---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR form after an incident ingestion

# SIR form after an incident ingestion {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After the ServiceNow AI Platform ingests the Microsoft Azure Sentinel
incident, a security incident is created and the updates are made to that security incident
record.

## Work notes {#sir-form-after-incident-ingestion__section_xf1_b1k_tpb}

A work note is posted when an incident is aggregated and if you have configured the
Log work note for new incident option in the [Incident Aggregation
Criteria](https://www.servicenow.com/docs/R0wRCFMiG0Xpn_0_g6ciUg#define-azure-filter-aggregation-criteria "Set the filtering conditions so that security incidents are created only when the filtering conditions match."). The following example shows the work notes in SIR.
Figure 1. Viewing work notes in SIR

When you click the incident number, you can view the internal incident import record that
contains the raw incident data. The following example shows the raw incident data in SIR.
Figure 2. Viewing the incident raw data in SIR

When you click the Click here link, you can view the record in the Microsoft Azure Sentinel environment. The following example shows the record in the
Microsoft Azure Sentinel environment.
Figure 3. Viewing the incident record in Azure Sentinel

## Aggregated Sentinel
Incidents {#sir-form-after-incident-ingestion__section_e3k_b1k_tpb}


View Aggregated Sentinel Incidents: View the incidents that are aggregated to the security
incident. Navigate to Show All Related ListsAggregated Microsoft Azure Sentinel incidents.

Create security incident: Select an incident from the list, click the
Actions menu, and then click Create security incident. This option creates a new security incident for the incident and this
incident is de-aggregated from the parent security incident.

## Azure Sentinel Alerts {#sir-form-after-incident-ingestion__section_end_spp_xsb}

To view the alerts that are associated with the Sentinel Incident that triggered the security
incident, navigate to Show All Related ListsAzure Sentinel Alerts.
Figure 4. Azure Sentinel Alerts

*[\>]: and then


