Security Operations Integration Configurations

  • Release version: Australia
  • Updated March 12, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Security Operations Integration Configurations

    This guide outlines the setup and differences among various integrations available with ServiceNow's Security Operations. While many integrations require minimal configuration, some, like Qualys Cloud Platform, necessitate specific setup steps. Understanding these integrations is crucial for enhancing your security incident management and response capabilities.

    Show full answer Show less

    Key Features

    • Carbon Black Integration: Enables investigation and response to security incidents by querying endpoints.
    • Check Point Anti-bot - Email Parser: Creates security incidents from email notifications.
    • Elasticsearch Incident Enrichment: Enriches security incidents with log searches and sighting information.
    • Have I been pwned? Integration: Quickly checks for breached accounts via a RESTful service.
    • HPE Security ArcSight Integrations: Includes email parser and incident enrichment for creating security incidents from notifications.
    • IBM QRadar Incident Enrichment: Adds relevant information to incidents through log searches.
    • McAfee ESM Integrations: Similar functionalities as HPE ArcSight, focusing on email notifications and incident enrichment.
    • OPSWAT Metadefender: Allows tracking of threat data in the Threat Intelligence application.
    • Palo Alto Networks Integrations: Include AutoFocus for threat intelligence, Firewall for network protection, and WildFire for querying analysis jobs.
    • Splunk Incident Enrichment: Enhances incidents with log search results.
    • VirusTotal Integration: Provides threat intelligence; requires activation of the respective plugin.
    • WhoisXML API: Delivers structured Whois data, ensuring accessibility at all times.

    Key Outcomes

    By configuring these integrations, customers can improve their security posture, streamline incident response, and gain comprehensive insights into potential threats. Activating and managing these integrations can be done from a single screen, simplifying the process for users and partners looking to enhance their security operations.

    Many of the integrations included in the base system require little or no setup, and operate in the same way. Certain integrations, such as the Qualys Cloud Platform, however, require separate steps for setting up the integration. Others support different sets of scan and lookup types and different rate limits.

    This section describes the differences between the supported integrations and points you to more documentation, as needed.