SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Major Security Incident Promotion Grayed Out ?

Hello All, I am banging my head against the wall with this one. I am in the MSIM workspace. I have the sn_msi.worksapce_admin and the sn_msi.workspace_manager roles. I can propose that a security incident become a major incident. But then cannot prom...

PSCWILLEY by Tera Contributor
  • 1899 Views
  • 4 replies
  • 2 helpfuls

Remediation Target on some VIT not getting populated

We are on Vulnerability Response Vulnerability Response 21.1.2.  What we are seeing is that some VITs although they meet the remediation target rule condition(s) they are not getting remediation target dates populated on the VIT.   The remediation ta...

Metric Definition for Security Incident state

Hello, I want to create a Metric Definition that calculates the state duration of a SIR from when it was opened till its state changed from 'Contain'. By now I have the following script : // variables available// current: GlideRecord -  target incide...

TiberiuZ by Giga Contributor
  • 747 Views
  • 2 replies
  • 0 helpfuls

Resolved! SIR Workspace Plugin

Hi all, I am trying to install the Security Incident Response Workspace plugin in my instance. I first installed all the dependent plugins, and when I proceeded to install the Security Incident Response Workspace plugin, I could not find it in the Pl...

TanayaGavande_0-1715685936489.png TanayaGavande_1-1715685954151.png TanayaGavande_2-1715685967323.png

ServiceNow VR integration with Qualys, error 400

Hello ServiceNow Community! I am doing an integration of ServiceNow VR with Qualys, and encountered an issue where KB import works fine, but Host import fails with error 400 (Bad Request).We've dug through all the logs we could find, but the most des...

Slav464 by Tera Contributor
  • 2998 Views
  • 6 replies
  • 1 helpfuls

Resolved! Is there some changes to itil role?

Hello experts,I encountered this behavior but I am not sure if this is changes in Washington Version.For both Utah and Vancouver version (based on PDI test), there is no added role for survey_reader when the itil role is added to a user. But in the W...

RainVaine_0-1715048716865.png RainVaine_1-1715048791433.png
Rain Vaine by Kilo Sage
  • 1799 Views
  • 5 replies
  • 2 helpfuls

Remediation Task Rules

Hello Team,I am working on a VR implementation and If I want to assign all VULs to one group, Is it better to use the User Group option to assign to a static group? I created an assignment rule to assign all the VITs to the one group, but when runnin...

Resolved! Security Tickets

Is it possible to lock down an individual security incident ticket to the assignee and their manager to view and edit only? For example, if we had a checkbox to tick as "confidential", it would then lock it down to just the assignee and manager to vi...

Vulnerability Response Tables Mindmap

Here's a mindmap I've made, breaking down all of the many tables that come along with the baseline ServiceNow Vulnerability Response offering. My hope is that this provides value to ServiceNow developers and implementers new to the Security Operation...

ServiceNow Vulnerability Response Tablesv2.png
Nick Sessa by Kilo Sage
  • 3051 Views
  • 2 replies
  • 16 helpfuls

ServiceNow integration with QRADAR

I need all the detail about how to configure integration between ServiceNow and QRADAR (IBM). Please provide the specifics of steps after the QRADAR plugin is installed. Thanks for all the help.

Zubair Alam by Tera Contributor
  • 1530 Views
  • 1 replies
  • 2 helpfuls

Resolved! Exception Questionnaire

I am wondering how the Exception Questionnaire in Vulnerability Response is useful for approvers/where the answers can be found? I know the metric results and assessment instance questions are linked to the state change approval record, but they aren...

Jkelley by Tera Contributor
  • 2657 Views
  • 5 replies
  • 3 helpfuls

Resolved! machine_filter on Vulnerability response Microsoft TVM

Im trying to apply a machine_filter for importing machines from Microsoft TVM in VR. The filters the machines being imported as CIs, but doesn not filter the vulnerabilities on machines, so we end up with a lot of vulnerabilities that we do not want ...

obos-andreas by Giga Contributor
  • 1847 Views
  • 1 replies
  • 1 helpfuls