---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# ArcSight ESM Event Ingestion integration

# ArcSight ESM Event Ingestion integration {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of ArcSight ESM Event Ingestion integration

The ArcSight ESM Event Ingestion integration enables security incident analysts using ServiceNow Security Incident Response (SIR) to collect correlated events from ArcSight ESM and automate the creation of security incidents.
This integration facilitates continuous data ingestion on a scheduled basis, allowing analysts to detect and respond to cybersecurity threats efficiently.
It supports mapping correlated event fields to SIR incident fields, previewing incident setups, and scheduling ongoing event ingestion for automatic incident creation.
Show full answer Show less  
This integration enhances SOC analysts' visibility by integrating ArcSight ESM correlated event data into ServiceNow's AI Platform for deeper investigation and remediation. Customizable profiles allow different event types from ArcSight to be tailored in the SIR interface.

## Key Features

* Create multiple event ingestion profiles targeting specific threat types like malware or unauthorized access attempts.
* Use drag-and-drop functionality to map ArcSight ESM correlation event fields to corresponding SIR incident fields.
* Preview the SIR security incident layout with sample events to validate the mapping before deployment.
* Ingest both historical and new notable correlation events at configurable intervals.
* Filter out low priority or non-relevant events to avoid cluttering incident queues.
* Aggregate events into existing incidents based on matching criteria, preventing duplication.
* Support bi-directional updates between ArcSight events and SIR incidents, including incident creation and closure status.

## Supported Versions and Requirements

This integration supports ServiceNow AI Platform versions New York Patch 6 and Orlando. It requires installation and activation of several Security Operations applications from the ServiceNow Store in a specific order to ensure smooth operation. Key applications include Security Integration Framework, Security Support Common, Security Incident Response, Event and Alert Ingestion, and Integration Hub plugins.

ArcSight ESM version 7.0.0.2436 has been tested for compatibility. The integration works with both on-premises and cloud-hosted ArcSight ESM deployments.

## MID Server Requirements

If ArcSight ESM is deployed within a corporate network (on-premises), a configured MID Server in the ServiceNow AI Platform is required to connect to the ArcSight ESM service. For cloud-hosted ArcSight ESM services, a MID Server is not necessary.

## Practical Benefits for ServiceNow Customers

By implementing this integration, ServiceNow customers can automate the ingestion and processing of ArcSight ESM correlated security events, improving incident creation accuracy and timeliness. This reduces manual effort for SOC analysts, enhances incident prioritization, and supports faster cybersecurity threat response through seamless coordination between ArcSight and ServiceNow Security Incident Response.  
The ArcSight ESM event ingestion integration with the Security Incident Response product allows security incident analysts to collect correlated
events and automate creation of security incidents with the ServiceNow
platform. Data is ingested continually based on a configured polling schedule, and it is used by
analysts to identify and respond to potential cyber security threats.

With this integration, correlated events that are candidates for security incidents can be
ingested on a periodic basis. You can map fields in correlated events to security incident
fields, preview the setup of an event as a security incident, and setup scheduled ingestion of
events to automatically create security incidents on an ongoing basis.

## Overview of ArcSight ESM Event Ingestion integration {#arcsight-esm__section_zll_h12_zkb}

This integration provides a security operations center (SOC) analyst with visibility to
correlation events in ArcSight ESM. This data can be integrated into ServiceNow AI Platform Security Incident Response (SIR) security incidents for further
investigation and remediation. Profiles are created in your ServiceNow AI Platform instance to
handle different correlation event types that are created and made available via correlation
query viewers in ArcSight ESM. These profiles customize how different ArcSight ESM correlated event fields are displayed on SIR security incidents.

## Key features {#arcsight-esm__section_if2_s12_zkb}

This integration includes the following key features:

* Create multiple event ingestion profiles to create SIR security incidents for specific types of threats such as malware and unauthorized access attempts.
* Drag-and-drop mapping of ArcSight ESM correlation event field values to associated SIR security incident fields.
* A preview of the SIR security incident layout based on sample correlation events to validate event mapping details.
* Ingest historical correlation events as well as new notable events on configurable intervals.
* Filter out correlation events that do not meet SIR incident generation criteria, e.g. low priority events
* Aggregate events to existing SIR security incidents based on matching field values to avoid duplicate security incidents.
* Update correlation events based on SIR incident creation and/or closure conditionals via a bi-directional interface.
{#arcsight-esm__ul_e5r_512_zkb}

## Supported ServiceNow AI Platform versions {#arcsight-esm__section_e1h_mb2_zkb}

This integration supports the New York Patch 6 and Orlando ServiceNow AI Platform releases.

The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed
below to ensure a smooth installation:

1. Security Integration Framework
2. Security Support Common
3. Security Incident Response
4. Event and Alert Ingestion for Security Operations
5. Integration Hub Plugins
   1. ServiceNow Integration Hub Runtime
   2. ServiceNow Integration Hub Action Step - REST
   {#arcsight-esm__ol_c2p_542_zkb}

{#arcsight-esm__ol_p41_k32_zkb}

For more information about installing the Security Operations core applications, see [Get entitlement for a Security Operations product or application](https://www.servicenow.com/docs/oEh8SW2y0YHvcOMuL39Pew "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://www.servicenow.com/docs/TXrTKFpJjILx2FjdqPNmFg "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").

## ArcSight ESM supported versions {#arcsight-esm__section_lxn_4p2_zkb}

This integration has been tested with Version 7.0.0.2436 of the ArcSight ESM
Manager. The integration supports both ArcSight ESM on-premises and Cloud/Hosted
service environments.

## MID Server {#arcsight-esm__section_e2y_5rb_2gb}

This integration requires an installed and configured MID Server in your ServiceNow AI Platform® instance to connect to the ArcSight ESM service when
the ArcSight ESM server is deployed within your corporate network. If you are
using the ArcSight ESM cloud service, a MID Server is not required. See the [ServiceNow Product
Documentation website](https://www.servicenow.com/docs) for more information about MID Servers.

## References {#arcsight-esm__section_y2r_wqb_2gb}

{#arcsight-esm__table_axk_n23_2gb__entry__3}

| Reference | Document Identifier | Document Title |
|-|-|-|
| 1 | ArcSight ESM product documentation | [ArcSight product documentation](https://community.microfocus.com/t5/ArcSight-Product-Documentation/ct-p/productdocs). |
| 2 | ServiceNow Product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

{#arcsight-esm__table_axk_n23_2gb}

