---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Schedule the Symantec DLP Incident Retrieval

# Schedule the Symantec DLP Incident Retrieval {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Set a schedule to retrieve the incident data and ingest Symantec DLP
incidents that match the criteria in the profile. Configure the schedule to define how and
when you pull incidents from Symantec.

## Before you begin

Role required: sn_dlir.admin

## About this task

You can plan how often you will poll for future incidents that match the incident
profile configuration. To enable automated incident ingestion, you must configure
the scheduling and incident retrieval before you activate the profile. The profile
can be configured to do one-time retrieval using the One-Time Retrieval check box. The historical date can be up to the last three
months from the current date.

The polling interval is configured for each profile individually. The different
polling intervals may impact the performance of the Symantec DLP
incident integration. When scheduling, plan to balance the system load against the
urgency of an incident.

## Procedure

1. Set a schedule to retrieve data and ingest incidents that match the criteria in the profile.
2. On the form, fill the fields.  
   {#schedule-dlp-incident-retrieval__table_jyk_kcz_2tb__entry__2}

   | Field | Description |
   |-|-|
   | Ongoing Incident Ingestion | The ongoing incident ingestion that the ServiceNow AI Platform instance pulls from the  Symantec for new incidents. DLP incidents are created if triggered incidents are found and the incident generation filtering criteria matches. |
   | Polling increment (minutes) | The polling frequency that is defined in minutes. This field is automatically set to 300 minutes. |
   | Set Initial Incident Ingestion Time | Option to define a date and time for the initial ingestion. Subsequent ingestions are based on the polling interval period. |
   | Input Initial Incident Ingestion Time | Date and time that you specify for the incident ingestion. |
   | Initial Incident Ingestion Time | First time when the data is ingested. You can see the that values start showing up when the initial incident ingestion time is set. |
   | Next Incident Ingestion Time (estimated) | Next period for an estimated incident ingestion. |
   | One-Time Retrieval | Option to enable one-time historical data pull. If this field is selected, then historical data will be pulled from Symantec DLP according to the date added in the Since Date field. |
   | Since Date | Date from when data is supposed to be retrieved from Symantec. This field can be set to at most three months. |
   [Table 1. Schedule for the DLP incident]

   {#schedule-dlp-incident-retrieval__table_jyk_kcz_2tb}
3. To save the created profile configuration, click Finish on the pop-up window.
4. To activate the profile, open the created profile.
5. Enable Active option.
6. Click Update.

## Result

After successful creation and activation of the profile, the incidents are retrieved periodically as per the configuration set in the profile and added into DLP incidents table.

