Verify the Trigger Condition Filters
Test the profile and verify that the trigger condition filters that you have configured are working as expected.
Before you begin
Role required: sn_si.admin or sn_si.analyst
Once you activate the profile, based on the configured trigger conditions you can view the query results in the ServiceNow AI Platform security incidents.
Procedure
Navigate to Security Incidents > Show All Incidents.
Select New to create a new security incident.
Provide the filter conditions as given in the capability profile to trigger the respective profile.
Image omitted: fireeye-security-incidents.png
Security Incident Analysis state
Security Incident Analysis state
- Click Save.
Image omitted: fireeye-security-incidents-worknotes.png
Security Incident work notes
Security Incident work notes
Review the work notes and activities section.
View the profile initiated, profile completed, or profile failed tags.
Click Show all Related lists.
Click any related list (tab).
For example, Host Details.
Image omitted: fireeye-related-lists.png
Host Details tab selected
Host Details tab selected