SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Security Incident Response manual assignment

How do I remove the assignment group which was assigned automatically upon submit? I have set the assignment rule to "Manually" for the requests. Upon creating and submitting while leaving the assignment group blank, it will be automatically popula...

find_real_file.png find_real_file.png
joel_tan1991 by Kilo Contributor
  • 2609 Views
  • 7 replies
  • 2 helpfuls

Resolved! How to disable "remember me" on service portal login page?

In order to meet security compliance, I recently disabled glide.ui.forgetme on our instance. It worked great on the normal login page but the service portal login page still has the "Remember me" checkbox option (and it is functional, i.e. adds a coo...

Ryan Bray1 by ServiceNow Employee
  • 3154 Views
  • 4 replies
  • 2 helpfuls

Vulnerability Group Rule fields

Hello! I've install Vulnerability response module on my dev instance and trying to understang how it works in Kingston version. The documentation says that Vulnerability Group role has additional sections: Group by and Assignment. But in fact I see o...

find_real_file.png
Alex248 by Mega Expert
  • 1646 Views
  • 5 replies
  • 1 helpfuls

Resolved! How can I track when data is exported from an instance?

Hi, Is there any way to track if a user is exporting data from an instance? The transaction logs give me lots of information but I'm struggling to pinpoint when the function of exporting to .csv, .xls or pdf is happening. Appreciate any help...

ners by Giga Contributor
  • 2982 Views
  • 2 replies
  • 2 helpfuls

Risk score configuration

Hi, I'm just getting started with Security incident response, and I'm lost on how the risk score gets calculated out of the box. I'm trying to go through the RiskScoreUtil script include, but just wondering if someone else has already done this, and ...

cbester by Tera Contributor
  • 2322 Views
  • 3 replies
  • 1 helpfuls

Resolved! Anyone successfully activated the Crowdstrike plugin?

Greetings,We are trying to activate the Crowdstrike plugin in our dev instance for a proof of concept cycle, however, we continue to receive error messages that we are inputting incorrect API key and AIP ID info - we pulled the API info from our Crow...

Where is the correlation_id value used?

Hello..   I have been trying to understand where is the correlation_id field is used in the security operations application when managing an incoming security event.OOB, I think the SIEM (Splunk) sends a snsecevent message to SN.   I get to see the c...

Resolved! issues with notifcations in security incident response?

Hi All! After installation of the Security Incident Response plugin we faces with unexpected behavior of notifications.After creation of the Security Incident   there is no notification about creation of the SIR. But there is one about update of the ...

maximus by Tera Expert
  • 1370 Views
  • 1 replies
  • 7 helpfuls