Understand how trigger conditions work with a configuration item

  • Release version: Zurich
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Understand how trigger conditions work with a configuration item

    This content explains how to configure and use trigger conditions with configuration items (CIs) in ServiceNow's FireEye integration, specifically for managing security incidents and endpoint detection and response (EDR) profiles.

    Show full answer Show less

    Key Features

    • Trigger Conditions for Profiles: Profiles with selected FireEye capabilities can be set to run automatically when security incidents meet defined trigger conditions. Without trigger conditions, profiles must be run manually.
    • Default CI Field Usage: The integration uses the Configuration Item (CI) field on security incidents to match asset IDs with the Now Platform CMDB data, retrieving hostnames or IP addresses to resolve FireEye HX Agent IDs.
    • Automated Endpoint Identification: When a security incident is created and a profile runs, the CMDB is queried to find corresponding hostnames or IPs to identify the endpoint in FireEye HX, enabling data retrieval for display in related incident lists.
    • Alternate CI Field Configuration: If the default CI field is empty or mismatched, you can configure an alternate field on the security incident (including custom fields) to use for endpoint identification and Agent ID resolution.
    • Backup CI Field Selection: Selecting an alternate CI field ensures profiles run reliably even if the default CI is not populated when incidents are created.

    Practical Implications for ServiceNow Customers

    • By correctly configuring trigger conditions and CI fields, customers can automate EDR profile execution, improving incident response efficiency.
    • The use of the CMDB and flexible CI field mappings supports accurate endpoint identification, essential for correlating FireEye HX data with incidents.
    • Configuring alternate CI fields helps avoid manual intervention and ensures continuous data gathering from FireEye HX even when default CI data is missing.
    • Profiles will surface detailed FireEye HX data within ServiceNow security incidents, enhancing visibility and investigation capabilities.

    After you create a profile and select the FireEye capabilities that you want the profile to run, configure the profile settings so that it runs only when a set of specific conditions are met.

    You can set trigger conditions so the profile runs automatically whenever a security incident matching the trigger condition is created. If the trigger condition is not set, these profiles can be manually run by clicking the form 'Run EDR profile(s)' on the security incident, and selecting the profile.

    By default, the integration uses the Configuration Item (CI) field on the Security incident. This value is used to match the IDs of your assets with the information stored in the Now Platform CMDB. When a security incident is created, and a profile is run either automatically or manually, the CMDB is searched to retrieve the hostname and/or IP address based on the value of the CI field. The host name and or IP is used to resolve the Agent ID on FireEye HX to identify the endpoint.

    In an ideal case, a matching value is found in the database, and data is gathered from the FireEye HX console for the matching asset. The data for various capabilities are pulled into your ServiceNow AI Platform instance and displayed in the related lists of a security incidents. When the Configuration item (CI) field is not populated on the security incident with a host name, or an IP address that matches the database, you can select an alternate field on the security incident that contains either the host name or the IP to perform the Agent ID resolution.

    During the configuration step of the profile setup, you can select an alternate CI field for endpoint identification to ensure that the you are able to identify the endpoint on FireEye HX. You can select any field on the security incident as an alternate CI trigger field including custom fields that you create. By selecting this alternate CI field as a backup, you ensure that your profiles run even if the CI field is not populated on the associated security incident upon incident creation.

    Note:
    The alternate CI fields are considered only for capabilities that could be added to a profile. For all the additional actions, the alternate CI is picked from the default settings page.
    Security Incident New record