Create a detection profile
Determine the CrowdStrike Next-Gen SIEM detections that are suitable for creating security incidents by creating a detection profile in your ServiceNow AI Platform instance.
Before you begin
Role required: sn_si.ingestion_profile_admin
Important:
If no correlation rules are configured in the CrowdStrike portal, the detection profile may display a generic "No active correlation rules found. Please ensure that correlation rules are configured, activated, and published in your
Crowdstrike environment" message in ServiceNow® instance. To avoid this issue, confirm that at least one correlation rule is created in the CrowdStrike portal before configuring the ingestion profile.