SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Resolved! SNOW SIR (Security Incident Response) integration with Splunk Phantom

A few questions...   We are planning to use SNOW SIR (Security Incident Response) as our new Case Management / Ticketing System and we also have SOAR tool, Splunk Phantom.   1. What would be the best approach to integrate the two? 2. Do you have an a...

CarlV1 by Kilo Contributor
  • 3789 Views
  • 5 replies
  • 1 helpfuls

Resolved! Integration between QRADAR with ServiceNow

Hi all, How we can do integration between QRadar with Servicenow. If anybody has been done please share the document as well. I got something from  servicenow doc, but i am unable to understand properly. Please help.. Thanks for the advance. Regards,...

Neha52 by Tera Contributor
  • 2897 Views
  • 6 replies
  • 3 helpfuls

Resolved! wait for condition in flow designer

Hi experts, I am using flow designer , in which I need to wait until all the existing response tasks are completed and then move further. I am using wait for condition action in flow designer ad have written a script for it. But when I check flow exe...

find_real_file.png find_real_file.png
Kalyani35 by Tera Guru
  • 2559 Views
  • 8 replies
  • 3 helpfuls

Qualys scan from Servicenow -

Hello, While initiating scans from Servicenow to Qualys, I get the below error. I am using the "rescan vulnerable items" UI action from the VUL record. Error: Unsuccessful response from server.  Status code: 400   I have already default_scan_applian...

find_real_file.png find_real_file.png
User179407 by Mega Guru
  • 2222 Views
  • 6 replies
  • 1 helpfuls

Resolved! Security Incident Phishing Email PHIS0010001

I have configured email ingestion and I can see it created some record called Security Incident Phishing Email PHIS0010001 I wanted to create direct Security Incident. Is there anything changed recently which caused this record creation? Also system ...

Khanna Ji by Tera Guru
  • 2642 Views
  • 7 replies
  • 5 helpfuls

Resolved! Servicenow Qualys Integration - Asset Tag

Hi There, As per the docs, Servicenow Qualys Host detection Integration retrieves host tags(Asset tag) from Qualys. We had ran the Qualys job once and I could see the field named 'Qualys host ID' gets updated in our CMDB table with the relevant data ...

Priyanka56 by Tera Expert
  • 2509 Views
  • 5 replies
  • 5 helpfuls

Jobs are stuck in ECC Queue in ready state

Hi All, As part of Splunk ES to SIR integration, some of the alerts are not getting converted into a security incident. When found in the ECC queue, we are seeing most of the jobs are stuck in ready state. Could someone help with if any schedule is g...

Resolved! Mark service accounts as internal integration users

reference the SN documentation with regards to creating service accounts here, my understanding is that this checkbox should be checked so to prevent someone from logging into SN as a normal user would.  I would like to know that if SSO is enabled, t...

Dorothy by Tera Contributor
  • 9855 Views
  • 6 replies
  • 4 helpfuls