Create a Profile for Proofpoint DLP integration
Create an incident profile in your ServiceNow AI Platform instance. Determine the Proofpoint DLP incidents that are suitable for creating DLP incidents.
Before you begin
Role required: sn_dlir.admin
About this task
Configure the ServiceNow AI Platform to populate DLP alerts of Proofpoint. Store the alerts as DLP incidents in your ServiceNow instance.
Procedure
Navigate to Proofpoint DLP integration > Incident Profile.
Click New.
On the form, fill the fields in the Name section.
| Field | Description |
|---|---|
| Name | Name of the profile. This name helps you to identify the profile.Note: The name must be unique for each profile. |
| Source | The Proofpoint DLP instance that you configured to ingest incidents. If you have multiple instances configured, select the appropriate instance for the incident types that you are planning to ingest for the profile. |
| Active | Option to make the profile active.When the profile is active, your ServiceNow AI Platform instance is ready to receive the incidents from Proofpoint. |
| Description | Description to help distinguish this profile from other profiles. |
Create a profile for Proofpoint DLP integration.
Click Continue and move to the Filtering section.
Define filters to apply for the Incident creation
Define and set filter conditions to filter the incoming Proofpoint DLP incidents. Control which DLP incidents should be created on ServiceNow®.- Preview evidence files
Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
Parent Topic:Data Loss Prevention Incident Response Integration with Proofpoint