---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Incident Response integrations

# Security Incident Response integrations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Security Incident Response (SIR) integrates with third-party security tools to create security incidents.

## How integrations work {#sir_integrations__section_how_integrations_work}

1. Third-party tools (SIEM, EDR, email security, and threat intelligence) send events, alerts, incidents, or offenses to ServiceNow.
2. Ingestion profiles map source fields to Security Incident \[sn_si_incident\] fields and filter out low-value events.
3. Matching events create or aggregate to a security incident; enrichment integrations add sighting and threat context.
4. Analysts run response actions (isolate host, block value, sandbox a file) and, where supported, updates sync back bi-directionally.

## Available integrations {#sir_integrations__section_avail_integrations}

{#sir_integrations__table_avail_integrations__entry__4}

| Integration | Vendor | Use case | ServiceNow Store |
|-|-|-|-|
| Ingest events, alerts, incidents, and findings ||||
| [Micro Focus ArcSight ESM Event Ingestion](https://www.servicenow.com/docs/udPE1ZCDuAL6lNJ1FfauKQ "The ArcSight ESM event ingestion integration with the Security Incident Response product allows security incident analysts to collect correlated events and automate creation of security incidents with the ServiceNow platform. Data is ingested continually based on a configured polling schedule, and it is used by analysts to identify and respond to potential cyber security threats.") | OpenText | Ingest correlated events on a schedule to automatically create security incidents, with bi-directional updates. | [View in Store](https://store.servicenow.com/store/app/753aafe21b246a50a85b16db234bcb05) |
| [AWS Security Hub](https://www.servicenow.com/docs/uFPqmM7DbWhv4cfpFUmZaw "AWS Security Hub is a cloud security posture management (CSPM) service that provides automated and continuous security checks and best practice checks against your AWS resources.") | Amazon Web Services | Ingest Security Hub findings to auto-create security incidents, with bi-directional status and work-note sync. | [View in Store](https://store.servicenow.com/store/app/d049a7ae1be06a50a85b16db234bcb7f) |
| [Palo Alto Cortex XSIAM](https://www.servicenow.com/docs/w6~NEm4ZBbR3HKg6jbvPiQ "Security Incident Response Integration with Cortex XSIAM by Palo Alto Networks ingests Alerts and Incidents from Cortex XSIAM into ServiceNow's Security Incident Response platform, enabling seamless post-incident management while maintaining bi-directional status and work note synchronization.") | Palo Alto Networks | Ingest XSIAM alerts and incidents into SIR with bi-directional status and worknote synchronization. | [View in Store](https://store.servicenow.com/store/app/5fa1baf447f53a142ec7c1c4f16d439e) |
| [Microsoft Sentinel](https://www.servicenow.com/docs/sh7qSQIpelO96NQwNDawVg "Microsoft Azure Sentinel is a cloud-based Security Information Event Management (SIEM) and Security Orchestration Automated Response (SOAR) solution. You can use the Microsoft Azure Sentinel integration to ingest Azure Sentinel incidents and automatically create security incidents in Security Incident Response.") | Microsoft | Ingest Sentinel incidents to auto-create security incidents. Migrate to Defender before Azure portal deprecation (Mar 2027). | [View in Store](https://store.servicenow.com/store/app/093bab2a1b246a50a85b16db234bcb97) |
| [Microsoft Defender](https://www.servicenow.com/docs/xUbbtR22qcnVOnsoZKqBhw "The Microsoft Defender integration for ServiceNow Security Operations ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.") | Microsoft | Ingest Defender alerts and incidents for centralized case management with bi-directional sync. | [View in Store](https://store.servicenow.com/store/app/03ec7f8697633250cbe2f5411153af56) |
| [Microsoft Graph Security API](https://www.servicenow.com/docs/sRafBWSyHjpXjCp1sXLzUA "Use the Microsoft Graph Security API integration to ingest alerts from Microsoft Graph security providers and automatically create security incidents.") | Microsoft | Ingest alerts from multiple Microsoft security providers through one Graph interface to auto-create incidents. | [View in Store](https://store.servicenow.com/store/app/71cbe7ea1b246a50a85b16db234bcb9f) |
| [IBM QRadar Offense Ingestion](https://www.servicenow.com/docs/CLuqKgfVicyVUvsG1xznEw "The IBM QRadar Offense Ingestion integration allows you to automatically fetch IBM QRadar offenses and convert them into security incidents and enable automated response actions.") | IBM | Fetch QRadar offenses and convert them into security incidents with automated response actions. | [View in Store](https://store.servicenow.com/store/app/0f19ab6e1be06a50a85b16db234bcb6c) |
| [Secureworks CTP Ticket Ingestion](https://www.servicenow.com/docs/VgIKdjFtpIjx8uVvxcKMoA "The Secureworks Counter Threat Platform ticket ingestion integration enables you to automatically fetch Secureworks CTP tickets, convert them into security incidents and perform automated response actions.") | Secureworks | Fetch Secureworks tickets on a schedule, convert them into security incidents, and sync worklogs. | [View in Store](https://store.servicenow.com/store/app/6c4e236a1b646a50a85b16db234bcb2a) |
| [ServiceNow SecOps Add-on for Splunk](https://www.servicenow.com/docs/da8Vh3u_GLnPPlapVB05iw "The ServiceNow Security Operations add-on for Splunk allows a Splunk software administrator to collect data and create incidents and events in the ServiceNow AI Platform.") | Splunk | Let a Splunk administrator collect data and create incidents and events in ServiceNow. | [View on Splunkbase](https://splunkbase.splunk.com/app/3921) |
| [Proofpoint](https://www.servicenow.com/docs/v5r~qOzlqtxyT~11fRUgqw "The Proofpoint SIR integration supports the ingestion of events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.") | Proofpoint | Ingest Proofpoint events; SIR creates an incident per event for analysts to review or work on. | [View in Store](https://store.servicenow.com/store/app/974de7e21b646a50a85b16db234bcb70) |
| Endpoint detection and response (EDR) ||||
| [Carbon Black](https://www.servicenow.com/docs/Y9LJaNAfezHmcJ7oQCNkVQ "The Carbon Black integration enables you to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.") | Broadcom | Query and interact with endpoints tied to a security incident for investigation and response. | [View in Store](https://store.servicenow.com/store/app/a7cb6bea1b246a50a85b16db234bcb6e) |
| [CrowdStrike Falcon Insight](https://www.servicenow.com/docs/Af51NB5CK2np0HhjfhHgog "With the CrowdStrike Falcon Insight for Security Operations integration, you can make remediation actions on the endpoints in real time, use profiles to gather details about the host, and make specific queries or actions on the endpoint using the ServiceNow AI Platform Security Incident Response product.") | CrowdStrike | Gather host details and run real-time remediation actions on endpoints from SIR. | [View in Store](https://store.servicenow.com/store/app/fafcaf621b646a50a85b16db234bcba9) |
| [FireEye Endpoint Security (HX)](https://www.servicenow.com/docs/2nNhBB4yO6U705bUFASzig "FireEye Endpoint Security (HX series) helps organizations to inspect and analyze which contains known and unknown threats on any endpoint.") | Trellix | Investigate and remediate endpoints: enrichment, containment, and Enterprise Security Search. | [View in Store](https://store.servicenow.com/store/app/780c6b2e1b246a50a85b16db234bcbf1) |
| [Microsoft Defender for Endpoint](https://www.servicenow.com/docs/QwPmN9sJ3lCDsxxF50vv5w "The Microsoft Defender for Endpoint enables you to proactively inspect, analyze, and contain known and unknown threats on any endpoint.") | Microsoft | Enrich hosts and run response actions such as isolate host, AV scan, and restrict app execution. | [View in Store](https://store.servicenow.com/store/app/bbf9eba21b246a50a85b16db234bcb7b) |
| Incident enrichment and sightings search ||||
| [Carbon Black -- Incident Enrichment](https://www.servicenow.com/docs/lbCB6_j4klmOxLvMifPwGw "Use the Carbon Black integration to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents.") | Broadcom | Query endpoints tied to a security incident to add investigation context. | [View in Store](https://store.servicenow.com/store/app/a7cb6bea1b246a50a85b16db234bcb6e#linksAndDocuments) |
| [Elasticsearch -- Incident Enrichment](https://www.servicenow.com/docs/BkWTRznxRY8cruNGKWd5zA "The Elasticsearch - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.") | Elastic | Search your logs and add relevant sighting information to security incidents. | [View in Store](https://store.servicenow.com/store/app/4d6c27ae1b246a50a85b16db234bcbea) |
| [HPE ArcSight Logger -- Incident Enrichment](https://www.servicenow.com/docs/MgW5~AjwCoayuPbYqQSL6g "The HPE ArcSight Logger - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.") | OpenText | Search your logs and add relevant sighting information to security incidents. | [View in Store](https://store.servicenow.com/store/app/7ffaabe61b246a50a85b16db234bcb51) |
| [McAfee ESM -- Incident Enrichment](https://www.servicenow.com/docs/YLIBZj_ivNhnPoj_wribBA "McAfee ESM - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.") | Trellix | Search your logs and add relevant sighting information to security incidents. | [View in Store](https://store.servicenow.com/store/app/f36b2f6a1b246a50a85b16db234bcb32) |
| [IBM QRadar -- Incident Enrichment](https://www.servicenow.com/docs/kB9lg3Z6K0PTC18yEAUnaA "The IBM QRadar - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.") | IBM | Search your logs and add relevant sighting information to security incidents. | [View in Store](https://store.servicenow.com/store/app/a94c6f6e1b246a50a85b16db234bcb63) |
| [Splunk -- Incident Enrichment](https://www.servicenow.com/docs/ZlbPizFUL8XyOBtX59uJrw "The Splunk - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents.") | Splunk | Search your logs and add relevant sighting information to security incidents. | [View in Store](https://store.servicenow.com/store/app/f79da3661b646a50a85b16db234bcb9e) |
| Threat intelligence and malware analysis ||||
| [CrowdStrike Falcon Host](https://www.servicenow.com/docs/vMPdXLw~3piuvO9HoFbrTg "The CrowdStrike Falcon Host integration allows you to push observables in a security incident into a watchlist, making them able to generate additional alerts. This integration is an implementation of the CrowdStrike Falcon Host - Publish to Watchlist workflow.") | CrowdStrike | Push incident observables to a watchlist to generate additional alerts. | [View in Store](https://store.servicenow.com/store/app/4689e3221b246a50a85b16db234bcb19) |
| [CrowdStrike Falcon X Sandbox](https://www.servicenow.com/docs/NV7RBssi_oWbF1SLuH3Ekg "With the CrowdStrike Falcon X Sandbox for Security Operations integration, you can submit files and URLs as part of the security incident response process to CrowdStrike Falcon X Sandbox to perform a detailed malware and threat analysis.") | CrowdStrike | Submit files and URLs for detailed malware and threat analysis in an isolated sandbox. | [View in Store](https://store.servicenow.com/store/app/6b69a7ee1be06a50a85b16db234bcb4d) |
| [Have I Been Pwned?](https://www.servicenow.com/docs/Nc8gEl3k1CHIP0iASwoAIQ "The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches.") | Have I Been Pwned | Look up domains and email addresses to check whether data has been compromised in breaches. | [View in Store](https://store.servicenow.com/store/app/4ad8a32e1be06a50a85b16db234bcbcc) |
| [Palo Alto Networks AutoFocus](https://www.servicenow.com/docs/XCxNF2__bmCJGM3vJi6ccw "The Palo Alto Networks - AutoFocus integration base system includes a workflow and a series of workflow activities you can use to integrate Palo Alto Networks - AutoFocus with your instance.") | Palo Alto Networks | Search AutoFocus for malicious content to enrich observables. | [View in Store](https://store.servicenow.com/store/app/674a67261b246a50a85b16db234bcbd8) |
| [Palo Alto Networks WildFire](https://www.servicenow.com/docs/MQu_ZEjzM9k8P9cDFKeHMw "Palo Alto Networks - WildFire is a cloud-based application that interacts with your system firewall.") | Palo Alto Networks | Enrich observables with WildFire cloud-based malware analysis. | [View in Store](https://store.servicenow.com/store/app/7f3a23261b246a50a85b16db234bcb5a) |
| [Zscaler (ZIA)](https://www.servicenow.com/docs/2gKfy8RSgSNFhDldrMiEwA "You can use the Security Incident Response integration with Zscaler product to connect your Zscaler Internet Access server (ZIA) logs with the ServiceNow AI Platform. This integration enables you to view dashboards, create custom alerts, and help you investigate security incidents.") | Zscaler | Reputation lookups, block/allow lists, and sandbox reports from Zscaler Internet Access logs. | [View in Store](https://store.servicenow.com/store/app/9b1a67e21b246a50a85b16db234bcb8f) |
| Email parser and phishing response ||||
| [Check Point Anti-Bot -- Email Parser](https://www.servicenow.com/docs/ciTLfPGXRyK6CLy_lP2DlQ "Check Point Anti-bot - Email Parser integration is supported using an email parser that consumes email notifications from Check Point Anti-bot to create security incidents and drive enrichment and response workflows.") | Check Point | Parse Check Point Anti-Bot email notifications to create security incidents. |   |
| [HPE Security ArcSight ESM -- Email Parser](https://www.servicenow.com/docs/yZLUuQb4H_S~AtePod15mg "The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents.") | OpenText | Parse ArcSight ESM email notifications to create security incidents. |   |
| [McAfee ESM -- Email Parser](https://www.servicenow.com/docs/t8po573AiJAv9ussOn6YpA "The ESM - Email Parser integration is supported by an email parser that consumes email notifications from ESM to create security incidents.") | Trellix | Parse McAfee ESM email notifications to create security incidents. |   |
| [Microsoft Exchange On-Premises](https://www.servicenow.com/docs/TQFEOMHQFLs0lPMnN3FTMQ "The Microsoft Exchange On-Premises integration provides tools for security analysts to contain and eradicate phishing and spear phishing email threats in on-premises instances.") | Microsoft | Contain and eradicate phishing and spear-phishing email threats in on-premises Exchange. |   |
| Firewall and network containment ||||
| [Palo Alto Networks Firewall](https://www.servicenow.com/docs/qQxI_Q5hChbH19oRW2vqow "To perform Palo Alto Networks - Firewall integration, ensure that you have a MID Server set up with SSH credentials. If a firewall is not already set up, add one.") | Palo Alto Networks | Block malicious values on the firewall through a MID Server for network containment. | [View in Store](https://store.servicenow.com/store/app/824e636a1b646a50a85b16db234bcbaa) |
| Build your own integration ||||
| [LLM-powered SIR integration builder](https://www.servicenow.com/docs/cJpyIpWayPsvQ_8JOF16RQ "The LLM-powered SIR integration builder (ServiceNow Otto for Security Incident Response (SIR) integration Toolkit) enables you to integrate capabilities into the Security Incident Response application.") | ServiceNow | Use the ServiceNow Otto for Security Incident Response (SIR) Integration Toolkit for a guided, UI-driven setup to build SIR integrations quickly. | Platform capability |
[ ]

{#sir_integrations__table_avail_integrations}

