---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute integration

# Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute integration {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute integration

The Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute enables ServiceNow customers to import and manage vulnerability data for container images and running hosts.
This integration supports both SaaS and on-premises Prisma Cloud Compute deployments and requires a MID Server when the Prisma and ServiceNow instances are in different environments.
It allows synchronization of vulnerability information using Prisma Host APIs, helping organizations prioritize and remediate vulnerabilities effectively within the ServiceNow Vulnerability Response and Container Vulnerability Response applications.
Show full answer Show less  

## Key Features

* **Vulnerability Import:** Imports vulnerabilities for container images, base images, and running hosts from Prisma Cloud Compute into ServiceNow, creating findings and vulnerable items for detailed tracking.
* **Scheduled Integrations:** Supports daily and on-demand data retrieval through multiple integration types, including base images, container vulnerabilities, container counts, and registry scans.
* **Granularity Configuration:** Allows customization of container vulnerable items (CVITs) granularity by combining image repository, image, vulnerability, cluster, namespace, and data source (scanner or Discovery) information for precise vulnerability tracking.
* **National Vulnerability Database (NVD) Synchronization:** Checks CVEs against the NVD table and creates or updates placeholder records to maintain comprehensive vulnerability details. Prisma data populates key fields like exploit existence and remediation notes when NVD details are missing.
* **Dashboard Reporting:** Enables visualization of vulnerabilities and vulnerable items through Vulnerability Response dashboards to support prioritization and remediation workflows.

## Practical Steps for ServiceNow Customers

* **Installation:** Install the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute application, which requires a separate subscription.
* **Configuration:** Configure the integration, including registry and base image settings within Prisma, and set up MID Server if necessary to enable API communication.
* **Import and Use Data:** Import vulnerability data from Prisma Cloud Compute to identify and prioritize risks in docker images and hosts, leveraging ServiceNow's remediation capabilities.

## What to Expect

By integrating Prisma Cloud Compute with ServiceNow Vulnerability Response, customers gain automated, up-to-date insights into container and host vulnerabilities. This integration simplifies vulnerability management by consolidating data, enhancing visibility through dashboards, and supporting effective remediation prioritization. Customizable granularity and synchronization with the NVD ensure comprehensive and accurate vulnerability records aligned with organizational needs.  
The Prisma Cloud Compute integration enables you to scan container images to detect
vulnerabilities.

Starting with version 23.0 of the Vulnerability Response, you can use the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute in the Container Vulnerability Response application to import vulnerabilities on the running hosts. The Prisma Host APIs enable retrieval of comprehensive vulnerability information for a specific host and also provides a snapshot of
the host vulnerabilities at a specific time. This API enables regular synchronization between Prisma and ServiceNow instance. As Prisma is offered both as software as a service (SaaS) and on-prem solution, using a MID Server is
necessary to invoke Prisma APIs from the ServiceNow instance.

Starting with version 16.1 of the Vulnerability Response, you can use the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute in the Container Vulnerability Response application to import container image vulnerability data for deployed containers. You can then view reports on vulnerabilities and vulnerable items on the Vulnerability Response dashboards. These vulnerabilities can then be prioritized and remediated.

If the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute product and your ServiceNow AI Platform instance aren't in the same environment, you're required to use a MID Server. For more information, see [MID Server system requirements](https://www.servicenow.com/docs/access?context=r_MIDServerSystemRequirements&version=brazil&pubname=brazil-servicenow-platform&ft:locale=en-US).

## Viewing the integrations {#pcc-integration__section_lsk_dvl_xsb}

You can view the integrations that are part of the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute. To view the integrations, navigate to AllPrisma Cloud Compute IntegrationIntegrations.

The following integrations are available.  
{#pcc-integration__table_msk_dvl_xsb__entry__4}

| Run Sequence | Schedule | Integration | Description |
|-|-|-|-|
| 1 | Daily | Prisma Cloud Compute Base Images Integration | Retrieves the vulnerabilities for base images from the Prisma API and reports the base images vulnerabilities separately. It also creates image findings and vulnerable items, which point to the base images. |
| 2 | Daily | Prisma Cloud Compute Vulnerabilities Integration | Retrieves container vulnerabilities. Creates findings and container vulnerable items (CVITs) and discovered container images. |
| 3 | On Demand | Prisma Cloud Compute Container Counts Integration | Retrieves container counts for each non base image. |
| 4 | Daily | Prisma Cloud Compute Registry Integration | Retrieves static image findings obtained from the Prisma registry scan and ingests into Container Vulnerability Response. |
[ ]

{#pcc-integration__table_msk_dvl_xsb}

## Base image configuration in Prisma {#pcc-integration__section_spv_3xl_vsb}

In the Prisma console, you can configure the registry and then configure the base images from those registries. If a vulnerability is present in the base image, then when you run the Prisma Cloud Compute Base Images Integration,
the Base image check box is selected indicating the vulnerabilities are present in the base image.

## Configure CVR-based VI granularity {#pcc-integration__section_owh_qws_xsb}

To configure the granularity of CVITs, navigate to AllPrisma Cloud Compute IntegrationConfigure CVR based VI Granularity and specify the key combinations. By default, a CVIT is created for a combination of image repository, image, and vulnerability. You can add additional components to the key for further granularity. For example,
you can create a CVIT for a combination of image repository, image, vulnerability, and cluster.

Starting with v2.12.1 of Container Vulnerability Response, you can also configure the granularity of container vulnerable items (CVITs) using Registry information and data sources. The namespace and cluster information is received from both scanner
and Discovery. If you want this information only from Discovery, you can select Discovery Information from the Data Source field. Depending on the chosen data source, you can view either image or Kubernetes information related to a CVIT record.

If Scanner information is selected, the CVIT record shows Image clusters and Image namespace fields.

If Discovery Information is selected, the CVIT record shows Kubernetes clusters and Kubernetes namespace fields.

## Prisma integration process {#pcc-integration__section_qwh_gmn_ryb}

When the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute is run, it checks if a Common Vulnerability and Exposure (CVE) exists in the National Vulnerability Database (NVD) table. If it's already present, the existing information is
used. However, if the CVE isn't found, placeholder records are generated in the NVD table. When creating these placeholder NVD records, initially only the CVE and its name are populated. Other details aren't populated with the
assumption that the NVD integration fills in these details later. If the integration instance parameter update_nvd is set to true, it updates the placeholder NVD records. By default, the instance parameter
is set to false. However, atleast until the NVD integration runs and populates these details, some understanding of the CVE, such as its severity or other details about the issue is needed. To meet this requirement, the fields
Exploit exists and Remediation notes are populated with the details obtained from Prisma. Additionally, this configuration is made customizable, enabling you to specify any other
fields you want to populate in the NVD entry based on the information provided by Prisma.
* **[Preparing for the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute](https://www.servicenow.com/docs/phcxNJMMNRSoxBIM0CzPog)**   
  You can prepare for the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute by performing setup tasks.
* **[Install the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute](https://www.servicenow.com/docs/mABkLsR0LOeM~E2RoWm8rA)**   
  Before you run the integration on your instance, complete the installation and configuration steps so that the Prisma Cloud Compute product properly integrates with Vulnerability Response and Container Vulnerability Response. This application is available as a separate subscription.
* **[Configure the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute application](https://www.servicenow.com/docs/ZgHIinSE6_YML6N~nqGZNA)**   
  Install and configure the Vulnerability Response Integration with Palo Alto Networks Prisma Cloud Compute application. Import data from Prisma Cloud Compute. You can use the imported data to prioritize and remediate vulnerabilities for your docker images and hosts.

*[\>]: and then


