---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Integration Configurations

# Security Operations Integration
Configurations {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Security Operations Integration Configurations

ServiceNow Security Operations includes multiple integrations designed to enhance security incident investigation, enrichment, and response capabilities.
While many integrations are pre-configured and require minimal setup, certain integrations such as the Qualys Cloud Platform need additional configuration steps.
These integrations enable seamless connectivity with various third-party security tools and data sources to improve threat detection, incident enrichment, and vulnerability management.
Show full answer Show less  

## Key Features

* **Endpoint and Incident Investigation:** Carbon Black integration allows querying and interacting with endpoints through Carbon Black APIs to support incident investigation and response.
* **Email Parser Integrations:** Check Point Anti-bot, HPE ArcSight ESM, and McAfee ESM email parser integrations consume email notifications from these security products to automatically create security incidents.
* **Incident Enrichment:** Integrations with Elasticsearch, HPE ArcSight Logger, IBM QRadar, McAfee ESM, and Splunk enable log searches to add relevant sighting information to security incidents, enriching the context for analysts.
* **Threat Intelligence Integrations:** OPSWAT Metadefender imports threat data for prioritization and resolution; Palo Alto Networks AutoFocus provides session information related to observables; VirusTotal integration supports threat lookup (requires plugin activation).
* **Firewall and Threat Analysis:** Palo Alto Networks Firewall integration helps manage firewall rules to prevent threats, while WildFire integration allows programmatic queries of malware analysis jobs and historical results.
* **Vulnerability Management:** Qualys Cloud Platform integration is used within Vulnerability Response to manage and track vulnerabilities.
* **Whois Data Integration:** WhoisXML API integration provides consistent and accurate Whois lookup data accessible 24/7 for enriching security investigations.

## Activating and Configuring Integrations

ServiceNow enables customers to activate third-party integration plugins and configure them from a centralized interface. Partners can also create custom integrations by adding integration cards to the Security Integrations screen, facilitating tailored security workflows.

## Practical Benefits for ServiceNow Customers

* Automate incident creation from diverse security tools, reducing manual effort.
* Enrich security incidents with relevant log and threat intelligence data to improve analyst efficiency.
* Integrate vulnerability, threat, and firewall management workflows for comprehensive security operations.
* Leverage consistent, always-available external data sources like Whois information to enhance investigation accuracy.
* Streamline activation and configuration of multiple security integrations through ServiceNow's unified platform.  
Many of the integrations included in the base system require little or no setup, and
operate in the same way. Certain integrations, such as the Qualys Cloud Platform, however,
require separate steps for setting up the integration. Others support different sets of scan and
lookup types and different rate limits.

This section describes the differences between the supported integrations and points you to
more documentation, as needed.  
* [Carbon Black integration](https://www.servicenow.com/docs/KQexWa3G0CWNyKeymI0rdQ "The Carbon Black integration enables you to investigate and respond to security incidents using APIs to query and interact with endpoints associated with security incidents."): allows you to investigate and respond to security incidents by using the Carbon Black APIs to query and interact with endpoints associated with security incidents.
* [Check Point Anti-bot - Email Parser integration](https://www.servicenow.com/docs/DZdfNie6OHC6w7fXUb9reg "Check Point Anti-bot - Email Parser integration is supported using an email parser that consumes email notifications from Check Point Anti-bot to create security incidents and drive enrichment and response workflows."): uses an email parser that consumes email notifications from Check Point Anti-bot to create security incidents.
* [Elasticsearch Incident Enrichment integration](https://www.servicenow.com/docs/OJ4HcEvmo1Nw2oC0_T2TIw "The Elasticsearch - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents."): searches your logs and adds relevant sighting information to your security incidents.
* [Have I been pwned? integration](https://www.servicenow.com/docs/2rlubRwIzEUQgbFWk3FO3A "The Security Operations Have I been pwned? integration enables you to submit lookups on domain names and email addresses to determine whether user personal data has been compromised by data breaches."): allows the list of breached accounts (email addresses and usernames) to be quickly searched via a RESTful service.
* [HPE Security ArcSight ESM - Email Parser integration](https://www.servicenow.com/docs/npqo8GolV8sW4QPpgH8rRQ "The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents."): uses an email parser that consumes email notifications from HPE ArcSight ESM to create security incidents.
* [HPE ArcSight Logger - Incident Enrichment integration](https://www.servicenow.com/docs/zghygB9ntGl7rBvoCS7jpA "The HPE ArcSight Logger - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents."): searches your logs and adds relevant sighting information to your security incidents.
* [IBM QRadar - Incident Enrichment Integration](https://www.servicenow.com/docs/yjAzAJieNm6ePzB93TiMYg "The IBM QRadar - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents."): searches your logs and adds relevant sighting information to your security incidents.
* [McAfee ESM - Email Parser integration](https://www.servicenow.com/docs/7C_0vQA~eHfA6LkiNkxATQ "The ESM - Email Parser integration is supported by an email parser that consumes email notifications from ESM to create security incidents."): uses an email parser that consumes email notifications from McAfee ESM to create security incidents.
* [McAfee ESM - Incident Enrichment Integration](https://www.servicenow.com/docs/67AocrYMZ_i70ms9ieq15Q "McAfee ESM - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents."): searches your logs and adds relevant sighting information to your security incidents.
* [OPSWAT Metadefender integration overview](https://www.servicenow.com/docs/2WEYrrgc8Rrj0P2bnRzIpQ#c_Metadefenderintegration "OPSWAT Metadefender is a security solution that provides access to multiple anti-malware machines and easily integrates with Security Operations."): allows threat data, detected by the third-party Metadefender scanner, to be downloaded to the Threat Intelligence application for tracking, prioritization, and resolution.
* [Palo Alto Networks - AutoFocus integration](https://www.servicenow.com/docs/7R~tyRZYjf3kzJ7HA2YEig "The Palo Alto Networks - AutoFocus integration base system includes a workflow and a series of workflow activities you can use to integrate Palo Alto Networks - AutoFocus with your instance."): Palo Alto Networks AutoFocus, a threat intelligence cloud service, allows you to search for session information related to security incident observables.
* [Palo Alto Networks - Firewall integration](https://www.servicenow.com/docs/iaXHXydLo4Pe7FRXYIz0TA "To perform Palo Alto Networks - Firewall integration, ensure that you have a MID Server set up with SSH credentials. If a firewall is not already set up, add one."): Palo Alto Networks Firewall allows you to set up and maintain firewalls for preventing known and unknown threats across the network, cloud, and endpoints.
* [Palo Alto Networks - WildFire integration](https://www.servicenow.com/docs/qzROpGE~5oe42vWKtIZO3Q "Palo Alto Networks - WildFire is a cloud-based application that interacts with your system firewall."): Wildfire integration allows you to programmatically query analysis jobs on Wildfire and retrieve historical results through a simple XML API interface.
* [Understanding the Qualys Vulnerability Integration](https://www.servicenow.com/docs/WASTRO_pSAxKIUkiiZvtGA "The Qualys product sensors collect the data and automatically send it to the Qualys application, which continuously analyzes and correlates the information. It easily integrates with Vulnerability Response as the Qualys Vulnerability Integration to map vulnerabilities to CIs and business services to determine impact and priority of potentially malicious threats."): Qualys Cloud Platform is used in Vulnerability Response.
* [Splunk - Incident Enrichment integration](https://www.servicenow.com/docs/dGbVhevdnzcWC92Wdzb_RQ "The Splunk - Incident Enrichment integration searches your logs and adds relevant sighting information to your security incidents."): searches your logs and adds relevant sighting information to your security incidents.
* [VirusTotal integration](https://www.servicenow.com/docs/Fp_BGEEo_nB1udb8_yUSDw "The VirusTotal integration enables you to request the analysis of suspicious IP addresses, files, file hashes, and URL addresses to aid in your investigation to determine if they are malicious."): used in Threat Intelligence. To use this lookup source, you must [activate the VirusTotal Integration plugin](https://www.servicenow.com/docs/mlYMej2RwjMfCxBQUTp82Q "You can activate the plugins for third-party integrations and configure them for use from the same screen.").
* [WhoisXML API integration setup](https://www.servicenow.com/docs/Z_L0NOqEcVsPNXUKaIo44Q "Before you can use the Whois integration, you must activate the plugin and add the credentials. If necessary, you can also update your X509 SSL certification."): provides consistent, well-structured data from a Whois lookup. Keeps accurate Whois data accessible 24/7.
{#third-party-integrations__ul_nhr_h3p_tv}
* **[Activate and configure third-party integrations](https://www.servicenow.com/docs/mlYMej2RwjMfCxBQUTp82Q)**   
  You can activate the plugins for third-party integrations and configure them for use from the same screen.
* **[Create an integration](https://www.servicenow.com/docs/cNcnSaNPGsprjF2ftfhfvQ)**   
  You can create an integration and add the associated integration card to the Security Integrations screen. This procedure is intended for partners who create third-party integrations.

**Related concepts**   

* [Types of ServiceNow integrations provided](https://www.servicenow.com/docs/~UySGMI5h5EkEJS9syXtRw "The Security Operations applications (Security Incident Response, Threat Intelligence, and Vulnerability Response) can be seamlessly integrated with other ServiceNow applications to enhance their functionality.")
* [Tips for writing integrations](https://www.servicenow.com/docs/nQ_NV95Gio4lkPddC3NLEQ "Avoid some of the pitfalls you can encounter when writing your own integrations by following these guidelines.")
* [Integration troubleshooting](https://www.servicenow.com/docs/xbDRYfHOBX~4dBMEy09klg "These troubleshooting suggestions can help you resolve common issues you can encounter when setting up or running integrations.")

