---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Trigger a FireEye capability profile from Related Links

# Trigger a FireEye capability profile from Related Links {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Trigger a capability profile manually after reviewing a security incident from
related links.

## Before you begin

Role required: sn_si.admin or sn_si.analyst

## Procedure

1. Navigate to Security IncidentsShow All Incidents.
2. Select the security incident that you want to review.
3. Click Run EDR Profile(s)in the related links section.  
4. Browse and select a profile from the list of available profiles and click Submit.  
5. The selected profile is triggered manually.
6. Review the work notes and activities section.
7. View the tags and check the related lists for the data.  
   Note:  
   In addition to running the profile for the CI or the Alternate CI of the security incident, you could also run the profile for CI values present in the Configuration Item Related list by checking the Include Related CI on the dialog box. This will fetch data for the CI values present in the related list as well. Alternatively, you could run the profile just for the CI values present in the related list.

*[\>]: and then


