Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Cloud Exchange
    Ticket Orchestrator Module
    Configure 3rd-party Ticket Orchestrator Plugins
    ServiceNow Plugin for Ticket Orchestrator

    ServiceNow Plugin for Ticket Orchestrator

    This document explains how to configure your ServiceNow v2.2.0 plugin with the Ticket Orchestrator module of the Netskope Cloud Exchange platform. This plugin is used to create incidents on the Incident > All page, security incidents on the Security Incident > Incidents > Show All Incidents page, GRC issues on the Policy and Compliance > Issues > All Issues page and records on the Custom Table record page of the ServiceNow platform. It also supports updating incidents/issues and syncing their status. This plugin is NOT the same as ServiceNow’s DLP Incident Response product, nor does this plugin work with that solution.

    Prerequisites

    To complete this configuration, you need:

    • A Netskope tenant (or multiple, for example, production and development/test instances).
    • A Netskope Cloud Exchange tenant with the the Tenant plugin and Ticket Orchestrator plugin already configured.
    • A ServiceNow account.
    • Permissions needed for the plugin are itil or sn_incident_write, sn_incident_read, personalize_dictionary, sn_si.admin, sn_grc.business_user, and admin.
    • Connectivity to the following host: https://<instance>.service-now.com/ 
    • For GRC Issue creation, GRC: Policy and Compliance Management (App id: sn_compliance) plugin should be installed on your ServiceNow Instance.
    ServiceNow Plugin Support

    This plugin is used to create incidents on the Incident, Security Incident, GRC issues, and Custom Table records on ServiceNow.

    Supported Alert Types for TicketsSupported Event Types for Tickets
    Compromised Credentials, policy, malsite, Malware, DLP, Security Assessment, watchlist, quarantine, Remediation, UBA, CTEP, Device, ContentEndpoint, Incident
    Mappings
    Queue Mappings
    Target FieldsValues
    Short DescriptionNetskope $appCategory alert name: $alertName
    Event Name: $alert_name
    DescriptionAlert/Event ID: $id

    Alert/Event App: $appAlert/Event User: $userAlert Name: $alertNameAlert Type: $alertTypeAlert App Category: $appCategoryEvent Name: $alert_nameEvent Type: $eventType

    Default Status Mappings

    This mapping is used to map the Netskope CE Status to ServiceNow Status. You can find the available ServiceNow Status by going to System Definitions > Tables> [Table Name] > [Status Column Name] > Choices.

    Cloud Exchange StatusValueServiceNow Status
    New1New
    In Progress2In Progress
    On Hold3On Hold
    Closed7Closed
    Deleted–(Default will be blank)
    You can create custom fields on ServiceNow to map.
    Other–(Default will be blank)
    Default Severity Mappings

    This mapping is used to map the Netskope CE Severity to ServiceNow Severity. You can find the available ServiceNow Severity values by going to System Definitions > Tables > [Table Name] > [Severity Column Name] > Choices.

    Cloud Exchange SeverityValueServiceNow Severity
    Critical–(Default will be blank)

    You can create custom fields on ServiceNow to map.

    High1High
    Medium2Medium
    Low3Low
    Informational–(Default will be blank)

    You can create custom fields on ServiceNow to map.

    Other–(Default will be blank)

    Note

    Default status and severity mapping in the ServiceNow plugin may vary, as these fields can be customized within the platform. Any status or severity that is not mapped with corresponding Netskope CE fields will be marked as other.

    Supported Fields in a Queue Configuration for Default Tables

    Here is the list of supported Fields in Queue Configuration for Default tables that you can map while creating the incident on ServiceNow.

    Security Incident
    Field NameField Type
    Malware hashString
    MITRE ATT&CK Procedure (Malware)String
    Last Updated From SourceChoice
    NumberString
    Platforms(MITRE)String
    Parent security incidentReference
    Affected userReference
    Alert RuleString
    New respondentsGlide_list
    Machine learning PredictionString
    Destination IPString
    ProblemReference
    ServiceReference
    Effective numberString
    Service offeringReference
    Rejection gotoReference
    Malware URLString
    Assigned toReference
    EscalationInteger
    Time workedTimer
    Additional assignee listGlide_list
    Correlation IDString
    MITRE ATT&CK TacticString
    Phish EmailReference
    VariablesVariables
    Alert SensorReference
    Additional commentsJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    Watch listGlide_list
    SLA dueDue_date
    ContractReference
    ActiveBoolean
    StateInteger
    Work notesJournal_input
    Closed byReference
    Follow upGlide_date_time
    Configuration itemReference
    Approval historyJournal
    Business durationGlide_duration
    LocationReference
    User inputUser_input
    Source IPString
    Change requestReference
    RiskInteger
    Workflow activityReference
    Risk changeString
    MITRE ATT&CK Data SourceString
    Work notes listGlide_list
    SkillsGlide_list
    Attack VectorGlide_list
    MITRE ATT&CK TechniqueString
    Allowed groupsGlide_list
    Automation activityJournal
    Business impactInteger
    Close codeString
    Read accessGlide_list
    Privileged accessGlide_list
    Risk scoreInteger
    Security tagsGlide_list
    SeverityInteger
    Security incident selfReference
    IncidentReference
    Comments and Work notesJournal_list
    MITRE ATT&CK Adversary GroupString
    DescriptionString
    ImpactInteger
    ClosedGlide_date_time
    Group listGlide_list
    Activity dueDue_date
    MITRE ATT&CK Procedure (Tool)String
    Request assessmentsGlide_list
    Allowed membersGlide_list
    ParentReference
    PriorityInteger
    Close notesString
    Reassignment countInteger
    Due dateGlide_date_time
    OrderInteger
    Short descriptionString
    CompanyReference
    Approval setGlide_date_time
    Opened byReference
    Contact typeString
    Made SLABoolean
    Post incident reportHtml
    Assignment groupReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    Correlation displayString
    Other IoCString
    Referrer URLString
    Confidence scoreDecimal
    DepartmentGlide_list
    VulnerabilityReference
    Delivery taskReference
    Actual endGlide_date_time
    Universal RequestReference
    Expected startGlide_date_time
    Actual startGlide_date_time
    Upon approvalString
    Transfer reasonInteger
    Enforce restrictionBoolean
    External URLUrl
    Delivery planReference
    Upon rejectString
    Override risk scoreBoolean
    Incident
    Field NameField Type
    Business impactString
    Probable causeString
    Reopen countInteger
    NumberString
    Parent IncidentReference
    ServiceReference
    Change RequestReference
    Effective numberString
    Service offeringReference
    Incident stateInteger
    Resolve timeInteger
    Rejection gotoReference
    Origin tableTable_name
    Resolved byReference
    Chronicle IncidentReference
    Assigned toReference
    EscalationInteger
    Time workedTimer
    Additional assignee listGlide_list
    Correlation IDString
    VariablesVariables
    Child IncidentsInteger
    Additional commentsJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    Watch listGlide_list
    SLA dueDue_date
    ContractReference
    ActiveBoolean
    StateInteger
    Work notesJournal_input
    Closed byReference
    Follow upGlide_date_time
    Configuration itemReference
    Approval historyJournal
    Business durationGlide_duration
    LocationReference
    User inputUser_input
    CategoryString
    Business resolve timeInteger
    OriginDocument_id
    Workflow activityReference
    Caused by ChangeReference
    Work notes listGlide_list
    Close codeString
    SkillsGlide_list
    ResolvedGlide_date_time
    Splunk URLUrl
    Last reopened atGlide_date_time
    ProblemReference
    CallerReference
    SubcategoryString
    Comments and Work notesJournal_list
    DescriptionString
    ImpactInteger
    ClosedGlide_date_time
    Group listGlide_list
    Activity dueDue_date
    ParentReference
    PriorityInteger
    Close notesString
    Reassignment countInteger
    Due dateGlide_date_time
    OrderInteger
    Short descriptionString
    CompanyReference
    Approval setGlide_date_time
    Opened byReference
    Contact typeString
    Made SLABoolean
    On hold reasonInteger
    Assignment groupReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    Correlation displayString
    Delivery taskReference
    Actual endGlide_date_time
    Universal RequestReference
    Expected startGlide_date_time
    NotifyInteger
    Actual startGlide_date_time
    Upon approvalString
    SeverityInteger
    Transfer reasonInteger
    Delivery planReference
    Upon rejectString
    Last reopened byReference
    GRC Issues
    Field NameField Type
    Is reparenting groupBoolean
    Authority documentReference
    ItemReference
    Issue managerReference
    Issue ratingReference
    Management methodString
    DocumentReference
    ExplanationString
    RecommendationString
    Action planHtml
    SubstateString
    Parent issueReference
    Control objective/Risk statementReference
    EntityReference
    Functional domainGlide_list
    User hierarchy statusString
    Is groupBoolean
    Issue group ruleReference
    Issue manager groupReference
    ClassificationString
    Allowed groupsGlide_list
    Issue sourceGlide_list
    User hierarchy 2Reference
    User hierarchy 1Reference
    PolicyReference
    ConfidentialBoolean
    ResponseInteger
    Confirmed dateGlide_date_time
    Issue typeString
    Allowed usersGlide_list
    Created manuallyBoolean
    Group levelString
    Actual endGlide_date_time
    CompanyReference
    NumberString
    ImpactInteger
    Short descriptionString
    Approval setGlide_date_time
    DescriptionString
    ClosedGlide_date_time
    Opened byReference
    Made SLABoolean
    Group listGlide_list
    Contact typeString
    Activity dueDue_date
    Workflow activityReference
    Rejection gotoReference
    Upon rejectString
    ContractReference
    EscalationInteger
    Effective numberString
    ActiveBoolean
    Work notesJournal_input
    Assigned toReference
    Time workedTimer
    Business serviceReference
    StateInteger
    Additional assignee listGlide_list
    Follow upGlide_date_time
    Correlation IDString
    Work notes listGlide_list
    Universal RequestReference
    Closed byReference
    Delivery planReference
    Upon approvalString
    ParentReference
    Close notesString
    Assignment groupReference
    DurationGlide_duration
    PriorityInteger
    ApprovalString
    Due dateGlide_date_time
    Correlation displayString
    Reassignment countInteger
    OrderInteger
    KnowledgeBoolean
    Service offeringReference
    Delivery taskReference
    Configuration itemReference
    Comments and Work notesJournal_list
    UrgencyInteger
    Approval historyJournal
    Additional commentsJournal_input
    OpenedGlide_date_time
    Business durationGlide_duration
    User inputUser_input
    VariablesVariables
    Watch listGlide_list
    LocationReference
    SLA dueDue_date
    Actual startGlide_date_time
    Expected startGlide_date_time
    Transfer reasonInteger
    SkillsGlide_list
    Permissions
    • Permission to send data to the Workflow URL.
      • Roles required when Incidents is configured in the Destination Table parameter:
        • itil or sn_incident_write, sn_incident_read
        • personalize_dictionary
      • Role required when Security Incidents is configured in the Destination Table parameter:
        • sn_si.admin
      • Roles required when GRC Issues is configured in the Destination Table parameter:
        • sn_grc.business_user (Users can only view issues that they have created themselves or have been assigned to them)
        • admin (This permission is necessary to view all GRC Issues, regardless of creator or assignee)
      • Role required when Custom Table is configured in the Destination Table parameter:
        • admin
    API Details

    List of APIs used

    API EndpointMethodUse Case
    /api/now/table/sys_dictionaryGETGet Incident or Security Incident or GRC Issue or Custom Table Fields
    /api/now/table/sys_user_groupGETGet ServiceNow groups as Queue
    /api/now/table/<table>POSTCreate Incident or Security Incident or GRC Issue or Custom Table Record
    /api/now/table/<table>GETGet Incident or Security Incidents or GRC Issues or Custom Table Record
    /api/now/table/<table>/<incident_id>PATCHUpdate Incident or Security Incident or GRC Issue or Custom Table Record
    /api/now/table/sys_userGETFetch Assignee Users

    Get Incident or Security Incident or GRC Issue or Custom Table Fields

    API Endpoint: <Instance URL>/api/now/table/sys_dictionary

    Method: GET

    Parameters

    KeyValue
    sysparm_queryname=<table_name>^ORname=task^internal_type!=collection For Custom Table: name=<custom_table_name>
    sysparm_fieldscolumn_label,element
    sysparm_limit1000
    sysparm_offset0

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Sample API Response (Security Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Malware hash",
                "element": "malware_hash"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Malware)",
                "element": "mitre_malware"
            },
            {
                "column_label": "Last Updated From Source",
                "element": "last_updated_from_src"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Platforms(MITRE)",
                "element": "mitre_platform"
            },
            {
                "column_label": "Parent security incident",
                "element": "parent_security_incident"
            },
            {
                "column_label": "Affected user",
                "element": "affected_user"
            },
            {
                "column_label": "Alert Rule",
                "element": "alert_rule"
            },
            {
                "column_label": "New respondents",
                "element": "new_pir_respondents"
            },
            {
                "column_label": "Machine learning Prediction",
                "element": "prediction"
            },
            {
                "column_label": "Destination IP",
                "element": "dest_ip"
            },
            {
                "column_label": "Problem",
                "element": "problem"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Malware URL",
                "element": "malware_url"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "MITRE ATT&CK Tactic",
                "element": "mitre_tactic"
            },
            {
                "column_label": "Phish Email",
                "element": "phish_email"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Alert Sensor",
                "element": "alert_sensor"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Source IP",
                "element": "source_ip"
            },
            {
                "column_label": "Change request",
                "element": "change_request"
            },
            {
                "column_label": "Risk",
                "element": "risk"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Risk change",
                "element": "risk_change"
            },
            {
                "column_label": "MITRE ATT&CK Data Source",
                "element": "mitre_data_source"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Attack Vector",
                "element": "attack_vector"
            },
            {
                "column_label": "MITRE ATT&CK Technique",
                "element": "mitre_technique"
            },
            {
                "column_label": "Allowed groups",
                "element": "allowed_groups"
            },
            {
                "column_label": "Automation activity",
                "element": "automation_activity"
            },
            {
                "column_label": "Business impact",
                "element": "business_criticality"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Read access",
                "element": "special_access_read"
            },
            {
                "column_label": "Privileged access",
                "element": "special_access_write"
            },
            {
                "column_label": "Risk score",
                "element": "risk_score"
            },
            {
                "column_label": "Security tags",
                "element": "security_tags"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Security incident self",
                "element": "security_incident_self"
            },
            {
                "column_label": "Incident",
                "element": "incident"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "MITRE ATT&CK Adversary Group",
                "element": "mitre_group"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Tool)",
                "element": "mitre_tool"
            },
            {
                "column_label": "Request assessments",
                "element": "pir_respondents"
            },
            {
                "column_label": "Allowed members",
                "element": "allowed_members"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Post incident report",
                "element": "pir"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Other IoC",
                "element": "other_ioc"
            },
            {
                "column_label": "Referrer URL",
                "element": "referrer_url"
            },
            {
                "column_label": "Confidence score",
                "element": "confidence_score"
            },
            {
                "column_label": "Department",
                "element": "department"
            },
            {
                "column_label": "Vulnerability",
                "element": "vulnerability"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Enforce restriction",
                "element": "enforce_restriction"
            },
            {
                "column_label": "External URL",
                "element": "external_url"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Override risk score",
                "element": "risk_score_override"
            }
        ]
    }
    

    Sample API Response (Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Business impact",
                "element": "business_impact"
            },
            {
                "column_label": "Probable cause",
                "element": "cause"
            },
            {
                "column_label": "Reopen count",
                "element": "reopen_count"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Parent Incident",
                "element": "parent_incident"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Change Request",
                "element": "rfc"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Incident state",
                "element": "incident_state"
            },
            {
                "column_label": "Resolve time",
                "element": "calendar_stc"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Origin table",
                "element": "origin_table"
            },
            {
                "column_label": "Resolved by",
                "element": "resolved_by"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Child Incidents",
                "element": "child_incidents"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Category",
                "element": "category"
            },
            {
                "column_label": "Chronicle Incident",
                "element": "x_cdsp_chroni_itsm_chronicle_incident_ref"
            },
            {
                "column_label": "Business resolve time",
                "element": "business_stc"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Origin",
                "element": "origin_id"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Caused by Change",
                "element": "caused_by"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Resolved",
                "element": "resolved_at"
            },
            {
                "column_label": "Splunk URL",
                "element": "x_splu2_splunk_ser_splunk_url"
            },
            {
                "column_label": "Last reopened at",
                "element": "reopened_time"
            },
            {
                "column_label": "Problem",
                "element": "problem_id"
            },
            {
                "column_label": "Caller",
                "element": "caller_id"
            },
            {
                "column_label": "Subcategory",
                "element": "subcategory"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "On hold reason",
                "element": "hold_reason"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Notify",
                "element": "notify"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Last reopened by",
                "element": "reopened_by"
            }
        ]
    }
    

    Sample API Response (GRC Issues) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Is reparenting group",
                "element": "is_reparenting_group"
            },
            {
                "column_label": "Authority document",
                "element": "authority_document"
            },
            {
                "column_label": "Item",
                "element": "item"
            },
            {
                "column_label": "Issue manager",
                "element": "issue_manager"
            },
            {
                "column_label": "Issue rating",
                "element": "issue_rating"
            },
            {
                "column_label": "Management method",
                "element": "management_method"
            },
            {
                "column_label": "Document",
                "element": "document"
            },
            {
                "column_label": "Explanation",
                "element": "explanation"
            },
            {
                "column_label": "Recommendation",
                "element": "recommendation"
            },
            {
                "column_label": "Action plan",
                "element": "action_plan"
            },
            {
                "column_label": "Substate",
                "element": "substate"
            },
            {
                "column_label": "Parent issue",
                "element": "parent_issue"
            },
            {
                "column_label": "Control objective/Risk statement",
                "element": "content"
            },
            {
                "column_label": "Entity",
                "element": "profile"
            },
            {
                "column_label": "Functional domain",
                "element": "functional_domain"
            },
            {
                "column_label": "User hierarchy status",
                "element": "user_hierarchy_status"
            },
            {
                "column_label": "Is group",
                "element": "is_group"
            },
            {
                "column_label": "Issue group rule",
                "element": "issue_group_rule"
            },
            {
                "column_label": "Issue manager group",
                "element": "issue_manager_group"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Classification",
                "element": "classification"
            },
            {
                "column_label": "Allowed groups",
                "element": "confidential_user_groups"
            },
            {
                "column_label": "Issue source",
                "element": "issue_source"
            },
            {
                "column_label": "User hierarchy 2",
                "element": "user_hierarchy_2"
            },
            {
                "column_label": "User hierarchy 1",
                "element": "user_hierarchy_1"
            },
            {
                "column_label": "Policy",
                "element": "policy"
            },
            {
                "column_label": "Confidential",
                "element": "is_confidential"
            },
            {
                "column_label": "Response",
                "element": "response"
            },
            {
                "column_label": "Confirmed date",
                "element": "confirmed_date"
            },
            {
                "column_label": "Issue type",
                "element": "issue_type"
            },
            {
                "column_label": "Allowed users",
                "element": "confidential_users"
            },
            {
                "column_label": "Created manually",
                "element": "created_manually"
            },
            {
                "column_label": "Group level",
                "element": "group_level"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Business service",
                "element": "business_service"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            }
        ]
    }
    


    Get ServiceNow groups as Queue

    API Endpoint: <Instance URL>/api/now/table/sys_user_group

    Method: GET

    Parameters

    KeyValue
    sysparm_fieldsname,sys_id
    sysparm_limit1000
    sysparm_offset0

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    
    { "result": [ { "sys_id": "01336b6347332100158b949b6c9a71b5", "name": "Finance Vendors" }, …. ] }
    

    Create Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: POST

    Path Parameters

    KeyValue
    tableincident sn_si_incident sn_grc_issue custom_table_name

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Body

    
    {
        "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
        "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
        "assignment_group": "<group_sys_id>"
    }
    

    Sample API Response (Security Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:39",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "0",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    

    Sample API Response (Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "made_sla": "true",
            "caused_by": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:44:54",
            "child_incidents": "0",
            "hold_reason": "",
            "origin_table": "",
            "task_effective_number": "INC0923990",
            "approval_history": "",
            "skills": "",
            "number": "INC0923990",
            "resolved_by": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:44:54",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "state": "1",
            "route_reason": "",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "calendar_stc": "",
            "x_cdsp_chroni_itsm_chronicle_incident_ref": "",
            "closed_at": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "business_service": "",
            "business_impact": "",
            "priority": "5",
            "sys_domain_path": "/",
            "rfc": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:44:54",
            "business_duration": "",
            "group_list": "",
            "work_end": "",
            "caller_id": "",
            "reopened_time": "",
            "resolved_at": "",
            "approval_set": "",
            "subcategory": "",
            "work_notes": "",
            "universal_request": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "close_code": "",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "additional_assignee_list": "",
            "business_stc": "",
            "cause": "",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "origin_id": "",
            "calendar_duration": "",
            "close_notes": "",
            "notify": "1",
            "service_offering": "",
            "sys_class_name": "incident",
            "closed_by": "",
            "follow_up": "",
            "parent_incident": "",
            "sys_id": "d1f994dc1be15a549f2eeb98b04bcb71",
            "contact_type": "",
            "reopened_by": "",
            "incident_state": "1",
            "urgency": "3",
            "problem_id": "",
            "company": "",
            "reassignment_count": "0",
            "activity_due": "",
            "assigned_to": "",
            "severity": "3",
            "comments": "",
            "approval": "not requested",
            "sla_due": "",
            "comments_and_work_notes": "",
            "due_date": "",
            "sys_mod_count": "0",
            "reopen_count": "0",
            "sys_tags": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "correlation_id": "",
            "location": "",
            "category": "inquiry"
        }
    }
    

    Sample API Response (GRC Issue) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "shadow": "false",
            "watch_list": "",
            "authority_document": "",
            "recommendation": "",
            "wbs": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:11",
            "explanation": "",
            "approval_history": "",
            "rollup": "false",
            "skills": "",
            "number": "IPT0020059",
            "schedule_start_date": "2024-10-25 10:46:11",
            "capex_cost": "0",
            "state": "1",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "work_duration": "",
            "item": "",
            "budget_cost": "0",
            "cmdb_ci": "",
            "dependency": "",
            "contract": "",
            "impact": "3",
            "key_milestone": "false",
            "profile": "",
            "remaining_effort": "",
            "active": "true",
            "work_notes_list": "",
            "functional_domain": "",
            "classification": "",
            "priority": "4",
            "sys_domain_path": "/",
            "version": "",
            "business_duration": "",
            "group_list": "",
            "override_status": "false",
            "approval_set": "",
            "critical_path": "false",
            "status": "green",
            "universal_request": "",
            "end_date": "2024-10-26 10:46:11",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "work_start": "",
            "top_task": {
                "link": "https://service-now.com/api/now/table/planned_task/444a541847e5161034d5e0d3706d4326",
                "value": "444a541847e5161034d5e0d3706d4326"
            },
            "parent_issue": "",
            "time_constraint": "asap",
            "document": "",
            "additional_assignee_list": "",
            "service_offering": "",
            "sys_class_name": "sn_grc_issue",
            "closed_by": "",
            "follow_up": "",
            "calculation_type": "automatic",
            "confidential_user_groups": "",
            "reassignment_count": "0",
            "schedule_end_date": "2024-10-26 10:46:11",
            "assigned_to": "",
            "policy": "",
            "start_date": "2024-10-25 10:46:11",
            "mpp_task_id": "",
            "sub_tree_root": "",
            "sla_due": "",
            "comments_and_work_notes": "",
            "remaining_duration": "",
            "has_conflict": "false",
            "substate": "",
            "allow_dates_outside_schedule": "false",
            "escalation": "0",
            "upon_approval": "proceed",
            "issue_manager": "",
            "correlation_id": "",
            "group_level": "",
            "made_sla": "true",
            "user_hierarchy_2": "",
            "user_hierarchy_1": "",
            "wbs_order": "",
            "task_effective_number": "IPT0020059",
            "work_effort": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/dadb5bc43be9d210c71edd6aa5e45a1b",
                "value": "dadb5bc43be9d210c71edd6aa5e45a1b"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:11",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "route_reason": "",
            "start_date_derived_from": "",
            "orig_sys_id": "",
            "closed_at": "",
            "is_reparenting_group": "false",
            "level": "",
            "business_service": "",
            "confidential_users": "",
            "is_confidential": "false",
            "relation_applied": "",
            "time_worked": "",
            "expected_start": "",
            "issue_group_rule": "",
            "opened_at": "2024-10-25 10:46:11",
            "task": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name​IPT0020059",
            "work_end": "",
            "run_calc_brs": "true",
            "work_notes": "",
            "work_cost": "0",
            "assignment_group": "",
            "orig_top_task_id": "",
            "user_hierarchy_status": "2",
            "software_model": "",
            "created_manually": "true",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "effort": "",
            "calendar_duration": "",
            "end_date_derived_from": "",
            "close_notes": "",
            "content": "",
            "duration": "1970-01-02 00:00:00",
            "issue_manager_group": "",
            "sys_id": "444a541847e5161034d5e0d3706d4326",
            "contact_type": "",
            "urgency": "3",
            "constraint_date": "",
            "company": "",
            "end": "2024-10-25",
            "activity_due": "",
            "comments": "",
            "cost": "0",
            "approval": "not requested",
            "due_date": "",
            "issue_type": "",
            "start": "2024-10-25",
            "sys_mod_count": "0",
            "management_method": "",
            "confirmed_date": "",
            "model_id": "",
            "opex_cost": "0",
            "sys_tags": "",
            "time_zone": "",
            "html_description": "",
            "percent_complete": "0",
            "is_group": "false",
            "milestone": "false",
            "issue_source": "44ab97f6c75200107e299e0703c2602a",
            "action_plan": "",
            "response": "",
            "issue_rating": "",
            "location": ""
        }
    }
    


    Get Incident or Security Incidents or GRC Issues or Custom Table Record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: GET

    Path Parameters

    KeyValue
    tableincident sn_si_incident sn_grc_issue custom_table_name

    Parameters

    KeyValue
    sysparm_fieldssys_id,state,severity,assigned_to
    sysparm_querysys_idIN<incident_sys_id>

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "severity": "2",
                "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
                "state": "10",
                "assigned_to": {
                    "link": "https://<Instance URL>/api/now/table/sys_user/324sndm",
                    "value": "324sndm"
                }
            }
        ]
    }
    

    Sample API Response (GRC Issue) (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "444a541847e5161034d5e0d3706d4326",
                "impact": "3",
                "state": "1",
                "assigned_to": ""
            }
        ]
    }
    

    Update Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: PATCH

    Path Parameters

    KeyValue
    tableincident sn_si_incident sn_grc_issue custom_table_name

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Body

    
    {
        "work_notes": "Received new alert with Alert ID: $id and Alert Name: $alertName in Cloud Exchange."
    }
    

    Sample API Response (Status Code: 200)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 11:56:25",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "automation",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "2",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    


    Fetch Assignee Users

    API Endpoint: <Instance URL>/api/now/table/sys_user

    Method: GET

    Parameters

    KeyValue
    sysparm_querysys_id,user_name
    sysparm_fieldssys_idIN<user_sys_id>

    Headers

    KeyValue
    User-Agentnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "800b174138d089c868d09de320f9833b",
                "user_name": "user.abc"
            }
        ]
    }
    

    Performance Matrix

    These readings are collected on a Large CE Stack with these specifications.

    Performed performance for Custom table on ServiceNow instance.

    DescriptionSpecification
    Stack detailsSize: Large

    RAM: 32 GB

    CPU: 16 Cores

    Tickets Created Per Minute~ 160 Incidents/min

    User Agent

    netskope-ce-6.0.0-cto-servicenow-v2.2.0

    Workflow

    1. Create a new user in ServiceNow
    2. Assign a role to the user
    3. Configure the ServiceNow plugin
    4. Add a Business Rule for ServiceNow.
    5. Add a Queue for ServiceNow.
    6. Validate the plugin.

    Watch a video

    Click play to watch a video.

     

    Create a New User

    1. Log in to ServiceNow.
    2. Go to System Security > Users and Groups > Users.
    3. Click New.
    4. Enter the required information and make a copy of the User ID. Click Submit.
    5. On the Users page, search for your user ID and click on your user (like shown below).
    6. Click Set Password.
    7. Click Generate. Copy the password, and then click Save Password and Close.

    Assign Role to the User

    1. Scroll down to Roles and click Edit.
    2. Add roles per your requirements:
      Roles required when Incidents is configured in the Destination Table parameter:
      • itil or sn_incident_write, sn_incident_read
        personalize_dictionary
      Role required when Security Incidents is configured in the Destination Table parameter:
      • sn_si.admin
      Roles required when GRC Issues is configured in the Destination Table parameter:
      • sn_grc.business_user (Users can only view issues that they have created themselves or have been assigned to them) admin (This permission is necessary to view all GRC Issues, regardless of creator or assignee)
      Role required when Custom Table is configured in the Destination Table parameter:
      • admin
    3. Click Save.

      Note

      Admin permission is only required for accessing all GRC issues irrespective of its creator and assignee.

    4. Click Update.

    Configure the ServiceNow Plugin

    1. In Cloud Exchange, go to Settings > Plugin Store. Search for and select ServiceNow v2.2.0 (CTO) plugin box.
    2. Provide a Configuration Name and change the Sync Interval per your requirement.
    3. Click Next and enter the Authentication Parameters:
      • Instance URL: ServiceNow Instance URL.
      • Username: Instance username.
      • Password: Instance password.
      • Destination Table: Name of the table where incidents will be created.
    4. Enter the Configuration Parameters. For Custom Table, map these fields as per your requirement.
      • Custom Table Name: Provide name of your custom table.
      • Custom Status: Status field Column name of your custom table.
      • Custom Severity: Severity field Column name of your custom table.
      • Custom Assignee: Assignee field Column name of your custom table if it reference to the ‘sys_user_’ table of the ServiceNow.
      • Custom Group: Group field Column name of your custom table if it reference to the ‘sys_user_group’ table of the ServiceNow.
      • Custom Update: Update field Column name of your custom table. This field will be used to add a message when the dedup rule is executed.

      Note

      No fields will be mapped by default for the custom table in the Queue Configuration. However, if you specify the Custom Update field, a default mapping for Deduplication Map Fields will be provided during queue creation.

    5. Use Default Mappings: Select Yes for the No Queue option (No Queue uses default mappings for the queue, and does not require elevated access) on the Queue configuration page; otherwise, select No.
      • Yes: These default mappings will be used for the No Queue option.
        Target FieldsValues
        Short DescriptionNetskope $appCategory alert name: $alertName
        Event Name: $alert_name
        DescriptionAlert/Event ID: $id
        Alert/Event App: $appAlert/Event
        User: $userAlert
        Name: $alertName
        Alert Type: $alertType
        Alert App Category: $appCategory
        Event Name: $alert_name
        Event Type: $eventType
      • No: You can create custom mappings.
    6. Select the mapping configuration from the following fields.
      Following is the default mapping for status and severity mappings:
      To create a custom status, click Add at the bottom of the page.
      Click Add New to create a Cloud Exchange field.
      Provide the field name and click Add Field. Map it to the the status of your choice.
    7. Click Save.

    Add a Ticket Orchestrator Business Rule for ServiceNow

    Create a business rule based on the filters you need to create incidents in the ServiceNow plugin.

    1. In Ticket Orchestrator, got to Business Rules and click Create New Rule.
    2. Enter a Rule Name and build the appropriate filter query condition on the field(s) for the business rule. You can also enter the query manually by clicking Filter Query.
    3. Click Save.

    Add a Ticket Orchestrator Queue for ServiceNow

    1. In Ticket Orchestrator, go to Queues and click Add Queue Configuration.
    2. Select the Business Rule, plugin Configuration, and Queue from the dropdowns.

      Note

      Target fields for Map Fields section will be fetched from the ServiceNow instance based on the destination table selected during the plugin configuration.

    3. Click Save and sync the queue if you already have the alerts/events pulled.

    Validate the ServiceNow Plugin

    Validate in Cloud Exchange

    In order to validate the workflow, you must already have Netskope Alerts/Events.

    • To view the list of tickets created on ServiceNow, go to Tickets in Ticket Orchestrator.

    Note

    Any status that is not mapped with corresponding Cloud Exchange fields will not sync the status of the ticket.

    • Verify Ticket creation/sync by going to Logging.

    Validate in ServiceNow

    To validate the incident creation, go to Tickets in Ticket Orchestrator, and open on External Link of Ticket
    Make sure you are logged in to ServiceNow.

    Security Incident Ticket:

    Incident Ticket:

    GRC Issues Ticket:

    Custom Table Ticket:

    Troubleshooting the ServiceNow Plugin

    Unable to update Destination table to Custom table during the plugin upgrade

    When upgrading the plugin from old version to v2.1.0, you might encounter this error if you select the Custom Table in the Destination Table field:

    
    CTO ServiceNow [CTO ServiceNow]: Validation error occurred. Custom Table Name is required Configuration Parameter.
    

    What to do: You need to use the Skip button, then edit the plugin configuration from the plugins page to use the Custom table.

    Unable to configure the CTO ServiceNow plugin

    If you are unable to configure the ServiceNow plugin, it could be due to one of these reasons:

    • Incorrect credentials provided.
    • User does not have required permissions.
    • Incorrect instance URL provided.

    What to do:

    1. Make sure to provide the correct credentials. Follow the steps, to create a user.
    2. Make sure that the user has the required permissions. Follow the steps, to provide a role to the user.
    3. Make sure that the correct instance URL is provided.
    Unable to create an Incident using the plugin

    If you are unable to create an Incident in the plugin, it could be due to one of these reasons:

    • No alerts or events are available in Cloud Exchange, or no new alerts or events are pulled.
    • Business Rule has no alerts/events filtered.
    • The user does not have a required role for creating incidents.

    What to do: Find the root cause and select the best fit resolution.

    1. Check if the alerts/events are available in the Alerts/Events page, if no alerts/events are available the ticket won’t be created. Configure Tenant or other required configuration to create alerts/events in Ticket Orchestrator.
    2. Check the business rule and test it to confirm if it has any alerts filtered. If no alerts are available in the filtering, update the business rule.
    3. Ensure users have required roles. Follow the steps, to provide a role to the user.

    Known Behavior

    We have observed that in the Incidents table, when an incident is created and the Assignee field is mapped in the Queue mapping, the incident is automatically assigned the In Progress state, even when the incident event retrieved from the Netskope Tenant has a status of New.

    In this Topic
    • ServiceNow Plugin for Ticket Orchestrator