andy_ojha
ServiceNow Employee

Hi there.

 

By chance have you opened a ServiceNow Support Case for assistance?   

 

The Store App integration available today, combined with Threat Intelligence (from SIR, not TISC) should do the trick, with a few configuration updates.

 

After you install the Azure Sentinel for SIR Store App, you may need to update a property that sets what version of the Azure Sentinel Incident API is used.   This is because, the default version it is set to use, only pulls MITRE Tactics and not Techniques.

Then you would ensure you have the MITRE Technique Exraction Rule feature setup for Azure Sentinel