SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Separating multiple detections out of VI without Port

Out-of-box there is a Vulnerability Response configuration to consolidate (or not) multiple detections of a vulnerability on the same device based on different ports. In other words, if the same CVE is detected on a device on multiple ports it can be...

Resolved! One host can't connect to the dev instance

I have a dev instance setup and I can connect to it from multiple different hosts in our network, except the one I am doing development on.  $ openssl s_client -connect dev########.service-now.com:443 --stateCONNECTED(00000003)SSL_connect:before SSL ...

eolmstead by Giga Expert
  • 1690 Views
  • 8 replies
  • 0 helpfuls

Vulnerability Response ACTIVE definition

Thanks in advance to anybody that can clarify what I thought I knew versus what I am finding because a few dashboard widget reports are giving me grossly different results.  This may sound like a total newbie situation, but .... I have three reports ...

Joe Kline by Kilo Guru
  • 967 Views
  • 2 replies
  • 1 helpfuls

Resolved! Security Operations workspace - Close Security Incident

Hello, When using the Security Operations workspace, we have the hability to go through the stages of the incident: However, when trying to close the SI, I am getting an error:And it returns back to "Review" state. I think the problem is not having t...

PedroSilva4_1-1669294413008.png PedroSilva4_2-1669294457679.png

Resolved! Reapply CI lookup rule not changing to a found CI

I seem to have found an issue that maybe someone can help me with. Prior to this release (16.1.1) if I had an unmatched discovered item which created a ci in either the custom tenable or Qualys tables, changing the CI lookup rule and then reapplying ...

Resolved! Export all admin activity (syslog) to external server

Our Infosec team has required that all admin activity that occurs in ServiceNow needs to be exported to an external syslog server. From initial review, it looked like the SecOps module included SIEM integrations. However, it appears that integration ...

Brad59 by Giga Guru
  • 1442 Views
  • 4 replies
  • 1 helpfuls

Resolved! Code for adding multiple user emails in the event queue

Hello All, We have an Event which triggers a notification on Security Incident response.I am looking for code of adding Users email address to event so that the notification can be sent to email address of users in Affected user related list.Table : ...

Resolved! send notification to users in related list

Hello All, We have a requirement where in notifications should go to all the affected users in the related list not just one in the Affected user field on the form.Whats happening right now is the notification is only being sent to the person in affe...

IceIronDragon_0-1669132917546.png IceIronDragon_1-1669132955271.png

Resolved! Does ServiceNow encrypt all our data at rest?

We're going through a security audit and this question was posed to us...."Does ServiceNow encrypt all our data at rest?"   Is this something done by ServiceNow or do we need to arrange for this?   

Gary Winslow by Mega Contributor
  • 12476 Views
  • 8 replies
  • 7 helpfuls