Bi-directional incidents sync between Microsoft Sentinel and ServiceNow

bekfro
Kilo Sage

I have installed the Microsoft Sentinel Bi-directional incidents sync between Microsoft Sentinel and ServiceNow.

A few things I'm having an issue with.

  • Comments from Sentinel are not displaying in ServiceNow (however ServiceNow work notes are appearing in Sentinel).  I see a business rule with custom mappings, do we need to set comments up in this business rule?
  • We have the default Incident filter set to so the tag of "snow" will filter in Incidents.  Not all Sentinel Incidents with this tag are coming into ServiceNow
    bekfro_0-1694705029191.png

     

    Here's an example that didn't filter into servcienow:

    bekfro_1-1694705454751.png

    Here's one that did:

    bekfro_2-1694705608071.png

     



    Any help would be greatly appreciated. 
1 ACCEPTED SOLUTION

Prabu Velayutha
Mega Sage
Mega Sage

@bekfro  

The application uses the following business rules:

If my response helps to solve your issue kindly mark it as helpful & correct.

 
 

 

 

 

View solution in original post

12 REPLIES 12

rabbanis
Tera Contributor

Through this integration, are we creating only incidents in ServiceNow? or any other ITSM we can manage, such as change,request, and problem tickets? 

sorry I am new to this integration we need to implementing in our client environment so 

@rabbanis , this is a configuration under 'Microsoft Azure Sentinel System Properties ->Table where the Azure Sentinel incidents will be created' but this would ideally be pointed to Incident or Security Incident based on the Integration & your subscription to Security Incident (SIR) Module. 

 

iDNS_0-1729182279737.png

 

 

rabbanis
Tera Contributor

Hello All,

 

Hi  

 

we are planning to integarte sentenal to servicenow .

so i go through the above document and servicenow document both are different now 

Azure-Sentinel/Solutions/Servicenow/StoreApp/README.md at master · Azure/Azure-Sentinel · GitHub

 

https://docs.servicenow.com/bundle/xanadu-security-management/page/product/secops-integration-sir/se...

which document is latest and I ned to follow to complete integration?

so I am stucked in the configuration 

Here name,identity URL and azure resource manger I have doubt what I need to mentioned here

 

I am getting error once I filled all the details

could you please guide me on this 

 

Regards

Shaik.Rabbani