- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-14-2023 08:34 AM
I have installed the Microsoft Sentinel Bi-directional incidents sync between Microsoft Sentinel and ServiceNow.
A few things I'm having an issue with.
- Comments from Sentinel are not displaying in ServiceNow (however ServiceNow work notes are appearing in Sentinel). I see a business rule with custom mappings, do we need to set comments up in this business rule?
- We have the default Incident filter set to so the tag of "snow" will filter in Incidents. Not all Sentinel Incidents with this tag are coming into ServiceNow
Here's one that did:
Any help would be greatly appreciated.
Solved! Go to Solution.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-14-2023 09:13 AM
The application uses the following business rules:
- add_work_note_to_sentinel: sycnhronizes work notes to sentinel comments can you verify the configuration as shown in the screenshot below
information source: https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-introducing-microsoft-sent...
If my response helps to solve your issue kindly mark it as helpful & correct.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-16-2024 11:59 PM
Through this integration, are we creating only incidents in ServiceNow? or any other ITSM we can manage, such as change,request, and problem tickets?
sorry I am new to this integration we need to implementing in our client environment so
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-17-2024 09:24 AM
@rabbanis , this is a configuration under 'Microsoft Azure Sentinel System Properties ->Table where the Azure Sentinel incidents will be created' but this would ideally be pointed to Incident or Security Incident based on the Integration & your subscription to Security Incident (SIR) Module.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-11-2024 10:40 PM
Hello All,
Hi
we are planning to integarte sentenal to servicenow .
so i go through the above document and servicenow document both are different now
Azure-Sentinel/Solutions/Servicenow/StoreApp/README.md at master · Azure/Azure-Sentinel · GitHub
which document is latest and I ned to follow to complete integration?
so I am stucked in the configuration
Here name,identity URL and azure resource manger I have doubt what I need to mentioned here
I am getting error once I filled all the details
could you please guide me on this
Regards
Shaik.Rabbani