Configuring external connections
editConfiguring external connections
editYou can push new cases and case updates to ServiceNow. To do this, you need to create a connector, which stores the information required to push cases to ServiceNow via ServiceNow’s Table API. After you have created a connector, you can set SIEM cases to automatically close when they are sent to ServiceNow.
To create a ServiceNow connector and send cases to ServiceNow, you need the appropriate license.
Create a new connector
edit-
Go to SIEM → Cases → Edit external connection.
-
Click
Add new connector option, and then click ServiceNow.
-
Fill in the following:
- Connector name: A name for the connector.
- URL: The URL of the ServiceNow instance to which you want to send cases.
- Username: The username of the ServiceNow account used to access the ServiceNow instance.
- Password: The password of the ServiceNow account used to access the ServiceNow instance.
-
To represent a SIEM case as a ServiceNow incident, these SIEM case fields are mapped to ServiceNow incidents fields as follows:
-
Title: Mapped to the ServiceNowShort descriptionfield. When an update to a SIEM case title is sent to ServiceNow, the existing ServiceNowShort descriptionfield is overwritten. -
Description: Mapped to the ServiceNowDescriptionfield. When an update to a SIEM case description is sent to ServiceNow, the existing ServiceNowDescriptionfield is overwritten. -
Comments: Mapped to the ServiceNowCommentsfield. When a comment is updated in a SIEM case, a new comment is added to the ServiceNow incident.
-
- Save the connector.
Close sent cases automatically
editTo close cases when they are sent to ServiceNow, select the Automatically close SIEM cases when pushing new incident to third-party option.
Change and update connectors
editYou can create additional connectors, update existing connectors, and change the connector used to send cases to ServiceNow.
-
To change the connector used to send cases to ServiceNow:
- Go to SIEM → Cases → Edit external connection.
-
Select the required connector from the
Incident management systemlist.
-
To update an existing connector:
-
Click
Update connector. - Update the connector fields as required.
-
Click