We've updated the ServiceNow Community Code of Conduct, adding guidelines around AI usage, professionalism, and content violations. Read more

Crowdstrike Endpoint integration

Rahulkalra
Tera Contributor

Is any other way to filter the endpoint alerts that come in so that security incidents are only created for certain alert types besides altering the scripts?

 

Are there alert rules or something we can configure to get this to work without updating the scripting?
Are here rules that can be configured to deduplicate endpoint alerts as well to prevent incidents being created when multiple alerts come in with the same threat/same host?

1 REPLY 1

bpolo
Tera Guru

Hi there

Just curious, did you ever find a solution to your question

"Are there rules that can be configured to deduplicate endpoint alerts as well to prevent incidents being created when multiple alerts come in with the same threat/same host?" Thanks!