andy_ojha
ServiceNow Employee

Hey @dhruv_gupta  - looks like @Martin Dewit  has got you on the right track.

A few questions that may help:

1) Have we already configured MITRE ATT&CK - and pulled in the data from the "TAXII Profiles"?
  - Assuming we went with "Enterprise ATT&CK" but can you confirm?

andy_ojha_0-1721832963928.png

 


2) What flavor of Splunk are we using?
  - Are we using Splunk Enterprise Security (ES) - where the Notable Events actually have MITRE ATT&CK TTPs in the Notable event field data?

 

3) How are we integration Splunk with SecOps?
 - Are we using the NOW Store App - and setup the Profiles for Automated ingestion (scheduled)?
 - Or, are we first testing with the "Manual" option to push Notables to NOW with the button?

4) Can you confirm on the ServiceNow config side -> the Extraction Rule for Splunk -> has the Ignore option disabled (false)?  

 

andy_ojha_0-1721833336244.png