---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Create an Agent Client Collector Security Incident Response command

# Create an Agent Client Collector
Security Incident Response command {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define a command or command string to be executed on a machine referenced by a
security incident. Commands are listed by operating system. For example, a
ps command on a Windows OS retrieves the status of active Windows OS
processes in the system.

## Before you begin

Role required: sn_si.admin

## Procedure

1. Navigate to AllAgent Client Collector SIR IntegrationACC Integration Commands.
2. Select New.  
   The ACC Integration Commands - New Record page appears.
3. Configure the fields on the page.  
   {#acc-create-command__table_ngg_y4s_hsb__entry__2}

   | Field | Description |
   |-|-|
   | Name | A descriptive name for the command. |
   | Operating System | The CI's operating system supported by the Agent Client Collector. |
   | Command | The actual command or command string to be executed. |
   [Table 1. ACC Integration Commands]

   {#acc-create-command__table_ngg_y4s_hsb}
4. To validate that the command you are writing works, select Test Command.  
   The Test Command page appears.{#acc-create-command__table_svt_svr_g5b__entry__2}

   | Field | Description |
   |-|-|
   | Agent | The specific end-point where the command is run. |
   [Table 2. Test Command]

   {#acc-create-command__table_svt_svr_g5b}
5. Enter the specific end-point Agent where the result of the test is displayed.  
   * ![successful]() If it was successful
   * ![large]() too large of an output
   * ![error]() or an Error occurred with the error message displayed to the sn_si.admin.
   {#acc-create-command__ul_ijf_pzz_h5b}
6. Select Submit

*[\>]: and then


