Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Disable automated alarm closure for LogRhythm

Disable the automated alarm closure capability if you no longer want to view the security incident closure information on the LogRhythm Web Console. Once deactivated, the ServiceNow AI Platform no longer closes alarms within the LogRhythm Web Console. This process is optional.

Before you begin

Role required: sn_si.admin

About this task

Once disabled, the status notes and other closure information on the security incident are no longer displayed on the LogRhythm Web Console.

Procedure

  1. Navigate to All > System definition > Business Rules and select the Business Rules module.

  2. If not displayed in the Business Rules list, enter LogRhythm Close Alarm On SI Closure in the search field and press Enter.

Image omitted: lr-bus-list-search.png
Business rule highlighted in search field.
  1. In the Name column, click the LogRhythm Close Alarm On SI Closure link to open the record.

  2. In the record that is displayed, clear the Active check box.

  3. Click Update.

    The automated alarm closure capability is now disabled.

Parent Topic:Additional configurations for the LogRhythm integration