We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

SecOps forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Best Practice for removing inherited roles from groups??

"sys_user_has_role has entries that shouldn't exist" Years ago In our early stages of go-live, we had configured the itil role to be inherited when a user was granted the it_project_manager role. Recently, we removed the inherited role (itil) from it...

find_real_file.png find_real_file.png find_real_file.png
jennif by Giga Contributor
  • 7814 Views
  • 8 replies
  • 4 helpfuls

Resolved! Vulnerable items and Vulnerability groups status changes

Hi All, I have gone through the state changes between vulnerable item and group but have some questions unanswered. https://docs.servicenow.com/bundle/london-security-management/page/product/vulnerability-response/concept/vulnerabillity-states.html#V...

Khanna Ji by Tera Guru
  • 5990 Views
  • 8 replies
  • 2 helpfuls

Resolved! Missing TAXII Collections for MITRE ATT&CK Profile

I recently thought that I would try out the MITRE ATT&CK integration.  After performing all updates, I now see the MITRE ATT&CK TAXII Profile, but do not see any TAXII Collections available. I'm asking for assistance in determining why these didn't g...

rcarmack1 by Kilo Guru
  • 7491 Views
  • 10 replies
  • 12 helpfuls

Resolved! Record Producer mapping to Related list fields

Hi Everyone I need to map 'Requested by' and 'Requested for' fields from the Input form and map it to fields in the Related list table. I used a small script, in the scripting section of the producer, 'Requested by' from the form should map it to rep...

Shubha2 by Tera Guru
  • 3527 Views
  • 14 replies
  • 0 helpfuls

Configure Splunk events to include MITRE ATT&CK TTPs

Does anyone have any documentation on how to configure the Splunk "ServiceNow Event Integration" to include MITRE-ATT&CK TTPs to use in the new Threat Intelligence MITRE ATT&CK framework? I found documentation on how to "Auto-extract technique rules ...

Mandy8 by Kilo Contributor
  • 7453 Views
  • 10 replies
  • 5 helpfuls

Resolved! SNOW SIR (Security Incident Response) integration with Splunk Phantom

A few questions...   We are planning to use SNOW SIR (Security Incident Response) as our new Case Management / Ticketing System and we also have SOAR tool, Splunk Phantom.   1. What would be the best approach to integrate the two? 2. Do you have an a...

CarlV1 by Kilo Contributor
  • 5371 Views
  • 5 replies
  • 1 helpfuls

Resolved! wait for condition in flow designer

Hi experts, I am using flow designer , in which I need to wait until all the existing response tasks are completed and then move further. I am using wait for condition action in flow designer ad have written a script for it. But when I check flow exe...

find_real_file.png find_real_file.png
Kalyani35 by Tera Guru
  • 3760 Views
  • 8 replies
  • 3 helpfuls

Qualys scan from Servicenow -

Hello, While initiating scans from Servicenow to Qualys, I get the below error. I am using the "rescan vulnerable items" UI action from the VUL record. Error: Unsuccessful response from server.  Status code: 400   I have already default_scan_applian...

find_real_file.png find_real_file.png
User179407 by Mega Guru
  • 3437 Views
  • 6 replies
  • 1 helpfuls

Resolved! Security Incident Phishing Email PHIS0010001

I have configured email ingestion and I can see it created some record called Security Incident Phishing Email PHIS0010001 I wanted to create direct Security Incident. Is there anything changed recently which caused this record creation? Also system ...

Khanna Ji by Tera Guru
  • 4287 Views
  • 7 replies
  • 5 helpfuls