Azure Sentinel Integration: ServiceNow Incident status not updating on closure of incident in Sentinel

MM25
Kilo Guru

Hi Team,

Azure Sentinel Integration: ServiceNow Incident status not updating on the closure of the incident in Sentinel.

Has anyone faced this issue?
3 REPLIES 3

danielgarner
Tera Contributor

I, too, am running into this issue as well. Moreover, I am not ingesting all the Azure Sentinel incidents when leveraging the plugin. Any status update from the Sentinel incident is not updating the mapped fields. I do not know if the parameters of the plugin can be adjusted to bring in all of the Sentinel incidents then including status updates within the corresponding SIR record. Please advise.

designitsecure
Tera Expert

Hello, I realize this is an old post but it appears that the integration is not designed to close incidents in SIR when they are closed in Sentinel. Did you ever find a workaround for this?