SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! Splunk Sighting Search

HI, I am running Sighting search for IP Address in Splunk,i am using OOB "Sightings Search Configurations" and i have created same config in splunk as well but i am getting Sighting Search count as 0 in SNOW while in Splunk we are getting results for...

find_real_file.png
Apoorva12 by Giga Contributor
  • 2210 Views
  • 5 replies
  • 2 helpfuls

Resolved! Setting VIT/VUL to Closed/Deferred

Hi SecOps experts, I was just thinking if I set VIT/VUL to Closed/Deferred and if that vulnerability state changes to fixed in Qualys, does that change the state in ServiceNow to closed or fixed or will it be ignored? Wondering how state changes are ...

Khanna Ji by Tera Guru
  • 2182 Views
  • 15 replies
  • 3 helpfuls

Resolved! Error - "ACL Exception Insert Failed due to security constraints"

Hi, I am trying to upload an attachment in the incident table using API. But I am getting below error: status: failure The remote server returned an error: (403) Forbidden. message: Operation Failed detail: ACL Exception Insert Failed due to security...

shubham23 by Giga Contributor
  • 12438 Views
  • 15 replies
  • 8 helpfuls

Best Practice for removing inherited roles from groups??

"sys_user_has_role has entries that shouldn't exist" Years ago In our early stages of go-live, we had configured the itil role to be inherited when a user was granted the it_project_manager role. Recently, we removed the inherited role (itil) from it...

find_real_file.png find_real_file.png find_real_file.png
jennif by Giga Contributor
  • 4437 Views
  • 8 replies
  • 4 helpfuls

Resolved! Vulnerable items and Vulnerability groups status changes

Hi All, I have gone through the state changes between vulnerable item and group but have some questions unanswered. https://docs.servicenow.com/bundle/london-security-management/page/product/vulnerability-response/concept/vulnerabillity-states.html#V...

Khanna Ji by Tera Guru
  • 3326 Views
  • 8 replies
  • 2 helpfuls

Resolved! Missing TAXII Collections for MITRE ATT&CK Profile

I recently thought that I would try out the MITRE ATT&CK integration.  After performing all updates, I now see the MITRE ATT&CK TAXII Profile, but do not see any TAXII Collections available. I'm asking for assistance in determining why these didn't g...

rcarmack1 by Kilo Guru
  • 2819 Views
  • 10 replies
  • 12 helpfuls

Resolved! Record Producer mapping to Related list fields

Hi Everyone I need to map 'Requested by' and 'Requested for' fields from the Input form and map it to fields in the Related list table. I used a small script, in the scripting section of the producer, 'Requested by' from the form should map it to rep...

Shubha2 by Mega Guru
  • 1881 Views
  • 14 replies
  • 0 helpfuls

Configure Splunk events to include MITRE ATT&CK TTPs

Does anyone have any documentation on how to configure the Splunk "ServiceNow Event Integration" to include MITRE-ATT&CK TTPs to use in the new Threat Intelligence MITRE ATT&CK framework? I found documentation on how to "Auto-extract technique rules ...

Mandy8 by Kilo Contributor
  • 3352 Views
  • 10 replies
  • 5 helpfuls

Resolved! SNOW SIR (Security Incident Response) integration with Splunk Phantom

A few questions...   We are planning to use SNOW SIR (Security Incident Response) as our new Case Management / Ticketing System and we also have SOAR tool, Splunk Phantom.   1. What would be the best approach to integrate the two? 2. Do you have an a...

CarlV1 by Kilo Contributor
  • 2914 Views
  • 5 replies
  • 1 helpfuls

Resolved! Integration between QRADAR with ServiceNow

Hi all, How we can do integration between QRadar with Servicenow. If anybody has been done please share the document as well. I got something from  servicenow doc, but i am unable to understand properly. Please help.. Thanks for the advance. Regards,...

Neha52 by Tera Contributor
  • 2368 Views
  • 6 replies
  • 3 helpfuls