---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create an alarm profile

# Creating an alarm profile for LogRhythm {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

In an alarm profile that you create and name, you specify which alarms you want to
pull from the LogRhythm Client
Console. You also define how they are mapped to fields on a ServiceNow AI Platform security
incident.

## Before you begin

Role required: sn_si.admin

## About this task

Based on the Alarm Profile configured, one alarm profile can ingest all types of
alarms out of the box, but you can use filter criteria to ingest specific types of
alarms. Using this ServiceNow AI Platform integration, all configured alarm rules
or specific ones based on the profile created are ingested. Alarm rules such as only
high-risk level alarms can then be filtered to specify which alarms should create
security incidents. Before security incidents are created, individual field values
on the filtered alarms are mapped to corresponding fields on the ServiceNow AI Platform security incident. This configuration is done via an alarm
profile within your ServiceNow AI Platform instance.

## Procedure

1. Navigate to AllLogRhythm Integration.
2. Select the LogRhythm Alarm Profiles module to display the Alarm Profiles list.  
   Figure 1. Alarm Profile
3. To create a new alarm profile, click New.  
   A new alarm profile form is displayed. At the top of the page in the progress bar, Name is selected. This bar tracks your progress during the configuration.
4. On the form, fill the fields.  
   {#create-alarm-profile-logrhythm__table_zg3_n1r_2tb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the alarm profile. This name helps you identify the alarm types such as Unauthorized access (VPN), malware, or phishing. |
   | Short description | Short text for additional information about the alarm profile, which may include the type of alarms, or an alarm category. An example description: All alarms associated with unauthorized Powershell and Sudo access attempts. |
   | Source | Source server from the choice list. The list consists of LogRhythm configurations you have already set up, for example, <kbd class="ph userinput">logrhythm-server-a</kbd>. See [Install the plugin and configure LogRhythm](https://www.servicenow.com/docs/S849QzBkZaUTWs2Je5D71w "Before you run the integration on your instance, complete the installation and configuration steps so the application properly integrates with Security Operations on the ServiceNow AI Platform."). |
   | Order | Alarm profile priority. This field indicates the order in which the alarm profiles are executed when two or more alarm profiles share the triggering conditions. |
   | Active | By default this option is not selected. After you complete all alarm profile setup steps and click Finish, you are prompted to select this check box to activate the alarm profile. When the alarm profile is active, it pulls alarms from the LogRhythm Client Console automatically. |
   [Table 1. Alarm Profile]

   {#create-alarm-profile-logrhythm__table_zg3_n1r_2tb}
5. Click Continue to save your data and proceed to the Mapping form.  
   If the validation is successful, the page reloads and the
   Mapping form is displayed. You cannot proceed
   with the configuration until you have successfully validated your connection
   and credentials.
{#create-alarm-profile-logrhythm__steps_cxp_43z_f2b}
* **[Mapping](https://www.servicenow.com/docs/Pje9k4C~oM9cH~6aHKFl4A)**   
  After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.
* **[Filter alarms for LogRhythm](https://www.servicenow.com/docs/x0ej4oBenoEKO1loekH6hQ)**   
  Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.
* **[Previewing the security incident with mapped LogRhythm alarm values](https://www.servicenow.com/docs/7vTMv3oX1rNdBvBSM1rNGw)**   
  After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident.
* **[Schedule and retrieve LogRhythm alarms](https://www.servicenow.com/docs/1I4ovCm3G8uz_mn15Czxbg)**   
  After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated.
* **[Additional options for LogRhythm alarms](https://www.servicenow.com/docs/CIXTiUhIVP1T2uM8BLxVnA)**   
  The LogRhythm Enterprise integration provides you the ability to automatically update or close the LogRhythm alarms based on the security incidents.

**Previous topic:** [Install the plugin and configure LogRhythm](https://www.servicenow.com/docs/S849QzBkZaUTWs2Je5D71w "Before you run the integration on your instance, complete the installation and configuration steps so the application properly integrates with Security Operations on the ServiceNow AI Platform.")  
**Next topic:** [Mapping](https://www.servicenow.com/docs/Pje9k4C~oM9cH~6aHKFl4A "After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.")  
**Related concepts**   

* [Mapping](https://www.servicenow.com/docs/Pje9k4C~oM9cH~6aHKFl4A "After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.")

*[\>]: and then


