Use the script editor to format correlation event values for ArcSight ESM integration
In addition to the directly mapped fields from the ingested correlation event values, use the script editor to format field values on the security incident during the mapping step.
Before you begin
Role required: sn_si.admin
About this task
The script editor changes the values of a ArcSight ESM correlation event field so that values that are supported by the ServiceNow AI Platform SIR security incident are mapped to the Category, Configuration item (CI), Observable, and other security incident fields.
In certain cases, ArcSight ESM correlation event values are mapped to reference fields such as, Category, Configuration item (CI), and Observable fields on the security incident. As a user with the sn_si.admin role, you may prefer to edit the mapped event field values to translate format or data values to conform with incident field formats and values expected. If you want to translate the value of a ArcSight ESM correlation event to a value that is supported by these fields on the SIR security incident, use the script editor.