<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Security incident inbound email action has a confusing condition in SecOps forum</title>
    <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321903#M7693</link>
    <description>&lt;P&gt;I dont think, thats an OOB inbound actions. Someone must have modified it.&lt;/P&gt;
&lt;P&gt;But for Security Operations, we usually use an Email parser.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2019 20:40:06 GMT</pubDate>
    <dc:creator>SanjivMeher</dc:creator>
    <dc:date>2019-08-23T20:40:06Z</dc:date>
    <item>
      <title>Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321901#M7691</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;
&lt;P&gt;we have the email inbound action part of the security incident response application and it has this out of box condition which I am not sure of&lt;/P&gt;
&lt;P&gt;is it expecting recipients to have 'sn_si' in the email address? if that is the case, do we provision a mailbox with that text in the email address and use that mailbox to create security incident tickets? I can always modify the condition but don't want to customize this action.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="find_real_file.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/134192i28D6260A456099B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="find_real_file.png" alt="find_real_file.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 19:42:01 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321901#M7691</guid>
      <dc:creator>Ravish Shetty</dc:creator>
      <dc:date>2019-08-23T19:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321902#M7692</link>
      <description>&lt;P&gt;Hi Ravish,&lt;/P&gt;
&lt;P&gt;By the above screenshot of conditions it looks like it requires the recipients to have that sn_si in their email address, then only it will create or update the incident. I am not sure whether that is a required condition for this. But you can do it other way round by creating a custom action and action and make this one as false. In that way you will be having the main action as well and if you want to use it again just make the active true for the same.&lt;/P&gt;
&lt;P&gt;Hope that helps you. Please mark it helpful if it really helped you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Mohit Kaushik&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 19:55:44 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321902#M7692</guid>
      <dc:creator>Mohit Kaushik</dc:creator>
      <dc:date>2019-08-23T19:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321903#M7693</link>
      <description>&lt;P&gt;I dont think, thats an OOB inbound actions. Someone must have modified it.&lt;/P&gt;
&lt;P&gt;But for Security Operations, we usually use an Email parser.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 20:40:06 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321903#M7693</guid>
      <dc:creator>SanjivMeher</dc:creator>
      <dc:date>2019-08-23T20:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321904#M7694</link>
      <description>&lt;P&gt;based on the updated by and updated date it looks like it was part of the OOTB setup&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="find_real_file.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/134191i90ADFFE52A05DFC9/image-size/large?v=v2&amp;amp;px=999" role="button" title="find_real_file.png" alt="find_real_file.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 21:52:50 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321904#M7694</guid>
      <dc:creator>Ravish Shetty</dc:creator>
      <dc:date>2019-08-23T21:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321905#M7695</link>
      <description>&lt;P&gt;Ok..I see that too&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="find_real_file.png"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/134193iED040C7C3F2EA5A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="find_real_file.png" alt="find_real_file.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I think you need to change that with your company's id.&lt;/P&gt;
&lt;P&gt;For ex, we check if recipient is csirt@mycompany.com. So you can replace sn_si with csirt or any email id thats used by your company.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 23:58:24 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321905#M7695</guid>
      <dc:creator>SanjivMeher</dc:creator>
      <dc:date>2019-08-23T23:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321906#M7696</link>
      <description>&lt;P&gt;Hey Ravish - Yes, that is an older (prior to Kingston) baseline SIR inbound action that is still kicking around.&amp;nbsp; I believe the condition is mocked up to provide an example / leading point for configuring this (or cloning and adjusting this).&lt;/P&gt;
&lt;P&gt;You may want to check out some of the newer (introduced in Kingston+) SIR Email Processing capabilities introduced into the SIR app, since that specific inbound action was around.&amp;nbsp; These are meant to be configured and tuned for your use-cases, such that you do not need to touch `Inbound Email Actions`.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the app nav menu, check out&amp;nbsp;&lt;STRONG&gt;Security Operations &amp;gt; Email Processing&lt;/STRONG&gt; ...&lt;/P&gt;
&lt;P&gt;You will see several modules here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can configure inbound emails for scenarios such:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;- Security tools to send emails to SN and create SIR records&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;- Users to report phishing / suspicious emails by sending them to SN as an attachment (this feature is pretty neat, it parses artifacts&amp;nbsp;from the msg attachment to create Observables that can be used for Threat Lookups and other slicing and dicing)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;- Ad-hoc users to send emails to SN to create SIR records&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Using these capabilities offers duplication / aggregation capabilities, parsing capabilities - in bit more 'configuration friendly way', than the platform Inbound Action.&amp;nbsp; Also, users with the &amp;lt;sn_si.admin&amp;gt; role, can modify these configs; whereas Inbound Actions at the platform level are not necessarily accessible to users&amp;nbsp;only having the&amp;nbsp;&amp;lt;sn_si.admin&amp;gt; role.&lt;/P&gt;
&lt;P&gt;The [&lt;STRONG&gt;Email Parsing&lt;/STRONG&gt;] Module, essentially allows you to create your own configurations to control what to do when an email is received (based on criteria such as subj, recipients, body text, etc) - and you can use this to parse data / set values on the target SIR records that are created.&lt;/P&gt;
&lt;P&gt;If you are curious, you can check out the Inbound Email Action called "&lt;EM&gt;&lt;STRONG&gt;Record SecOps Email Events&lt;/STRONG&gt;&lt;/EM&gt;".&amp;nbsp; This acts a front, to the Email Processing capabilities, and leverages the configurations you make within the Email Processing configs (i.e. SIR Email Parsing Rules).&amp;nbsp; There&amp;nbsp;are&amp;nbsp;two Inbound Email Actions called "&lt;EM&gt;&lt;STRONG&gt;User Reported Phishing&lt;/STRONG&gt;&lt;/EM&gt;", that acts as a front, to the User Reported Phishing configurations you make (sender, subject, body, etc) (one covers new msgs and one covers fwd msgs).&lt;/P&gt;
&lt;P&gt;Using the [&lt;STRONG&gt;Email Parsing&lt;/STRONG&gt;] or [&lt;STRONG&gt;User Reported Phishing&lt;/STRONG&gt;] here allows you configure what you need, without having to touch the `Inbound email actions`, and with only having the &amp;lt;sn_si.admin&amp;gt; role.&lt;/P&gt;
&lt;P&gt;The one caveat to not needing to touch these Inbound Email Actions, may occur when custom Inbound Actions were introduced onto the SN Platform with very broad conditions and a low Order number that it is ran with; sometimes the Order number may need to be adjusted on these "SecOps" Inbound Email Actions (this may involve working with someone who has the platform &amp;lt;admin&amp;gt; role)...&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Reference:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/madrid-security-management/page/product/security-operations-common/concept/email-parsing.html" rel="nofollow"&gt;https://docs.servicenow.com/bundle/madrid-security-management/page/product/security-operations-common/concept/email-parsing.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/madrid-security-management/page/product/security-incident-response/task/create-email-matching-rules.html" rel="nofollow"&gt;https://docs.servicenow.com/bundle/madrid-security-management/page/product/security-incident-response/task/create-email-matching-rules.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2019 17:43:04 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321906#M7696</guid>
      <dc:creator>andy_ojha</dc:creator>
      <dc:date>2019-08-24T17:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321907#M7697</link>
      <description>&lt;P&gt;hi Andy, I activated the plugin in Madrid so I am not sure why I see a Kingston inbound action.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 21:37:22 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321907#M7697</guid>
      <dc:creator>Ravish Shetty</dc:creator>
      <dc:date>2019-08-26T21:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security incident inbound email action has a confusing condition</title>
      <link>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321908#M7698</link>
      <description>&lt;P&gt;Hey Ravish - You will see this `Email Inbound Action` on a fresh Madrid install SIR.&lt;/P&gt;
&lt;P&gt;There are some components introduced in earlier versions of the product, that are also included in the current release (such as this inbound email action).&lt;/P&gt;
&lt;P&gt;I would try to use the new SecOps email handling capabilities (i.e. Email Parser) rather than this&amp;nbsp;inbound action, for the use-cases you might be looking at.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 21:46:53 GMT</pubDate>
      <guid>https://www.servicenow.com/community/secops-forum/security-incident-inbound-email-action-has-a-confusing-condition/m-p/1321908#M7698</guid>
      <dc:creator>andy_ojha</dc:creator>
      <dc:date>2019-08-26T21:46:53Z</dc:date>
    </item>
  </channel>
</rss>

