Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Missing Security Incident SLA details

We're trying to setup SLAs for Security Incidents and not getting any helpful metrics per SIR. Posting the configurations. The relevant fields are empty and "Made SLA" is always true. How can we get these fields to show details? Are these numbers tra...

About Manual Intake of Vulnerability Information.

SeqOps-VR's vulnerability management provides an OOTB feature for manual capture of vulnerabilities. Reference:https://www.servicenow.com/docs/bundle/vancouver-security-management/page/product/vulnerability-response/concept/manually-ingest-vulnerabil...

Tenable split detections

Do the split tenable detections using proof still work without port granularity turned on? See this article: Split Tenable detections based on the vulnerability instance to split vulnerable items. It isn't mandatory to select port granularity in orde...

LaceyMorrison_0-1741792378632.png
Lacey L by Tera Expert
  • 566 Views
  • 1 replies
  • 0 helpfuls

VR - missing VIT

We have been running VR in prod for almost a year. Our SN VR is integrated with Rapid7. Came across a scenario that is baffling. The jobs seem to be successful but came across an asset. The Discovered Item record created successfully but there was no...

lak-ann by Tera Contributor
  • 564 Views
  • 2 replies
  • 0 helpfuls

Security Operations Observable type mappings and creation

Hello community,  We are wanting to cleanup and enrich our Observable data in order to effectively report details within the associated SIRs. I have the following goals. Focusing on 'unknown' observables (~4500 count) update the logic that maps the O...

ScottW1 by Tera Contributor
  • 678 Views
  • 1 replies
  • 1 helpfuls

Azure Sentinel Integration

Hello, When using the Microsoft Azure Sentinel Incident Ingestion Integration For Security Operations is it possible to update security incidents when you make changes to the mapping in the profile? For example, if I update the profile to include a f...