SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

A vulnerable item was not grouped into any remediation task

A vulnerable item was not grouped into any remediation task although all the conditions matched the VIT and there is no missing data. So the issue is that VIT now does not have any remediation task. What could be the possible issue?

SimranL by Tera Contributor
  • 191 Views
  • 1 replies
  • 0 helpfuls

Monitoring Vulnerability Response Exception Rules

Is there a way to determine which Exception rule resulted in a deferral, similar to the assignment rules, where the assignment rule is tracked in the VIT?If not, this may be a valid enhancement request.Aside from identifying why the VIT was deferred,...

Tenable.sc integration - reference data updates

Hi All, We have Tenable.sc integrated with ServiceNow using the ServiceNow integration application. I'm having trouble when the reference data in Tenable is updated but those updates are not received by ServiceNow.  I'll illustrate with an example: B...

AliceS by Tera Contributor
  • 345 Views
  • 2 replies
  • 1 helpfuls

Daily Extract of Reports to Sharepoint site or Shared Drive

Hi Everyone, I was wondering, how to link daily extract of two reports to a SharePoint site. While scheduling the report, is there a way to configure to go to a SharePoint site? or Shared Drive?  Any help would be greatly appreciated. Thank you  

Shubha2 by Mega Guru
  • 2539 Views
  • 5 replies
  • 2 helpfuls

ServiceNow Rest API throwing error (401 UNAUTHORIZED)

Hello Experts, I am using the below command from a unix machine. curl -v "https://<instancename>/api/now/table/incident?sysparm_query=assigned_to=aea28412db295704e744f1e51d96194c" --request GET --header "Accept:application/json" --header "X-userToken...

Arpit6 by Kilo Contributor
  • 31307 Views
  • 10 replies
  • 7 helpfuls

Vulnerabilities in an IT Portfolio

Has anyone successfully created a relationship between the vulnerabilities in the 'Vulnerable Items" table to an IT Portfolio (indirectly to the portfolio manager) without using Query Builder? If yes, could you please share how you went about doing t...

Resolved! External Access for Security Incident Response Tasks

When we stood up the Security Incident Response module, our request was that non-SOC members could not see the SIR, but could only be assigned SITs.  Based on this, the appropriate groups were given the "response_task" Type and can be assigned tasks....

rcarmack1 by Kilo Guru
  • 4744 Views
  • 21 replies
  • 6 helpfuls

Sentinel to ServiceNow (SIR) sync

Hi, I have rolled out the first portion of the Microsoft Sentinel Integration (from ServiceNow store). I already have SIR +Secops and have done most of the mapping and config in SNOW. The issue I am having is that when polling for say 1m, I am pickin...

joshgbignal by Tera Contributor
  • 490 Views
  • 2 replies
  • 0 helpfuls

Resolved! Reapply Assignment Rules on manually reassigned VIT's

We have various VIT's (in the thousands) that were manually reassigned therefore the newly created assignment rules don't apply to them. However, we would like to know if there is a solution we can implement to get the assignment rules to apply, even...

14Hernan by Tera Contributor
  • 489 Views
  • 2 replies
  • 1 helpfuls

SIR Playbook Promote to Major Security Incident

Hi All,I'm creating playbooks to deal with Security Incident and Major Security Incident processes. One of my requests is to, based on conditions, trigger buttons either Promote Major Security Incident or Propose Major Security Incident directly from...

artur3 by Mega Guru
  • 235 Views
  • 1 replies
  • 0 helpfuls