Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

How to create incident when integration fails

ArushiG
Tera Contributor

Hi team,

I got inducted in SecOps with zero experience.

My first task is to create incidents in the system when integration fails.

Can you please help me.

I was wondering maybe there is a process to create alert when integration fails and that alert can generate incident? I am not sure, Im fumbling. Please help me.

4 REPLIES 4

Ankur Bawiskar
Tera Patron

@ArushiG 

what type of integration and how is it configured?

flow designer etc?

Regards,
Ankur
✨ Certified Technical Architect  ||  ✨ 10x ServiceNow MVP  ||  ✨ ServiceNow Community Leader

Thank you for reply Ankur.
It is not flow designer. I do not have much detail other than to come up with a solution for incident creation when integration fails. They will share details with me later. I need to present some ideas. I am assuming it is basic integration only

Sudhanva
Tera Contributor

@ArushiG 
If the integration is triggered from the flow can have the Error Handler configured
Error Handler Configuration

  1. Open the flow.
  2. Select the REST/IntegrationHub action.
  3. Add an Error Handler path.
  4. In the Error Handler:
    • Create Record
    • Table = Incident

In the Flow Based on the Http status we could have an if condition configured in flow to create record action in flow with Flow spokes we have option to enable Retry policies.

 

In the Script Approach we can have retry policies and then create incident with the below script which can be used in BR, scheduled job etc..

try {

 var r = new sn_ws.RESTMessageV2(“Rest message name”);

//override authentication profile

//authentication type ='basic'/ 'oauth2'

//r.setAuthenticationProfile(authentication type, profile name);

 

//set a MID server name if one wants to run the message on MID

//r.setMIDServer('MY_MID_SERVER');

 

//if the message is configured to communicate through ECC queue, either

//by setting a MID server or calling executeAsync, one needs to set skip_sensor

//to true. Otherwise, one may get an intermittent error that the response body is null

//r.setEccParameter('skip_sensor', true);

 

var response = r.execute();

or you can use r. executeAsync()// for better performance

var status = response.getStatusCode();

 

if (status != 200) {

 

createIncident(

"Integration Failed",

response.getBody()

);

}

 

} catch(ex) {

 

createIncident(

"Integration Exception",

ex.getMessage()

);

}

 

function createIncident(shortDesc, desc){

 

var inc = new GlideRecord('sn_si_incident');

inc.initialize();

 

inc.short_description = shortDesc;

inc.description = desc;

inc.category = 'software';

 

inc.insert();

}

Please mark helpful if this solves your query.

Regards
Sudhanva Chandra D
Certified ArchX || 8x ServiceNow CIS

pururavasin
Tera Contributor

Hello  ,
I am assuming your SecOps application is running on an Integration Model.
If the direction of this integration is Outbound (i.e. from SN to any external system), and the fail scenario is connection break, then you can create a Security Incident:

//---------- 
var si = new GlideRecord('sn_si_incident'); 
si.initialize(); 
si.short_description = 'Critical Integration Failure'; 
si.description = 'Authentication failure detected during external system integration.'; 
si.insert();
 //-------

 

For most implementations, Flow Designer is the preferred low-code approach:

  • Trigger: Integration log record created/updated with Status = Failed
  • Action: Create Security Incident (or Incident)
  • Action: Send email/Teams notification to support team

This ensures every integration failure is automatically tracked and investigated.

Please note that fail scenarios can be different in nature, e.g. 

REST API error, timeout, authentication failure, non-2xx response, MID Server failure, etc.

If you would plan to use Flow-Designer to create alerts/incident, it would ease the process manage such a failure mechanism.

Please share more details about the set-up of this Integration.

Best regards,
Puru.