---
sourceDocument: Xanadu Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/employee-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Submit a digital forensic request

# Submit a digital forensic request {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read

Submit a legal request to access data of current or former employees for internal
investigation or litigation reasons.

## Before you begin

Role required: sn_lg_ops.legal_user

## Procedure

1. Navigate to AllLegal RequestLegal Service Portal.  
   Note:  
   If you're using [Employee Center](https://www.servicenow.com/docs/xGLtfD7pLDCvsFRshZjnCQ "ServiceNow Employee Center portal is a standard multi-department, dynamic portal for service delivery, and employee engagement."), you can submit a legal request by navigating to the Employee Center portal and selecting a request from the Legal servicesBrowse Legal services menu.
2. Click Service Catalog to view all available request categories.
3. Search for the digital forensic request item.
4. Click Digital Forensic Request.
5. On the form, fill in the fields.  
   {#submit-legal-dft-request__table_DFT_request_form__entry__2}

   | Field | Description |
   |-|-|
   | Add this request to | Option to associate the legal request with an existing legal matter or to a new legal matter. * Existing matter: Option to associate the legal request with an existing legal matter. Only current legal matters that you have permission to access appear in the list. * New matter: Option to create a new legal matter and associate the legal request with it. {#submit-legal-dft-request__ul_qgh_1zf_btb} |
   | Existing matter | List of existing legal matters to associate with the legal request. Only current legal matters that you have permission to access appear in the list. This field appears only when the Existing matter option is selected. |
   | Name of new matter | Name of the new legal matter. This field appears only when the New matter option is selected. |
   | Activity request | Short description of the request. |
   | Detailed description | Detail information of the request, for example, details of the suspicious activities by the custodians or details of the litigation. |
   | Custodial data | Employees on whose data you are requesting the investigation. Also provide other investigation details for a custodian---search keywords, data sources, and search period. For more information, see [Add a custodian to a digital forensic request](https://www.servicenow.com/docs/UFePv5KA_Ob_F1EFpeOeuQ#add-custodian-dft-request "Add a custodian and related data source details in your digital forensic request."). |
   | Non-custodial data | Resources and assets, such as server, laptop, mobile, or cloud storage, on which you are requesting the investigation. Also provide other investigation details for a non-custodian---search keywords, data sources, and search period. For more information, see [Add a non-custodial data to a digital forensic request](https://www.servicenow.com/docs/UFePv5KA_Ob_F1EFpeOeuQ#add-non-custodial-data-dft-request "Add a non-custodial data and related search source details in your digital forensic request."). |
   | Bulk upload | Export multiple custodian and non-custodial data from a file. For more information on uploading the data from a file, see [Add custodial and non-custodial data from a file](https://www.servicenow.com/docs/UFePv5KA_Ob_F1EFpeOeuQ#upload-custodians-dft-request "Upload a Microsoft Excel or CSV file containing custodial and non-custodial data to quickly add multiple records in a digital forensic request in one go."). |
   | Activities requested | Type of actions required on the data for the investigation. * Preserve: Secure the original data from the source devices in compliance with departmental guidelines to protect and preserve the evidence. * Collect: Acquire the digital evidence that may be relevant to the investigation. Collection might involve activities such as imaging storage devices, or copying or printing of the digital information. * Review: Conduct an in-depth, systematic examination of the facts in the collected digital evidence related to the investigation. * Present: Document and present the relevant information and findings of the examination in an appropriate format to stakeholders. {#submit-legal-dft-request__ul_tqz_jtn_nnb} |
   | Third party reference ID | Reference to a legal matter ID stored in your other matter management system. |
   | Third party reference system | Reference to your other matter management system. |
   | Preferred completion date and time | Date by which the investigation must be complete. The date and time is based on the time zone you are in while requesting. |
   [Table 1. Digital Forensic Request intake form]

   {#submit-legal-dft-request__table_DFT_request_form}
6. Click Submit.

## Result

* A digital forensic request is created in the New state.
* The Standard Ticket page displays that has the following tabs to perform different tasks:
  * Activity: Track the activity history of the request and post messages for the fulfiller working on the request.
  * Attachments or Documents: Upload and manage the documents in the legal request.  
    Note:  
    If the external storage option is enabled, the Documents tab is displayed. Otherwise, the Attachments tab is displayed.
  * Custodial data: View existing custodial details. You can also export the data to a file.
  * Non-custodial data: View existing non-custodial details. You can also export the data to a file.
  * Request Details: Review request details.
  {#submit-legal-dft-request__ul_dj1_xnm_d4b}
* If you [uploaded custodial and
  non-custodial data from an Excel or CSV file](https://www.servicenow.com/docs/UFePv5KA_Ob_F1EFpeOeuQ#upload-custodians-dft-request "Upload a Microsoft Excel or CSV file containing custodial and non-custodial data to quickly add multiple records in a digital forensic request in one go."), the file is attached as a reference document to the request.

  The number of records successfully
  uploaded from the file into the request is posted as additional comments in
  the Activity tab on the Standard Ticket page.

  If a record from the
  file isn't added to the request, an error log file is added in the Activity
  tab. You can review the reason for failure in the error log file, fix the
  errors in your file, and upload it again by [editing the
  request](https://www.servicenow.com/docs/L60THJrpdjTFK7Jex5r1rw "Update the request details, add comments, manage custodial and non-custodial data, or upload documents in a digital forensic request you submitted while it is still in the New state. You can cancel a submitted request irrespective of its state.").
* For each custodian added in the request, a record is created in the Custodial Data \[sn_lg_forensics_custodial_data\] table. If a legal profile record for each custodian is not already present in the Legal Profile \[sn_lg_ops_legal_profile\] table, a corresponding record is created.
* For each non-custodial data added in the request, a record is created in the Non Custodial Data \[sn_lg_forensics_non_custodial_data\] table.
{#submit-legal-dft-request__ul_gzc_4vf_d4b}

## What to do next

On the Standard Ticket page, you can update request details, add comments, manage
custodial and non-custodial data, upload supporting documents, or cancel the
request. For more information, see [Update a submitted digital forensic request](https://www.servicenow.com/docs/L60THJrpdjTFK7Jex5r1rw "Update the request details, add comments, manage custodial and non-custodial data, or upload documents in a digital forensic request you submitted while it is still in the New state. You can cancel a submitted request irrespective of its state.").  
Any member from the digital forensic team can triage and assign the request to themselves or to any other member in the group. Once the request is assigned, an approval flow is triggered. The flow creates an approval record for each custodial and non-custodial added in the digital forensic request. These approval records are assigned to the privacy team in the legal department. Any member from the legal privacy team can approve the request. After the approval, a digital forensic team member to whom the legal request is assigned can start working on the request. For more information, see [Work on a digital forensic request](https://www.servicenow.com/docs/SlcgazrYE0uPrHyCEtmMvw "As a member of the digital forensic team, you work on a legal request to investigate and resolve the request.").  
Note:  
The approval details appear under the Approvals tab on the Standard Ticket page.

## Add a custodian to a digital forensic request {#ariaid-title2}

Add a custodian and related data source details in your digital forensic
request.

### Before you begin

Role required: sn_lg_ops.legal_user

### Procedure

1. On the Digital Forensic Request intake form, in the Custodial data section, click Add.
2. On the Add Row dialog box, fill in the fields.  
   {#add-custodian-dft-request__table_custo_fields__entry__2}

   | Field | Description |
   |-|-|
   | Custodian name | Name of the custodian on whose digital assets you are requesting a digital forensic investigation. |
   | Data source | Source (hardware or software) from which the data for investigation is to be collected. |
   | Other data sources | Source (hardware or software), not listed in the Data source field, from which the data for investigation is to be collected. This field appears only when Other is selected from Data source. |
   | Keywords | Terms to look for within the data collected from the custodian data sources. You can provide multiple search terms each separated by a comma. |
   | Filter start date | Start date of the digital forensics investigation period. The digital forensic team member would check for the search terms in the data from this date onwards. |
   | Filter end date | End date of the digital forensics investigation period. The digital forensic team member would check for the search terms in the data until this date. |
   | Additional information | Additional details about the custodial data that would be helpful in resolving the request. |
   [Table 2. Add a custodian in a digital forensic request]

   {#add-custodian-dft-request__table_custo_fields}
3. Click Add.  
   The custodian record appears in the Custodial data list on the Digital Forensic Request intake form.

## Add a non-custodial data to a digital forensic request {#ariaid-title3}

Add a non-custodial data and related search source details in your digital forensic
request.

### Before you begin

Role required: sn_lg_ops.legal_user

### Procedure

1. On the Digital Forensic Request intake form, in the Non-custodial data section, click Add.
2. On the Add Row dialog box, fill in the fields.  
   {#add-non-custodial-data-dft-request__table_non_custo_fields__entry__2}

   | Field | Description |
   |-|-|
   | Non-custodial details | Details of the non-custodial data on which you are requesting a digital forensic investigation. For example, you can enter details such as model number, serial number, or product name of the non-custodial data. |
   | Data source | Source from which the data for investigation is to be collected. |
   | Other data sources | Source (hardware or software), not listed in the Data source field, from which the data for investigation is to be collected. This field appears only when Other is selected from Data source. |
   | Search location/File path | Location of the folder or file from where the data for investigation is to be collected. For example, a URL on a cloud storage or a folder or file in a system. |
   | Keywords | Terms to look for within the data collected from the data sources. You can provide multiple search terms each separated by a comma. |
   | Filter start date | Start date of the digital forensics investigation period. The digital forensic team member would check for the search terms in the data from this date onwards. |
   | Filter end date | End date of the digital forensics investigation period. The digital forensic team member would check for the search terms in the data until this date. |
   | Additional information | Additional details about the non-custodial data that would be helpful in resolving the request. |
   [Table 3. Add a non-custodial data in a digital forensic request]

   {#add-non-custodial-data-dft-request__table_non_custo_fields}
3. Click Add.  
   The non-custodial record appears in the Non-custodial data list on the Digital Forensic Request intake form.

## Add custodial and non-custodial data from a file {#ariaid-title4}

Upload a Microsoft Excel or CSV file containing custodial and non-custodial data to
quickly add multiple records in a digital forensic request in one go.

### Before you begin

Role required: sn_lg_ops.legal_user

### About this task

Use a file with a predefined format available on the digital forensics request page
to upload custodial and non-custodial data.

### Procedure

1. Download the template file with the predefined columns and add custodial and non-custodial details.
   1. Click the Download an upload template here link to download the Excel file template.  
      The template file contains sample records for custodial and non-custodial data. During import, the columns marked as Not applicable in the file are ignored.
   2. Review the sample data in the downloaded Excel file and add custodial and non-custodial details in the same format, and then save.
   {#upload-custodians-dft-request__substeps_r3h_kmf_d4b}
2. On the Digital Forensic Request intake form, in the Bulk Upload section, click Upload.
3. Browse and select the Excel file containing the custodial and non-custodial data.  
   The file is attached to the request. The data from the file is uploaded into the request when you submit the request.

*[\>]: and then


