---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure Hybrid Analysis

# Install and configure Hybrid Analysis {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Before you run the integration on your instance, complete the installation and
configuration steps so the Hybrid Analysis application properly
integrates with ServiceNow AI Platform
Security Operations.

## Before you begin

Complete the following setup checklist prior to installation. These setup tasks are required for a smooth installation and configuration. {#install-and-configure-hybrid-analysis__table_xxz_jyj_4cb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform and Security Incident Response roles. | The following roles are required for installation, configuration, and verification of expected results: * The administrator (admin) installs the app and assigns the Security Incident Administrator (sn_si.admin) role. * The Security Incident Administrator (sn_si.admin) oversees the configuration and verifies the expected results. This role also has access to the Security Operations module and assigns the sn_si.analyst role. {#install-and-configure-hybrid-analysis__ul_wnc_15r_tcb} |
| Obtain an API key. | Visit the Hybrid Analysis website for information on API keys and to create an account: [Hybrid Analysis website](https://www.hybrid-analysis.com/). The configuration requires that you enter the API keys. |
| Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you install the application for the integration. | For the Madrid release and later family releases, the com.snc.si_dep plugin is required. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before installing and activating the other Security Operations applications. The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed below to ensure a smooth installation: 1. Security Integration Framework 2. Security Support Common 3. Security Support Orchestration 4. Security Incident Response {#install-and-configure-hybrid-analysis__ol_xcx_jzk_tgb} For more information on setting up your ServiceNow AI Platform instance for the integration, see [Get entitlement for a Security Operations product or application](https://www.servicenow.com/docs/EuIstpyLSbg5yLNaGpGURg "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") and [Activate a ServiceNow Store application](https://www.servicenow.com/docs/0MywJIMcl~fLN9sNG1RJww "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
[ ]

{#install-and-configure-hybrid-analysis__table_xxz_jyj_4cb}

Role required: admin

## About this task

Perform the following steps to update system properties and install and configure the
integration.

## Procedure

1. In the navigation filter, enter <kbd class="ph userinput">sys_properties.list</kbd> and press Enter.  
   The System Properties list is displayed.
2. Click New.  
   A new record is displayed.
3. Fill in the fields, or select the values listed in the following table and click Submit.  
   {#install-and-configure-hybrid-analysis__table_r42_yvn_5cb__entry__2}

   | Field name | Value |
   |-|-|
   | Name | <kbd class="ph userinput">glide.outbound.tls_sni.enabled</kbd> |
   | Type | Select true l false |
   | Value | <kbd class="ph userinput">true</kbd> |
   [ ]

   {#install-and-configure-hybrid-analysis__table_r42_yvn_5cb}
4. If you have not installed the application for the integration, see [Install a Security Operations integration](https://www.servicenow.com/docs/hKAhlPYreboSlsmsZCS3nA "All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.") and follow the steps to install it.
5. After the installation completes, navigate to IntegrationsIntegrations Configurations and locate the Hybrid Analysis tile.
6. Click Configure.  
7. In the Hybrid Analysis Configuration dialog box, enter the API key you obtained from the Hybrid Analysis website and click Submit.  
8. Verify successful configuration.  
   Configuration is successfully completed unless an error message is displayed.

   If an error message is displayed during the configuration, the
   Hybrid Analysis API key
   may be invalid.
**Previous topic:** [Hybrid Analysis integration](https://www.servicenow.com/docs/GwHxSsoTFeimgqsC5JYBtw "The Hybrid Analysis application is part of an open online community in which users analyze files and URLs for threats. You share results and utilize research from the community for more effective incident responses. When integrated with the ServiceNow AI Platform Security Operations product, the shared threat intelligence provides you with additional insight into the severity of specific observables.")  
**Next topic:** [Verify expected results for Hybrid Analysis](https://www.servicenow.com/docs/uM2gvE~sqW6RqCT~M~i_OQ "Observables are generated automatically by a security incident and scanned by the application. Locate the lookup results on the security incident to verify the threat lookup has run successfully. Also view raw data and run threat lookups on child observables.")

*[\>]: and then


