Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Severity mapping between Symantec DLP incidents with ServiceNow incidents

Use the severity mapping feature to configure and synchronize the mapping between Symantec incidents and ServiceNow AI Platform® incidents.

Before you begin

Role required: sn_dlir.admin

About this task

DLP Severity mapping allows you to map the source severity with the DLP incident severity. You can customize and define the source severity value and map it to the desired DLP incident severity value.

Procedure

  1. Navigate to Symantec DLP integration > Incident Severity Mapping.

  2. Click New.

  3. On the form, fill in the fields.

    FieldDescription
    SourceThe configured Symantec Endpoint source from where you want to fetch the incident.
    Target ValueTarget value is the DLP incident severity ID. The available values are Critical, High, Medium, Low, and Info (used as the info severity in Symantec).
    Source ValueSource value is the Symantec incident severity.

    Note: Within the base system, there are four severity mappings that are shipped to the DLP users.

  4. Click Submit.

Image omitted: dlp-severity-mapping.png
DLP Severity Mapping

Parent Topic:Symantec Integration for Data Loss Prevention Incident Response