDB or identity records are not found. After ingestion, Security Incident records show Unmatched CI in the Configuration Items related list and Unmatched Affected Users in a dedicated related list, ensuring complete visibility of affected entities throughout the incident life-cycle.
7. After you have fixed any errors and verified that the fields are the way you want them, choose one option to continue.

   | Option | Description |
   | Continue | The Scheduling form is displayed for profiles with scheduled alerts. Scheduling is selected on the progress bar. |
   | Finish | For profiles with configured for manual event forwarding, click Finish. There is no scheduling step for profiles with event data that are exported on-demand directly from the Splunk Enterprise console. |
   | Update | Your data is saved, and you are returned to the Splunk Event Profiles list. |
   | Previous | The Mapping step on the progress bar is displayed. |
   | Delete | Delete this event profile and the Splunk Event Profiles list is displayed. |
   |-|-|

   {#splunk-event-ingest-preview__choicetable_svs_ttl_kdb}

## What to do next

If no error messages are displayed, and you are satisfied with the field mapping on the
security incident, the next step is to [Schedule and retrieve alerts for the Splunk Enterprise Event Ingestion integration](https://servicenow-prod.fluidtopics.net/QzEbpAlPeGW5QVBXYujLJQ "For automated alert ingestion profiles, this step is final step of the event profile configuration. During this step, you can verify the default settings for alert retrieval or modify the scheduling as needed. This step permits you to filter your alert retrieval based on a date range.").

