---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up a profile for scheduled notable event ingestion

# Set up a profile for scheduled notable event ingestion {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Depending on the profile defined, Splunk ES notable events are
automatically ingested into the Security Operations environment of your ServiceNow AI Platform
instance.

The following table shows the list of tasks you need to follow to set up a profile for
scheduled ingestion of notable events:
{#splunk-event-scheduled-security__table_zs4_1xf_4jb__entry__2}

| Task | Section |
|-|-|
| Create an event profile | See [Create a profile](https://servicenow-prod.fluidtopics.net/yQlNfix8NhVebFDW4PqDBg "You can set up a profile so that notable events are automatically ingested.") |
| Select notable events based on correlation search name | See [Set Correlation rules](https://servicenow-prod.fluidtopics.net/1bWDoxD8f~Vvi9kolzZ4QA "After you have created a profile for a scheduled notable event type ingestion, select a Splunk Enterprise Security correlation rule name for this profile for which you want to map corresponding notable events to a ServiceNow AI Platform Security Incident Response security incident.") |
| Map notable event fields | See [Explore Mapping](https://servicenow-prod.fluidtopics.net/~jVPeN6fYvIBBDbCEuqhMg "After you identify the specific correlation rule and notable event type for the profile, the next step is to map individual notable event fields to the fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") |
| Create custom mappings | See [Map notable events](https://servicenow-prod.fluidtopics.net/S8Q5JE6V8DjCGdcO_0DVkg "During the notable event field-mapping step, you map individual event fields from notable events to fields on a ServiceNow AI Platform Security Incident Response (SIR) security incident.") |
| Preview the security incident | See [Preview security incident](https://servicenow-prod.fluidtopics.net/tlAekcp9oiqAvnlFmHL0Lw "After you complete the mapping step, preview the values that you mapped in a ServiceNow AI Platform Security Incident Response (SIR) security incident. This preview step permits you to verify that you have mapped all the notable fields that you want displayed on the security incident.") |
| Schedule and retrieve new and updated notable events | See [Schedule and retrieve notable events](https://servicenow-prod.fluidtopics.net/6IDa1YGM4R4SN5ikq0bcTQ "For automated notable event ingestion profiles, this step is required in the event profile configuration. During this step, you can verify the default settings for notable event retrieval or modify the scheduling as needed. This step also permits you to retrieve historical notable events using a date range.") |
| Automate notable event updates and closure based on SIR incident status | See [Automate notable event updates and closures](https://servicenow-prod.fluidtopics.net/BGqQIovgiKdXpnCPZ_cynQ "Security incidents can be created and updated after they are created with a bi-directional interface with the Splunk Enterprise Security integration.") |
[Table 1. Steps to set up a profile for scheduled notable event ingestion]

{#splunk-event-scheduled-security__table_zs4_1xf_4jb}

