Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Open Table with Sort

Hello,I am attempting to modify a module to load a table sorted by item number in ascending order to enhance performance. Despite setting the link type to URL and configuring the arguments, the module continues to use user preferences to load the vul...

gatesjj2 by Tera Contributor
  • 703 Views
  • 2 replies
  • 1 helpfuls

SIEM Auto Technique Extraction Rule

Hi,We have an API from Sentinel which creates records directly into the sn_si table as Security Incident. This integration passes the MITRE Technique T numbers into a custom "techniques" field today as well as the Tactic numbers into a different cust...

Rash99 by Tera Contributor
  • 1423 Views
  • 7 replies
  • 0 helpfuls

Auto Technique extraction rule for Azure Sentinel

We have integrated the Azure Sentinel with ServiceNow for Security Incident creation, and it also passes the Tactic and Technique information. We have enabled the MITRE ATT&CK matrice (Enterprise) and the associated techniques, however, this is only ...

Need to fetch custom fields from sentinel to SIR Servicenow

Hi Team, We have configures bidirectional integration for Microsoft Azure Sentinel and SIR ServiceNow ,there is a requirement to fetch custom field on sentinel called as site_name we want to map it to Business Unit of SIR record . while checking azur...

Pooja P by Tera Contributor
  • 784 Views
  • 3 replies
  • 0 helpfuls

Resolved! Azure Sentinel Integration - Configuration Item (CI) mapping

Hello! Scenario: We have already implemented the SecOps integration with Sentinel and our current CMDB uses both IP or hostname as identifierQuestion 1: What is the best "Azure Sentinel Source Fields" to map to the "ServiceNow Configuration Item" fie...

Map entities from Sentinel to ServiceNow

Hi ServiceNow Community, I am currently working with mapping entities from Sentinel to ServiceNow using the plugin called Microsoft Sentinel (x_mioms_azsentinel). The problem is that the entities on the Sentinel tickets are being mapped to Work notes...

theabb by Tera Contributor
  • 1283 Views
  • 2 replies
  • 0 helpfuls

Roles for security incident response tasks

Hello,which roles must be assigned to an agent to handle responses tasks without having access to the security incident responses father?Thanks for your help

Dedea by Giga Contributor
  • 804 Views
  • 1 replies
  • 0 helpfuls

Plao Alto Cortex XSOAR integration with SIR

Hi All, I have requirement of integration Palo Alto XSOAR to create Security Incident Response in ServiceNow.Can anyone help me to implement plan? can we configure bi-directional between XSOAR and ServiceNow?regard,Amit 

amit_kishore by Tera Contributor
  • 1674 Views
  • 2 replies
  • 0 helpfuls

Resolved! sn_vulc.auditor

Hi all,I'm looking for the detailed permissions this role provides and what use cases there are for it please.Thank you.

Greg Stone1 by Tera Contributor
  • 463 Views
  • 1 replies
  • 1 helpfuls

In-Depth Guide: Integrating ServiceNow with Qualys

In-Depth Guide: Integrating ServiceNow with Qualys   Integrating ServiceNow with Qualys can streamline your organization’s vulnerability management and incident response workflows. This comprehensive guide provides a step-by-step process to set up t...

MDE Integration with SIR and Isolate Capability

Looking at the Microsoft Defender Endpoint integration with Security Incident Response and can't find documentation anywhere that goes into detail about contacting a host that is no longer online. Is there a looping process that continues to try to i...

Rachel3 by Tera Contributor
  • 565 Views
  • 1 replies
  • 0 helpfuls