---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# ArcSight ESM Event Ingestion integration

# ArcSight ESM Event Ingestion integration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of ArcSight ESM Event Ingestion integration

The ArcSight ESM Event Ingestion integration enables security incident analysts using ServiceNow Security Incident Response (SIR) to continuously collect and ingest correlated events from ArcSight ESM.
This integration automates the creation of security incidents within ServiceNow by polling data on a scheduled basis.
It provides analysts with visibility into potential cybersecurity threats by importing event data that can be mapped, previewed, and filtered before automated incident creation.
Show full answer Show less  
Profiles are configured in the ServiceNow AI Platform to handle different types of correlation events from ArcSight ESM, allowing customized display and processing of event fields on SIR security incidents.

## Key Features

* Create multiple event ingestion profiles tailored for specific threat types such as malware or unauthorized access attempts.
* Drag-and-drop interface for mapping ArcSight ESM correlated event fields to corresponding SIR incident fields, facilitating customization.
* Preview the layout of SIR security incidents based on sample correlation events to validate mappings before deployment.
* Ingest both historical and new correlation events on configurable intervals to maintain up-to-date incident information.
* Filter out low priority or irrelevant correlation events to avoid unnecessary incident generation.
* Aggregate related events into existing security incidents by matching specified field values to prevent duplicate incidents.
* Bi-directional updates between correlation events and SIR incidents, reflecting creation and closure status changes.

## Supported Versions and Requirements

This integration supports ServiceNow AI Platform versions New York Patch 6 and Orlando releases. Installation requires several Security Operations applications and Integration Hub plugins from the ServiceNow Store, which must be installed and activated in a specified order for a smooth setup.

ArcSight ESM integration has been tested with version 7.0.0.2436 and supports both on-premises and cloud/hosted ArcSight ESM environments.

## MID Server Requirement

A configured MID Server is required in the ServiceNow instance to connect to ArcSight ESM when it is deployed within a corporate network. For ArcSight ESM cloud services, a MID Server is not necessary.  
The ArcSight ESM event ingestion integration with the Security Incident Response product allows security incident analysts to collect correlated
events and automate creation of security incidents with the ServiceNow
platform. Data is ingested continually based on a configured polling schedule, and it is used by
analysts to identify and respond to potential cyber security threats.

With this integration, correlated events that are candidates for security incidents can be
ingested on a periodic basis. You can map fields in correlated events to security incident
fields, preview the setup of an event as a security incident, and setup scheduled ingestion of
events to automatically create security incidents on an ongoing basis.

## Overview of ArcSight ESM Event Ingestion integration {#arcsight-esm__section_zll_h12_zkb}

This integration provides a security operations center (SOC) analyst with visibility to
correlation events in ArcSight ESM. This data can be integrated into ServiceNow AI Platform Security Incident Response (SIR) security incidents for further
investigation and remediation. Profiles are created in your ServiceNow AI Platform instance to
handle different correlation event types that are created and made available via correlation
query viewers in ArcSight ESM. These profiles customize how different ArcSight ESM correlated event fields are displayed on SIR security incidents.

## Key features {#arcsight-esm__section_if2_s12_zkb}

This integration includes the following key features:

* Create multiple event ingestion profiles to create SIR security incidents for specific types of threats such as malware and unauthorized access attempts.
* Drag-and-drop mapping of ArcSight ESM correlation event field values to associated SIR security incident fields.
* A preview of the SIR security incident layout based on sample correlation events to validate event mapping details.
* Ingest historical correlation events as well as new notable events on configurable intervals.
* Filter out correlation events that do not meet SIR incident generation criteria, e.g. low priority events
* Aggregate events to existing SIR security incidents based on matching field values to avoid duplicate security incidents.
* Update correlation events based on SIR incident creation and/or closure conditionals via a bi-directional interface.
{#arcsight-esm__ul_e5r_512_zkb}

## Supported ServiceNow AI Platform versions {#arcsight-esm__section_e1h_mb2_zkb}

This integration supports the New York Patch 6 and Orlando ServiceNow AI Platform releases.

The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed
below to ensure a smooth installation:

1. Security Integration Framework
2. Security Support Common
3. Security Incident Response
4. Event and Alert Ingestion for Security Operations
5. Integration Hub Plugins
   1. ServiceNow Integration Hub Runtime
   2. ServiceNow Integration Hub Action Step - REST
   {#arcsight-esm__ol_c2p_542_zkb}

{#arcsight-esm__ol_p41_k32_zkb}

For more information about installing the Security Operations core applications, see [Get entitlement for a Security Operations product or application](https://www.servicenow.com/docs/ZG8H~Dkb43mJCGyzY2RF7g "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://www.servicenow.com/docs/kHqtg6gvS5wuwIk0efDLVw "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances.").

## ArcSight ESM supported versions {#arcsight-esm__section_lxn_4p2_zkb}

This integration has been tested with Version 7.0.0.2436 of the ArcSight ESM
Manager. The integration supports both ArcSight ESM on-premises and Cloud/Hosted
service environments.

## MID Server {#arcsight-esm__section_e2y_5rb_2gb}

This integration requires an installed and configured MID Server in your ServiceNow AI Platform® instance to connect to the ArcSight ESM service when
the ArcSight ESM server is deployed within your corporate network. If you are
using the ArcSight ESM cloud service, a MID Server is not required. See the [ServiceNow Product
Documentation website](https://www.servicenow.com/docs) for more information about MID Servers.

## References {#arcsight-esm__section_y2r_wqb_2gb}

{#arcsight-esm__table_axk_n23_2gb__entry__3}

| Reference | Document Identifier | Document Title |
|-|-|-|
| 1 | ArcSight ESM product documentation | [ArcSight product documentation](https://community.microfocus.com/t5/ArcSight-Product-Documentation/ct-p/productdocs). |
| 2 | ServiceNow Product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

{#arcsight-esm__table_axk_n23_2gb}

