Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Transform - Coalesce field not indexed

andersona
Tera Contributor

Has anyone experienced issues ingesting vulnerability findings from Google Cloud / Google SecOps into ServiceNow Vulnerability Response (IVR), where the JSON payload appears to be accepted but fails during processing or SIR creation?

We are currently troubleshooting an integration between Google SecOps (SIEM) and ServiceNow. Some vulnerability-related JSON events appear to be failing somewhere in the processing pipeline, and we are trying to determine whether the issue is occurring during:

  • Log ingestion into Google SecOps
  • UDM normalization/parsing
  • Webhook or API export
  • ServiceNow Import Set processing
  • Vulnerability Response (VR/IVR) record creation
  • Automatic Security Incident Response (SIR) creation

We are specifically looking for:

  1. Recommended logs to investigate on both Google SecOps and ServiceNow.
  2. Examples of JSON payload validation errors.
  3. Common parser or UDM mapping issues that prevent findings from reaching ServiceNow.
  4. Troubleshooting steps for failed Security Incident (SIR) creation from vulnerability findings.
  5. Any known limitations or best practices when integrating Google SecOps with ServiceNow Vulnerability Response.

Has anyone encountered similar behavior or identified specific logs that helped determine the root cause?

0 REPLIES 0