Can I integrate Microsoft Sentinel with the ServiceNow Developer instance?

Zach Tunnell
Kilo Contributor

I am trying to test Sentinel playbooks against a ServiceNow Developer instance. When I go to the store I get an error that I can not login with my credentials. I am new to ServiceNow so I am guessing the store is only for paid instances which is understandable. Is there a way I can use the ServiceNow Developer instance to test a playbook in Sentinel that creates an incident record and updates it?

1 ACCEPTED SOLUTION

Pradeep Sharma
ServiceNow Employee
ServiceNow Employee

Hi Zach,

Please note that "Microsoft Azure Sentinel Incident Ingestion Integration For Security Operations" is automatically entitled on all sub-prod instances, all ServiceNow instances and all ServiceNow developer portal instances. Please replace the below link with your instance name and click on the install button to activate the connector.

https://YOURINSTANCENAME.service-now.com/nav_to.do?uri=%2F$allappsmgmt.do%3Fsysparm_search%3DMicroso...

 

- Pradeep Sharma

 

View solution in original post

5 REPLIES 5

Pradeep Sharma
ServiceNow Employee
ServiceNow Employee

Hi Zach,

Please note that "Microsoft Azure Sentinel Incident Ingestion Integration For Security Operations" is automatically entitled on all sub-prod instances, all ServiceNow instances and all ServiceNow developer portal instances. Please replace the below link with your instance name and click on the install button to activate the connector.

https://YOURINSTANCENAME.service-now.com/nav_to.do?uri=%2F$allappsmgmt.do%3Fsysparm_search%3DMicroso...

 

- Pradeep Sharma

 

Hi @Pradeep Sharma @Zach Tunnell 

 

we are planning to integarte sentenal to servicenow .

so i go through the above document and servicenow document both are different now 

Azure-Sentinel/Solutions/Servicenow/StoreApp/README.md at master · Azure/Azure-Sentinel · GitHub

 

https://docs.servicenow.com/bundle/xanadu-security-management/page/product/secops-integration-sir/se...

which document is latest and I ned to follow to complete integration?

so I am stucked in the configuration 

Here name,identity URL and azure resource manger I have doubt what I need to mentioned here

 

I am getting error once I filled all the details

could you please guide me on this 

 

Regards

Shaik.Rabbani

Yousaf
Giga Sage

Hi Zach,

Go through this doc too it may be of any help:

https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/microsoft-sentinel-incident-bi-direct...

 

Mark Correct or Helpful if it helps.


***Mark Correct or Helpful if it helps.***

Zach Tunnell
Kilo Contributor

@Pradeep Sharma Thank you that link worked flawlessly! 

 

Yousaf Thank you as well these instructions helped me to finish out the connection!