---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# View and reprocess unmatched Security Operations emails

# View and reprocess unmatched Security Operations emails {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can review Unmatched Emails
for discontinued filters or as candidates for a new filter to maintain or improve the rate
at which you catch email threats.

## Before you begin

Role required: sn_sec_cmn.read

## Procedure

1. Navigate to AllSecurity OperationsUnmatched Emails.  
   If any unmatched emails have been found, they are listed.
2. The fields on the form are as follows:  
   {#viewing-reprocessing-unmatched-emails__table_vks_thr_ns__entry__2}

   | Field | Description |
   |-|-|
   | From | Email address of the sender. |
   | To | Email address of the recipients. |
   | Subject | Subject line in the email. |
   | Body | Contents of the body of the email. |
   | Matched | Indicates if this email event was matched. |
   [Table 1. Security email events]

   {#viewing-reprocessing-unmatched-emails__table_vks_thr_ns}
3. To reprocess this email, create an email record or edit an existing email record to match the information in this email.  
   See [Create email parsers in Security Operations](https://servicenow-prod.fluidtopics.net/ad9vca3b1Z_0QW33EljMRg "Email Parsing creates Security Operations records from your email for security, vulnerability, and observables to expedite threat response and remediation.").
4. Navigate back to Security OperationsUnmatched Emails.
5. Click Reprocess Email Event to attempt to process this email.  
   It returns you to the Unmatched Emails main list. If the new email record matches, the email event is no longer in the list. A message indicates if it was matched or not.
{#viewing-reprocessing-unmatched-emails__steps_rlb_yvs_zv}

*[\>]: and then


