Get started with the Elasticsearch - Incident Enrichment integration
Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations. Before you can use the Elasticsearch - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate API Base URL and login credentials.
始める前に
手順
タスクの結果
After it is configured, the Elasticsearch - Incident Enrichment integration can be selected for publishing observables to watchlists in Security Incident Response.