---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up a profile for manual event forwarding

# Set up a profile for manual event forwarding {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Depending on the profile defined, Splunk ES notable events
are forwarded manually as discrete notable events into the Security Operations
environment of your ServiceNow AI Platform instance.

To set up a profile for manual forwarding of notable events:
{#splunk-event-manual-security__table_zs4_1xf_4jb__entry__2}

| Task | Section |
|-|-|
| Create an event profile | See [Create a profile](https://servicenow-prod.fluidtopics.net/1FIaiavquwdDvq5P0Wf5YQ "You can set up a profile for manual forwarded events.") |
| Map notable event fields | See [Explore Mapping](https://servicenow-prod.fluidtopics.net/~jVPeN6fYvIBBDbCEuqhMg "After you identify the specific correlation rule and notable event type for the profile, the next step is to map individual notable event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") |
| Create custom mappings | See [Create mappings for Splunk ES notable event incident review and contributing event details (manual forwarding)](https://servicenow-prod.fluidtopics.net/~rNKJRN50J7hRcXEukxbtg "During the notable event field mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") |
| Preview the security incident | See [Preview security incident](https://servicenow-prod.fluidtopics.net/tlAekcp9oiqAvnlFmHL0Lw "After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the notable fields that you want displayed on the security incident.") |
| Set up your Splunk environment for manual ingestion | [Create a profile](https://servicenow-prod.fluidtopics.net/1FIaiavquwdDvq5P0Wf5YQ "You can set up a profile for manual forwarded events.") |
| Automate notable event updates and closure based on SIR incident status | See [Automate notable event updates and closures](https://servicenow-prod.fluidtopics.net/BGqQIovgiKdXpnCPZ_cynQ "Security incidents can be created and updated after they are created with a bi-directional interface with the Splunk Enterprise Security integration.") |
[ ]

{#splunk-event-manual-security__table_zs4_1xf_4jb}

