---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SIR form after an AWS Security Hub finding ingestion

# SIR form after an AWS Security Hub finding ingestion {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After the ServiceNow AI Platform ingests the AWS Security Hub finding, a security incident is created and the updates are made to that security incident record.

## Work notes {#sir-form-after-findings-ingestion__section_d4f_h5t_ddc}

A work note is posted when an incident is aggregated and if you have configured the Log work note for new finding option in the [Define filter and aggregation criteria for AWS Security Hub findings ingestion](https://www.servicenow.com/docs/3dhEsELs~I5K~cRbWSIxXA#aws-security-hub-profile-filter-and-aggregation-criteria "You can define and set filter conditions so that you can specify which incoming findings should create security incidents. You can also define additional incident field criteria that allows an incoming finding to be appended to an open security incident instead of creating an another security incident for the same finding.").

You can also view the internal finding import record that contains the raw incident data.

When you click the Click here link, you can view the record in the AWS Security Hub environment. The following example shows the record in the AWS Security Hub environment.

## Aggregated AWS Security Hub findings {#sir-form-after-findings-ingestion__section_psq_j5t_ddc}


View Aggregated AWS Security Hub findings: View the incidents that are aggregated to the security incident. Navigate to Show All Related ListsAggregated AWS Security Hub findings.

Create security incident: Select an incident from the list, click the Actions menu, and then click Create security incident. This option creates a new security incident for
the incident and this incident is de-aggregated from the parent security incident.

*[\>]: and then


