This document explains how to configure your ServiceNow v2.2.0 plugin with the Ticket Orchestrator module of the Netskope Cloud Exchange platform. This plugin is used to create incidents on the Incident > All page, security incidents on the Security Incident > Incidents > Show All Incidents page, GRC issues on the Policy and Compliance > Issues > All Issues page and records on the Custom Table record page of the ServiceNow platform. It also supports updating incidents/issues and syncing their status. This plugin is NOT the same as ServiceNow’s DLP Incident Response product, nor does this plugin work with that solution.
Prerequisites
To complete this configuration, you need:
- A Netskope tenant (or multiple, for example, production and development/test instances).
- A Netskope Cloud Exchange tenant with the the Tenant plugin and Ticket Orchestrator plugin already configured.
- A ServiceNow account.
- Permissions needed for the plugin are
itilorsn_incident_write,sn_incident_read,personalize_dictionary,sn_si.admin,sn_grc.business_user,andadmin. - Connectivity to the following host:
https://<instance>.service-now.com/ - For GRC Issue creation, GRC: Policy and Compliance Management (App id: sn_compliance) plugin should be installed on your ServiceNow Instance.
ServiceNow Plugin Support
This plugin is used to create incidents on the Incident, Security Incident, GRC issues, and Custom Table records on ServiceNow.
| Supported Alert Types for Tickets | Supported Event Types for Tickets |
|---|---|
| Compromised Credentials, policy, malsite, Malware, DLP, Security Assessment, watchlist, quarantine, Remediation, UBA, CTEP, Device, Content | Endpoint, Incident |
Mappings
Queue Mappings
| Target Fields | Values |
|---|---|
| Short Description | Netskope $appCategory alert name: $alertName Event Name: $alert_name |
| Description | Alert/Event ID: $id Alert/Event App: $appAlert/Event User: $userAlert Name: $alertNameAlert Type: $alertTypeAlert App Category: $appCategoryEvent Name: $alert_nameEvent Type: $eventType |
Default Status Mappings
This mapping is used to map the Netskope CE Status to ServiceNow Status. You can find the available ServiceNow Status by going to System Definitions > Tables> [Table Name] > [Status Column Name] > Choices.
| Cloud Exchange Status | Value | ServiceNow Status |
|---|---|---|
| New | 1 | New |
| In Progress | 2 | In Progress |
| On Hold | 3 | On Hold |
| Closed | 7 | Closed |
| Deleted | – | (Default will be blank) You can create custom fields on ServiceNow to map. |
| Other | – | (Default will be blank) |
Default Severity Mappings
This mapping is used to map the Netskope CE Severity to ServiceNow Severity. You can find the available ServiceNow Severity values by going to System Definitions > Tables > [Table Name] > [Severity Column Name] > Choices.
| Cloud Exchange Severity | Value | ServiceNow Severity |
|---|---|---|
| Critical | – | (Default will be blank)
You can create custom fields on ServiceNow to map. |
| High | 1 | High |
| Medium | 2 | Medium |
| Low | 3 | Low |
| Informational | – | (Default will be blank)
You can create custom fields on ServiceNow to map. |
| Other | – | (Default will be blank) |
Note
Default status and severity mapping in the ServiceNow plugin may vary, as these fields can be customized within the platform. Any status or severity that is not mapped with corresponding Netskope CE fields will be marked as other.
Supported Fields in a Queue Configuration for Default Tables
Here is the list of supported Fields in Queue Configuration for Default tables that you can map while creating the incident on ServiceNow.
Security Incident
| Field Name | Field Type |
|---|---|
| Malware hash | String |
| MITRE ATT&CK Procedure (Malware) | String |
| Last Updated From Source | Choice |
| Number | String |
| Platforms(MITRE) | String |
| Parent security incident | Reference |
| Affected user | Reference |
| Alert Rule | String |
| New respondents | Glide_list |
| Machine learning Prediction | String |
| Destination IP | String |
| Problem | Reference |
| Service | Reference |
| Effective number | String |
| Service offering | Reference |
| Rejection goto | Reference |
| Malware URL | String |
| Assigned to | Reference |
| Escalation | Integer |
| Time worked | Timer |
| Additional assignee list | Glide_list |
| Correlation ID | String |
| MITRE ATT&CK Tactic | String |
| Phish Email | Reference |
| Variables | Variables |
| Alert Sensor | Reference |
| Additional comments | Journal_input |
| Urgency | Integer |
| Opened | Glide_date_time |
| Watch list | Glide_list |
| SLA due | Due_date |
| Contract | Reference |
| Active | Boolean |
| State | Integer |
| Work notes | Journal_input |
| Closed by | Reference |
| Follow up | Glide_date_time |
| Configuration item | Reference |
| Approval history | Journal |
| Business duration | Glide_duration |
| Location | Reference |
| User input | User_input |
| Source IP | String |
| Change request | Reference |
| Risk | Integer |
| Workflow activity | Reference |
| Risk change | String |
| MITRE ATT&CK Data Source | String |
| Work notes list | Glide_list |
| Skills | Glide_list |
| Attack Vector | Glide_list |
| MITRE ATT&CK Technique | String |
| Allowed groups | Glide_list |
| Automation activity | Journal |
| Business impact | Integer |
| Close code | String |
| Read access | Glide_list |
| Privileged access | Glide_list |
| Risk score | Integer |
| Security tags | Glide_list |
| Severity | Integer |
| Security incident self | Reference |
| Incident | Reference |
| Comments and Work notes | Journal_list |
| MITRE ATT&CK Adversary Group | String |
| Description | String |
| Impact | Integer |
| Closed | Glide_date_time |
| Group list | Glide_list |
| Activity due | Due_date |
| MITRE ATT&CK Procedure (Tool) | String |
| Request assessments | Glide_list |
| Allowed members | Glide_list |
| Parent | Reference |
| Priority | Integer |
| Close notes | String |
| Reassignment count | Integer |
| Due date | Glide_date_time |
| Order | Integer |
| Short description | String |
| Company | Reference |
| Approval set | Glide_date_time |
| Opened by | Reference |
| Contact type | String |
| Made SLA | Boolean |
| Post incident report | Html |
| Assignment group | Reference |
| Approval | String |
| Duration | Glide_duration |
| Knowledge | Boolean |
| Correlation display | String |
| Other IoC | String |
| Referrer URL | String |
| Confidence score | Decimal |
| Department | Glide_list |
| Vulnerability | Reference |
| Delivery task | Reference |
| Actual end | Glide_date_time |
| Universal Request | Reference |
| Expected start | Glide_date_time |
| Actual start | Glide_date_time |
| Upon approval | String |
| Transfer reason | Integer |
| Enforce restriction | Boolean |
| External URL | Url |
| Delivery plan | Reference |
| Upon reject | String |
| Override risk score | Boolean |
Incident
| Field Name | Field Type |
|---|---|
| Business impact | String |
| Probable cause | String |
| Reopen count | Integer |
| Number | String |
| Parent Incident | Reference |
| Service | Reference |
| Change Request | Reference |
| Effective number | String |
| Service offering | Reference |
| Incident state | Integer |
| Resolve time | Integer |
| Rejection goto | Reference |
| Origin table | Table_name |
| Resolved by | Reference |
| Chronicle Incident | Reference |
| Assigned to | Reference |
| Escalation | Integer |
| Time worked | Timer |
| Additional assignee list | Glide_list |
| Correlation ID | String |
| Variables | Variables |
| Child Incidents | Integer |
| Additional comments | Journal_input |
| Urgency | Integer |
| Opened | Glide_date_time |
| Watch list | Glide_list |
| SLA due | Due_date |
| Contract | Reference |
| Active | Boolean |
| State | Integer |
| Work notes | Journal_input |
| Closed by | Reference |
| Follow up | Glide_date_time |
| Configuration item | Reference |
| Approval history | Journal |
| Business duration | Glide_duration |
| Location | Reference |
| User input | User_input |
| Category | String |
| Business resolve time | Integer |
| Origin | Document_id |
| Workflow activity | Reference |
| Caused by Change | Reference |
| Work notes list | Glide_list |
| Close code | String |
| Skills | Glide_list |
| Resolved | Glide_date_time |
| Splunk URL | Url |
| Last reopened at | Glide_date_time |
| Problem | Reference |
| Caller | Reference |
| Subcategory | String |
| Comments and Work notes | Journal_list |
| Description | String |
| Impact | Integer |
| Closed | Glide_date_time |
| Group list | Glide_list |
| Activity due | Due_date |
| Parent | Reference |
| Priority | Integer |
| Close notes | String |
| Reassignment count | Integer |
| Due date | Glide_date_time |
| Order | Integer |
| Short description | String |
| Company | Reference |
| Approval set | Glide_date_time |
| Opened by | Reference |
| Contact type | String |
| Made SLA | Boolean |
| On hold reason | Integer |
| Assignment group | Reference |
| Approval | String |
| Duration | Glide_duration |
| Knowledge | Boolean |
| Correlation display | String |
| Delivery task | Reference |
| Actual end | Glide_date_time |
| Universal Request | Reference |
| Expected start | Glide_date_time |
| Notify | Integer |
| Actual start | Glide_date_time |
| Upon approval | String |
| Severity | Integer |
| Transfer reason | Integer |
| Delivery plan | Reference |
| Upon reject | String |
| Last reopened by | Reference |
GRC Issues
| Field Name | Field Type |
|---|---|
| Is reparenting group | Boolean |
| Authority document | Reference |
| Item | Reference |
| Issue manager | Reference |
| Issue rating | Reference |
| Management method | String |
| Document | Reference |
| Explanation | String |
| Recommendation | String |
| Action plan | Html |
| Substate | String |
| Parent issue | Reference |
| Control objective/Risk statement | Reference |
| Entity | Reference |
| Functional domain | Glide_list |
| User hierarchy status | String |
| Is group | Boolean |
| Issue group rule | Reference |
| Issue manager group | Reference |
| Classification | String |
| Allowed groups | Glide_list |
| Issue source | Glide_list |
| User hierarchy 2 | Reference |
| User hierarchy 1 | Reference |
| Policy | Reference |
| Confidential | Boolean |
| Response | Integer |
| Confirmed date | Glide_date_time |
| Issue type | String |
| Allowed users | Glide_list |
| Created manually | Boolean |
| Group level | String |
| Actual end | Glide_date_time |
| Company | Reference |
| Number | String |
| Impact | Integer |
| Short description | String |
| Approval set | Glide_date_time |
| Description | String |
| Closed | Glide_date_time |
| Opened by | Reference |
| Made SLA | Boolean |
| Group list | Glide_list |
| Contact type | String |
| Activity due | Due_date |
| Workflow activity | Reference |
| Rejection goto | Reference |
| Upon reject | String |
| Contract | Reference |
| Escalation | Integer |
| Effective number | String |
| Active | Boolean |
| Work notes | Journal_input |
| Assigned to | Reference |
| Time worked | Timer |
| Business service | Reference |
| State | Integer |
| Additional assignee list | Glide_list |
| Follow up | Glide_date_time |
| Correlation ID | String |
| Work notes list | Glide_list |
| Universal Request | Reference |
| Closed by | Reference |
| Delivery plan | Reference |
| Upon approval | String |
| Parent | Reference |
| Close notes | String |
| Assignment group | Reference |
| Duration | Glide_duration |
| Priority | Integer |
| Approval | String |
| Due date | Glide_date_time |
| Correlation display | String |
| Reassignment count | Integer |
| Order | Integer |
| Knowledge | Boolean |
| Service offering | Reference |
| Delivery task | Reference |
| Configuration item | Reference |
| Comments and Work notes | Journal_list |
| Urgency | Integer |
| Approval history | Journal |
| Additional comments | Journal_input |
| Opened | Glide_date_time |
| Business duration | Glide_duration |
| User input | User_input |
| Variables | Variables |
| Watch list | Glide_list |
| Location | Reference |
| SLA due | Due_date |
| Actual start | Glide_date_time |
| Expected start | Glide_date_time |
| Transfer reason | Integer |
| Skills | Glide_list |
Permissions
- Permission to send data to the Workflow URL.
- Roles required when Incidents is configured in the Destination Table parameter:
- itil or sn_incident_write, sn_incident_read
- personalize_dictionary
- Role required when Security Incidents is configured in the Destination Table parameter:
- sn_si.admin
- Roles required when GRC Issues is configured in the Destination Table parameter:
- sn_grc.business_user (Users can only view issues that they have created themselves or have been assigned to them)
- admin (This permission is necessary to view all GRC Issues, regardless of creator or assignee)
- Role required when Custom Table is configured in the Destination Table parameter:
- admin
- Roles required when Incidents is configured in the Destination Table parameter:
API Details
List of APIs used
| API Endpoint | Method | Use Case |
|---|---|---|
| /api/now/table/sys_dictionary | GET | Get Incident or Security Incident or GRC Issue or Custom Table Fields |
| /api/now/table/sys_user_group | GET | Get ServiceNow groups as Queue |
| /api/now/table/<table> | POST | Create Incident or Security Incident or GRC Issue or Custom Table Record |
| /api/now/table/<table> | GET | Get Incident or Security Incidents or GRC Issues or Custom Table Record |
| /api/now/table/<table>/<incident_id> | PATCH | Update Incident or Security Incident or GRC Issue or Custom Table Record |
| /api/now/table/sys_user | GET | Fetch Assignee Users |
Get Incident or Security Incident or GRC Issue or Custom Table Fields
API Endpoint: <Instance URL>/api/now/table/sys_dictionary
Method: GET
Parameters
| Key | Value |
|---|---|
| sysparm_query | name=<table_name>^ORname=task^internal_type!=collection For Custom Table: name=<custom_table_name> |
| sysparm_fields | column_label,element |
| sysparm_limit | 1000 |
| sysparm_offset | 0 |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Sample API Response (Security Incident) (Status Code: 200)
{
"result": [
{
"column_label": "Malware hash",
"element": "malware_hash"
},
{
"column_label": "MITRE ATT&CK Procedure (Malware)",
"element": "mitre_malware"
},
{
"column_label": "Last Updated From Source",
"element": "last_updated_from_src"
},
{
"column_label": "Number",
"element": "number"
},
{
"column_label": "Platforms(MITRE)",
"element": "mitre_platform"
},
{
"column_label": "Parent security incident",
"element": "parent_security_incident"
},
{
"column_label": "Affected user",
"element": "affected_user"
},
{
"column_label": "Alert Rule",
"element": "alert_rule"
},
{
"column_label": "New respondents",
"element": "new_pir_respondents"
},
{
"column_label": "Machine learning Prediction",
"element": "prediction"
},
{
"column_label": "Destination IP",
"element": "dest_ip"
},
{
"column_label": "Problem",
"element": "problem"
},
{
"column_label": "Service",
"element": "business_service"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "Effective number",
"element": "task_effective_number"
},
{
"column_label": "Service offering",
"element": "service_offering"
},
{
"column_label": "Rejection goto",
"element": "rejection_goto"
},
{
"column_label": "Malware URL",
"element": "malware_url"
},
{
"column_label": "Assigned to",
"element": "assigned_to"
},
{
"column_label": "Escalation",
"element": "escalation"
},
{
"column_label": "Time worked",
"element": "time_worked"
},
{
"column_label": "Additional assignee list",
"element": "additional_assignee_list"
},
{
"column_label": "Correlation ID",
"element": "correlation_id"
},
{
"column_label": "Updated by",
"element": "sys_updated_by"
},
{
"column_label": "MITRE ATT&CK Tactic",
"element": "mitre_tactic"
},
{
"column_label": "Phish Email",
"element": "phish_email"
},
{
"column_label": "Variables",
"element": "variables"
},
{
"column_label": "Alert Sensor",
"element": "alert_sensor"
},
{
"column_label": "Additional comments",
"element": "comments"
},
{
"column_label": "Urgency",
"element": "urgency"
},
{
"column_label": "Opened",
"element": "opened_at"
},
{
"column_label": "Watch list",
"element": "watch_list"
},
{
"column_label": "SLA due",
"element": "sla_due"
},
{
"column_label": "Contract",
"element": "contract"
},
{
"column_label": "Active",
"element": "active"
},
{
"column_label": "State",
"element": "state"
},
{
"column_label": "Work notes",
"element": "work_notes"
},
{
"column_label": "Closed by",
"element": "closed_by"
},
{
"column_label": "Follow up",
"element": "follow_up"
},
{
"column_label": "Domain",
"element": "sys_domain"
},
{
"column_label": "Updates",
"element": "sys_mod_count"
},
{
"column_label": "Configuration item",
"element": "cmdb_ci"
},
{
"column_label": "Approval history",
"element": "approval_history"
},
{
"column_label": "Business duration",
"element": "business_duration"
},
{
"column_label": "Location",
"element": "location"
},
{
"column_label": "User input",
"element": "user_input"
},
{
"column_label": "Created by",
"element": "sys_created_by"
},
{
"column_label": "Source IP",
"element": "source_ip"
},
{
"column_label": "Change request",
"element": "change_request"
},
{
"column_label": "Risk",
"element": "risk"
},
{
"column_label": "Workflow activity",
"element": "wf_activity"
},
{
"column_label": "Risk change",
"element": "risk_change"
},
{
"column_label": "MITRE ATT&CK Data Source",
"element": "mitre_data_source"
},
{
"column_label": "Work notes list",
"element": "work_notes_list"
},
{
"column_label": "Skills",
"element": "skills"
},
{
"column_label": "Attack Vector",
"element": "attack_vector"
},
{
"column_label": "MITRE ATT&CK Technique",
"element": "mitre_technique"
},
{
"column_label": "Allowed groups",
"element": "allowed_groups"
},
{
"column_label": "Automation activity",
"element": "automation_activity"
},
{
"column_label": "Business impact",
"element": "business_criticality"
},
{
"column_label": "Close code",
"element": "close_code"
},
{
"column_label": "Read access",
"element": "special_access_read"
},
{
"column_label": "Privileged access",
"element": "special_access_write"
},
{
"column_label": "Risk score",
"element": "risk_score"
},
{
"column_label": "Security tags",
"element": "security_tags"
},
{
"column_label": "Severity",
"element": "severity"
},
{
"column_label": "Security incident self",
"element": "security_incident_self"
},
{
"column_label": "Incident",
"element": "incident"
},
{
"column_label": "Comments and Work notes",
"element": "comments_and_work_notes"
},
{
"column_label": "MITRE ATT&CK Adversary Group",
"element": "mitre_group"
},
{
"column_label": "Description",
"element": "description"
},
{
"column_label": "Impact",
"element": "impact"
},
{
"column_label": "Closed",
"element": "closed_at"
},
{
"column_label": "Group list",
"element": "group_list"
},
{
"column_label": "Activity due",
"element": "activity_due"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "MITRE ATT&CK Procedure (Tool)",
"element": "mitre_tool"
},
{
"column_label": "Request assessments",
"element": "pir_respondents"
},
{
"column_label": "Allowed members",
"element": "allowed_members"
},
{
"column_label": "Task type",
"element": "sys_class_name"
},
{
"column_label": "Parent",
"element": "parent"
},
{
"column_label": "Priority",
"element": "priority"
},
{
"column_label": "Close notes",
"element": "close_notes"
},
{
"column_label": "Reassignment count",
"element": "reassignment_count"
},
{
"column_label": "Due date",
"element": "due_date"
},
{
"column_label": "Order",
"element": "order"
},
{
"column_label": "Short description",
"element": "short_description"
},
{
"column_label": "Company",
"element": "company"
},
{
"column_label": "Approval set",
"element": "approval_set"
},
{
"column_label": "Opened by",
"element": "opened_by"
},
{
"column_label": "Contact type",
"element": "contact_type"
},
{
"column_label": "Made SLA",
"element": "made_sla"
},
{
"column_label": "Created",
"element": "sys_created_on"
},
{
"column_label": "Post incident report",
"element": "pir"
},
{
"column_label": "Assignment group",
"element": "assignment_group"
},
{
"column_label": "Approval",
"element": "approval"
},
{
"column_label": "Duration",
"element": "calendar_duration"
},
{
"column_label": "Knowledge",
"element": "knowledge"
},
{
"column_label": "Correlation display",
"element": "correlation_display"
},
{
"column_label": "Updated",
"element": "sys_updated_on"
},
{
"column_label": "Other IoC",
"element": "other_ioc"
},
{
"column_label": "Referrer URL",
"element": "referrer_url"
},
{
"column_label": "Confidence score",
"element": "confidence_score"
},
{
"column_label": "Department",
"element": "department"
},
{
"column_label": "Vulnerability",
"element": "vulnerability"
},
{
"column_label": "Delivery task",
"element": "delivery_task"
},
{
"column_label": "Actual end",
"element": "work_end"
},
{
"column_label": "Domain Path",
"element": "sys_domain_path"
},
{
"column_label": "Universal Request",
"element": "universal_request"
},
{
"column_label": "Expected start",
"element": "expected_start"
},
{
"column_label": "Actual start",
"element": "work_start"
},
{
"column_label": "Upon approval",
"element": "upon_approval"
},
{
"column_label": "Transfer reason",
"element": "route_reason"
},
{
"column_label": "Enforce restriction",
"element": "enforce_restriction"
},
{
"column_label": "External URL",
"element": "external_url"
},
{
"column_label": "Delivery plan",
"element": "delivery_plan"
},
{
"column_label": "Upon reject",
"element": "upon_reject"
},
{
"column_label": "Override risk score",
"element": "risk_score_override"
}
]
}
Sample API Response (Incident) (Status Code: 200)
{
"result": [
{
"column_label": "Business impact",
"element": "business_impact"
},
{
"column_label": "Probable cause",
"element": "cause"
},
{
"column_label": "Reopen count",
"element": "reopen_count"
},
{
"column_label": "Number",
"element": "number"
},
{
"column_label": "Parent Incident",
"element": "parent_incident"
},
{
"column_label": "Service",
"element": "business_service"
},
{
"column_label": "Change Request",
"element": "rfc"
},
{
"column_label": "Effective number",
"element": "task_effective_number"
},
{
"column_label": "Service offering",
"element": "service_offering"
},
{
"column_label": "Incident state",
"element": "incident_state"
},
{
"column_label": "Resolve time",
"element": "calendar_stc"
},
{
"column_label": "Rejection goto",
"element": "rejection_goto"
},
{
"column_label": "Origin table",
"element": "origin_table"
},
{
"column_label": "Resolved by",
"element": "resolved_by"
},
{
"column_label": "Assigned to",
"element": "assigned_to"
},
{
"column_label": "Escalation",
"element": "escalation"
},
{
"column_label": "Time worked",
"element": "time_worked"
},
{
"column_label": "Additional assignee list",
"element": "additional_assignee_list"
},
{
"column_label": "Correlation ID",
"element": "correlation_id"
},
{
"column_label": "Updated by",
"element": "sys_updated_by"
},
{
"column_label": "Variables",
"element": "variables"
},
{
"column_label": "Child Incidents",
"element": "child_incidents"
},
{
"column_label": "Additional comments",
"element": "comments"
},
{
"column_label": "Urgency",
"element": "urgency"
},
{
"column_label": "Opened",
"element": "opened_at"
},
{
"column_label": "Watch list",
"element": "watch_list"
},
{
"column_label": "SLA due",
"element": "sla_due"
},
{
"column_label": "Contract",
"element": "contract"
},
{
"column_label": "Active",
"element": "active"
},
{
"column_label": "State",
"element": "state"
},
{
"column_label": "Work notes",
"element": "work_notes"
},
{
"column_label": "Closed by",
"element": "closed_by"
},
{
"column_label": "Follow up",
"element": "follow_up"
},
{
"column_label": "Domain",
"element": "sys_domain"
},
{
"column_label": "Updates",
"element": "sys_mod_count"
},
{
"column_label": "Configuration item",
"element": "cmdb_ci"
},
{
"column_label": "Approval history",
"element": "approval_history"
},
{
"column_label": "Business duration",
"element": "business_duration"
},
{
"column_label": "Location",
"element": "location"
},
{
"column_label": "User input",
"element": "user_input"
},
{
"column_label": "Created by",
"element": "sys_created_by"
},
{
"column_label": "Category",
"element": "category"
},
{
"column_label": "Chronicle Incident",
"element": "x_cdsp_chroni_itsm_chronicle_incident_ref"
},
{
"column_label": "Business resolve time",
"element": "business_stc"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "Origin",
"element": "origin_id"
},
{
"column_label": "Workflow activity",
"element": "wf_activity"
},
{
"column_label": "Caused by Change",
"element": "caused_by"
},
{
"column_label": "Work notes list",
"element": "work_notes_list"
},
{
"column_label": "Close code",
"element": "close_code"
},
{
"column_label": "Skills",
"element": "skills"
},
{
"column_label": "Resolved",
"element": "resolved_at"
},
{
"column_label": "Splunk URL",
"element": "x_splu2_splunk_ser_splunk_url"
},
{
"column_label": "Last reopened at",
"element": "reopened_time"
},
{
"column_label": "Problem",
"element": "problem_id"
},
{
"column_label": "Caller",
"element": "caller_id"
},
{
"column_label": "Subcategory",
"element": "subcategory"
},
{
"column_label": "Comments and Work notes",
"element": "comments_and_work_notes"
},
{
"column_label": "Description",
"element": "description"
},
{
"column_label": "Impact",
"element": "impact"
},
{
"column_label": "Closed",
"element": "closed_at"
},
{
"column_label": "Group list",
"element": "group_list"
},
{
"column_label": "Activity due",
"element": "activity_due"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "Task type",
"element": "sys_class_name"
},
{
"column_label": "Parent",
"element": "parent"
},
{
"column_label": "Priority",
"element": "priority"
},
{
"column_label": "Close notes",
"element": "close_notes"
},
{
"column_label": "Reassignment count",
"element": "reassignment_count"
},
{
"column_label": "Due date",
"element": "due_date"
},
{
"column_label": "Order",
"element": "order"
},
{
"column_label": "Short description",
"element": "short_description"
},
{
"column_label": "Company",
"element": "company"
},
{
"column_label": "Approval set",
"element": "approval_set"
},
{
"column_label": "Opened by",
"element": "opened_by"
},
{
"column_label": "Contact type",
"element": "contact_type"
},
{
"column_label": "Made SLA",
"element": "made_sla"
},
{
"column_label": "Created",
"element": "sys_created_on"
},
{
"column_label": "On hold reason",
"element": "hold_reason"
},
{
"column_label": "Assignment group",
"element": "assignment_group"
},
{
"column_label": "Approval",
"element": "approval"
},
{
"column_label": "Duration",
"element": "calendar_duration"
},
{
"column_label": "Knowledge",
"element": "knowledge"
},
{
"column_label": "Correlation display",
"element": "correlation_display"
},
{
"column_label": "Updated",
"element": "sys_updated_on"
},
{
"column_label": "Delivery task",
"element": "delivery_task"
},
{
"column_label": "Actual end",
"element": "work_end"
},
{
"column_label": "Domain Path",
"element": "sys_domain_path"
},
{
"column_label": "Universal Request",
"element": "universal_request"
},
{
"column_label": "Expected start",
"element": "expected_start"
},
{
"column_label": "Notify",
"element": "notify"
},
{
"column_label": "Actual start",
"element": "work_start"
},
{
"column_label": "Upon approval",
"element": "upon_approval"
},
{
"column_label": "Severity",
"element": "severity"
},
{
"column_label": "Transfer reason",
"element": "route_reason"
},
{
"column_label": "Delivery plan",
"element": "delivery_plan"
},
{
"column_label": "Upon reject",
"element": "upon_reject"
},
{
"column_label": "Last reopened by",
"element": "reopened_by"
}
]
}
Sample API Response (GRC Issues) (Status Code: 200)
{
"result": [
{
"column_label": "Is reparenting group",
"element": "is_reparenting_group"
},
{
"column_label": "Authority document",
"element": "authority_document"
},
{
"column_label": "Item",
"element": "item"
},
{
"column_label": "Issue manager",
"element": "issue_manager"
},
{
"column_label": "Issue rating",
"element": "issue_rating"
},
{
"column_label": "Management method",
"element": "management_method"
},
{
"column_label": "Document",
"element": "document"
},
{
"column_label": "Explanation",
"element": "explanation"
},
{
"column_label": "Recommendation",
"element": "recommendation"
},
{
"column_label": "Action plan",
"element": "action_plan"
},
{
"column_label": "Substate",
"element": "substate"
},
{
"column_label": "Parent issue",
"element": "parent_issue"
},
{
"column_label": "Control objective/Risk statement",
"element": "content"
},
{
"column_label": "Entity",
"element": "profile"
},
{
"column_label": "Functional domain",
"element": "functional_domain"
},
{
"column_label": "User hierarchy status",
"element": "user_hierarchy_status"
},
{
"column_label": "Is group",
"element": "is_group"
},
{
"column_label": "Issue group rule",
"element": "issue_group_rule"
},
{
"column_label": "Issue manager group",
"element": "issue_manager_group"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "Classification",
"element": "classification"
},
{
"column_label": "Allowed groups",
"element": "confidential_user_groups"
},
{
"column_label": "Issue source",
"element": "issue_source"
},
{
"column_label": "User hierarchy 2",
"element": "user_hierarchy_2"
},
{
"column_label": "User hierarchy 1",
"element": "user_hierarchy_1"
},
{
"column_label": "Policy",
"element": "policy"
},
{
"column_label": "Confidential",
"element": "is_confidential"
},
{
"column_label": "Response",
"element": "response"
},
{
"column_label": "Confirmed date",
"element": "confirmed_date"
},
{
"column_label": "Issue type",
"element": "issue_type"
},
{
"column_label": "Allowed users",
"element": "confidential_users"
},
{
"column_label": "Created manually",
"element": "created_manually"
},
{
"column_label": "Group level",
"element": "group_level"
},
{
"column_label": "Actual end",
"element": "work_end"
},
{
"column_label": "Company",
"element": "company"
},
{
"column_label": "Task type",
"element": "sys_class_name"
},
{
"column_label": "Number",
"element": "number"
},
{
"column_label": "Impact",
"element": "impact"
},
{
"column_label": "Short description",
"element": "short_description"
},
{
"column_label": "Approval set",
"element": "approval_set"
},
{
"column_label": "Description",
"element": "description"
},
{
"column_label": "Closed",
"element": "closed_at"
},
{
"column_label": "Opened by",
"element": "opened_by"
},
{
"column_label": "Made SLA",
"element": "made_sla"
},
{
"column_label": "Group list",
"element": "group_list"
},
{
"column_label": "Contact type",
"element": "contact_type"
},
{
"column_label": "Activity due",
"element": "activity_due"
},
{
"column_label": "Created by",
"element": "sys_created_by"
},
{
"column_label": "Workflow activity",
"element": "wf_activity"
},
{
"column_label": "Rejection goto",
"element": "rejection_goto"
},
{
"column_label": "Upon reject",
"element": "upon_reject"
},
{
"column_label": "Contract",
"element": "contract"
},
{
"column_label": "Escalation",
"element": "escalation"
},
{
"column_label": "Effective number",
"element": "task_effective_number"
},
{
"column_label": "Active",
"element": "active"
},
{
"column_label": "Work notes",
"element": "work_notes"
},
{
"column_label": "Assigned to",
"element": "assigned_to"
},
{
"column_label": "Time worked",
"element": "time_worked"
},
{
"column_label": "Business service",
"element": "business_service"
},
{
"column_label": "Domain Path",
"element": "sys_domain_path"
},
{
"column_label": "State",
"element": "state"
},
{
"column_label": "Additional assignee list",
"element": "additional_assignee_list"
},
{
"column_label": "Follow up",
"element": "follow_up"
},
{
"column_label": "Sys ID",
"element": "sys_id"
},
{
"column_label": "Correlation ID",
"element": "correlation_id"
},
{
"column_label": "Created",
"element": "sys_created_on"
},
{
"column_label": "Work notes list",
"element": "work_notes_list"
},
{
"column_label": "Universal Request",
"element": "universal_request"
},
{
"column_label": "Closed by",
"element": "closed_by"
},
{
"column_label": "Domain",
"element": "sys_domain"
},
{
"column_label": "Delivery plan",
"element": "delivery_plan"
},
{
"column_label": "Upon approval",
"element": "upon_approval"
},
{
"column_label": "Parent",
"element": "parent"
},
{
"column_label": "Close notes",
"element": "close_notes"
},
{
"column_label": "Assignment group",
"element": "assignment_group"
},
{
"column_label": "Duration",
"element": "calendar_duration"
},
{
"column_label": "Priority",
"element": "priority"
},
{
"column_label": "Approval",
"element": "approval"
},
{
"column_label": "Due date",
"element": "due_date"
},
{
"column_label": "Updated by",
"element": "sys_updated_by"
},
{
"column_label": "Correlation display",
"element": "correlation_display"
},
{
"column_label": "Updates",
"element": "sys_mod_count"
},
{
"column_label": "Reassignment count",
"element": "reassignment_count"
},
{
"column_label": "Order",
"element": "order"
},
{
"column_label": "Knowledge",
"element": "knowledge"
},
{
"column_label": "Service offering",
"element": "service_offering"
},
{
"column_label": "Delivery task",
"element": "delivery_task"
},
{
"column_label": "Configuration item",
"element": "cmdb_ci"
},
{
"column_label": "Comments and Work notes",
"element": "comments_and_work_notes"
},
{
"column_label": "Urgency",
"element": "urgency"
},
{
"column_label": "Approval history",
"element": "approval_history"
},
{
"column_label": "Additional comments",
"element": "comments"
},
{
"column_label": "Opened",
"element": "opened_at"
},
{
"column_label": "Business duration",
"element": "business_duration"
},
{
"column_label": "User input",
"element": "user_input"
},
{
"column_label": "Variables",
"element": "variables"
},
{
"column_label": "Watch list",
"element": "watch_list"
},
{
"column_label": "Location",
"element": "location"
},
{
"column_label": "SLA due",
"element": "sla_due"
},
{
"column_label": "Updated",
"element": "sys_updated_on"
},
{
"column_label": "Actual start",
"element": "work_start"
},
{
"column_label": "Expected start",
"element": "expected_start"
},
{
"column_label": "Transfer reason",
"element": "route_reason"
},
{
"column_label": "Skills",
"element": "skills"
}
]
}
Get ServiceNow groups as Queue
API Endpoint: <Instance URL>/api/now/table/sys_user_group
Method: GET
Parameters
| Key | Value |
|---|---|
| sysparm_fields | name,sys_id |
| sysparm_limit | 1000 |
| sysparm_offset | 0 |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Sample API Response (Status Code: 200)
{ "result": [ { "sys_id": "01336b6347332100158b949b6c9a71b5", "name": "Finance Vendors" }, …. ] }
Create Incident or Security Incident or GRC Issue or Custom Table record
API Endpoint: <Instance URL>/api/now/table/<table>
Method: POST
Path Parameters
| Key | Value |
|---|---|
| table | incident sn_si_incident sn_grc_issue custom_table_name |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Body
{
"short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
"description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
"assignment_group": "<group_sys_id>"
}
Sample API Response (Security Incident) (Status Code: 201)
{
"result": {
"parent": "",
"sla_suspended_reason": "",
"watch_list": "",
"upon_reject": "cancel",
"sys_updated_on": "2024-10-25 10:46:39",
"qualification_group": "",
"expected_end": "",
"enforce_restriction": "false",
"approval_history": "",
"source_ip": "",
"skills": "",
"number": "SIR1083059",
"problem": "",
"previous_agent": "",
"state": "10",
"sys_created_by": "user1.abc",
"template_workflow_invoked": "false",
"knowledge": "false",
"order": "",
"phish_email": "",
"cmdb_ci": "",
"delivery_plan": "",
"contract": "",
"impact": "3",
"active": "true",
"work_notes_list": "",
"vulnerability": "",
"priority": "4",
"sys_domain_path": "/",
"sla_suspended": "false",
"business_duration": "",
"group_list": "",
"special_access_write": "",
"dest_ip": "",
"mitre_platform": "",
"approval_set": "",
"risk_change": "up",
"malware_url": "",
"universal_request": "",
"last_updated_from_src": "",
"template": "",
"short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
"correlation_display": "",
"delivery_task": "",
"work_start": "",
"request_type": "",
"affected_user": "",
"other_ioc": "",
"additional_assignee_list": "",
"alert_sensor": "",
"assigned_vendor": "",
"service_offering": "",
"sys_class_name": "sn_si_incident",
"closed_by": "",
"follow_up": "",
"mitre_group": "",
"sla_suspended_on": "",
"estimated_end": "",
"vendor_reference": "",
"reassignment_count": "0",
"assigned_to": "",
"request_category": "",
"requested_due_by": "",
"mitre_malware": "",
"sla_suspended_for": "",
"business_criticality": "3",
"sla_due": "",
"opened_for": {
"link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
"value": "c813b7cb1b8342148f4aedb8b04bcb91"
},
"comments_and_work_notes": "",
"mitre_technique": "",
"special_access_read": "",
"substate": "",
"escalation": "0",
"upon_approval": "proceed",
"allowed_groups": "",
"correlation_id": "",
"asset": "",
"mitre_tool": "",
"spam": "false",
"referrer_url": "",
"made_sla": "true",
"mitre_tactic": "",
"is_catalog": "false",
"malware_hash": "",
"alert_rule": "",
"task_effective_number": "SIR1083059",
"external_url": "",
"sys_updated_by": "user1.abc",
"opened_by": {
"link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
"value": "c813b7cb1b8342148f4aedb8b04bcb91"
},
"user_input": "",
"sys_created_on": "2024-10-25 10:46:39",
"sys_domain": {
"link": "https://service-now.com/api/now/table/sys_user_group/global",
"value": "global"
},
"pir": "",
"route_reason": "",
"closed_at": "",
"allowed_members": "",
"business_service": "",
"attack_vector": "",
"time_worked": "",
"expected_start": "",
"opened_at": "2024-10-25 10:46:39",
"task_created": "false",
"x_cdsp_chroni_sir_chronicle_si": "",
"work_end": "",
"confidence_score": "",
"prediction": "",
"automation_activity": "",
"subcategory": "",
"work_notes": "",
"security_tags": "",
"risk_score_override": "false",
"initiated_from": "",
"close_code": "",
"assignment_group": {
"link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
"value": "<group_sys_id>"
},
"description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
"calendar_duration": "",
"close_notes": "",
"pir_respondents": "",
"sys_id": "f25adc501b255a549f2eeb98b04bcb56",
"contact_type": "",
"urgency": "3",
"secure_notes": "",
"company": "",
"new_pir_respondents": "",
"department": "",
"activity_due": "",
"severity": "2",
"comments": "",
"risk_score": "40",
"approval": "not requested",
"due_date": "",
"sys_mod_count": "0",
"parent_security_incident": "",
"sys_tags": "",
"billable": "false",
"mitre_data_source": "",
"caller": "",
"location": "",
"risk": "3",
"category": "",
"incident": "",
"change_request": "",
"security_incident_self": {
"link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
"value": "f25adc501b255a549f2eeb98b04bcb56"
}
}
}
Sample API Response (Incident) (Status Code: 201)
{
"result": {
"parent": "",
"made_sla": "true",
"caused_by": "",
"watch_list": "",
"upon_reject": "cancel",
"sys_updated_on": "2024-10-25 10:44:54",
"child_incidents": "0",
"hold_reason": "",
"origin_table": "",
"task_effective_number": "INC0923990",
"approval_history": "",
"skills": "",
"number": "INC0923990",
"resolved_by": "",
"sys_updated_by": "user1.abc",
"opened_by": {
"link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
"value": "c813b7cb1b8342148f4aedb8b04bcb91"
},
"user_input": "",
"sys_created_on": "2024-10-25 10:44:54",
"sys_domain": {
"link": "https://service-now.com/api/now/table/sys_user_group/global",
"value": "global"
},
"state": "1",
"route_reason": "",
"sys_created_by": "user1.abc",
"knowledge": "false",
"order": "",
"calendar_stc": "",
"x_cdsp_chroni_itsm_chronicle_incident_ref": "",
"closed_at": "",
"cmdb_ci": "",
"delivery_plan": "",
"contract": "",
"impact": "3",
"active": "true",
"work_notes_list": "",
"business_service": "",
"business_impact": "",
"priority": "5",
"sys_domain_path": "/",
"rfc": "",
"time_worked": "",
"expected_start": "",
"opened_at": "2024-10-25 10:44:54",
"business_duration": "",
"group_list": "",
"work_end": "",
"caller_id": "",
"reopened_time": "",
"resolved_at": "",
"approval_set": "",
"subcategory": "",
"work_notes": "",
"universal_request": "",
"short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
"close_code": "",
"correlation_display": "",
"delivery_task": "",
"work_start": "",
"assignment_group": {
"link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
"value": "<group_sys_id>"
},
"additional_assignee_list": "",
"business_stc": "",
"cause": "",
"description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
"origin_id": "",
"calendar_duration": "",
"close_notes": "",
"notify": "1",
"service_offering": "",
"sys_class_name": "incident",
"closed_by": "",
"follow_up": "",
"parent_incident": "",
"sys_id": "d1f994dc1be15a549f2eeb98b04bcb71",
"contact_type": "",
"reopened_by": "",
"incident_state": "1",
"urgency": "3",
"problem_id": "",
"company": "",
"reassignment_count": "0",
"activity_due": "",
"assigned_to": "",
"severity": "3",
"comments": "",
"approval": "not requested",
"sla_due": "",
"comments_and_work_notes": "",
"due_date": "",
"sys_mod_count": "0",
"reopen_count": "0",
"sys_tags": "",
"escalation": "0",
"upon_approval": "proceed",
"correlation_id": "",
"location": "",
"category": "inquiry"
}
}
Sample API Response (GRC Issue) (Status Code: 201)
{
"result": {
"parent": "",
"shadow": "false",
"watch_list": "",
"authority_document": "",
"recommendation": "",
"wbs": "",
"upon_reject": "cancel",
"sys_updated_on": "2024-10-25 10:46:11",
"explanation": "",
"approval_history": "",
"rollup": "false",
"skills": "",
"number": "IPT0020059",
"schedule_start_date": "2024-10-25 10:46:11",
"capex_cost": "0",
"state": "1",
"sys_created_by": "user1.abc",
"knowledge": "false",
"order": "",
"work_duration": "",
"item": "",
"budget_cost": "0",
"cmdb_ci": "",
"dependency": "",
"contract": "",
"impact": "3",
"key_milestone": "false",
"profile": "",
"remaining_effort": "",
"active": "true",
"work_notes_list": "",
"functional_domain": "",
"classification": "",
"priority": "4",
"sys_domain_path": "/",
"version": "",
"business_duration": "",
"group_list": "",
"override_status": "false",
"approval_set": "",
"critical_path": "false",
"status": "green",
"universal_request": "",
"end_date": "2024-10-26 10:46:11",
"short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
"correlation_display": "",
"work_start": "",
"top_task": {
"link": "https://service-now.com/api/now/table/planned_task/444a541847e5161034d5e0d3706d4326",
"value": "444a541847e5161034d5e0d3706d4326"
},
"parent_issue": "",
"time_constraint": "asap",
"document": "",
"additional_assignee_list": "",
"service_offering": "",
"sys_class_name": "sn_grc_issue",
"closed_by": "",
"follow_up": "",
"calculation_type": "automatic",
"confidential_user_groups": "",
"reassignment_count": "0",
"schedule_end_date": "2024-10-26 10:46:11",
"assigned_to": "",
"policy": "",
"start_date": "2024-10-25 10:46:11",
"mpp_task_id": "",
"sub_tree_root": "",
"sla_due": "",
"comments_and_work_notes": "",
"remaining_duration": "",
"has_conflict": "false",
"substate": "",
"allow_dates_outside_schedule": "false",
"escalation": "0",
"upon_approval": "proceed",
"issue_manager": "",
"correlation_id": "",
"group_level": "",
"made_sla": "true",
"user_hierarchy_2": "",
"user_hierarchy_1": "",
"wbs_order": "",
"task_effective_number": "IPT0020059",
"work_effort": "",
"sys_updated_by": "user1.abc",
"opened_by": {
"link": "https://service-now.com/api/now/table/sys_user/dadb5bc43be9d210c71edd6aa5e45a1b",
"value": "dadb5bc43be9d210c71edd6aa5e45a1b"
},
"user_input": "",
"sys_created_on": "2024-10-25 10:46:11",
"sys_domain": {
"link": "https://service-now.com/api/now/table/sys_user_group/global",
"value": "global"
},
"route_reason": "",
"start_date_derived_from": "",
"orig_sys_id": "",
"closed_at": "",
"is_reparenting_group": "false",
"level": "",
"business_service": "",
"confidential_users": "",
"is_confidential": "false",
"relation_applied": "",
"time_worked": "",
"expected_start": "",
"issue_group_rule": "",
"opened_at": "2024-10-25 10:46:11",
"task": "Netskope $appCategory alert name: $alertName, Event Name: $alert_nameIPT0020059",
"work_end": "",
"run_calc_brs": "true",
"work_notes": "",
"work_cost": "0",
"assignment_group": "",
"orig_top_task_id": "",
"user_hierarchy_status": "2",
"software_model": "",
"created_manually": "true",
"description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
"effort": "",
"calendar_duration": "",
"end_date_derived_from": "",
"close_notes": "",
"content": "",
"duration": "1970-01-02 00:00:00",
"issue_manager_group": "",
"sys_id": "444a541847e5161034d5e0d3706d4326",
"contact_type": "",
"urgency": "3",
"constraint_date": "",
"company": "",
"end": "2024-10-25",
"activity_due": "",
"comments": "",
"cost": "0",
"approval": "not requested",
"due_date": "",
"issue_type": "",
"start": "2024-10-25",
"sys_mod_count": "0",
"management_method": "",
"confirmed_date": "",
"model_id": "",
"opex_cost": "0",
"sys_tags": "",
"time_zone": "",
"html_description": "",
"percent_complete": "0",
"is_group": "false",
"milestone": "false",
"issue_source": "44ab97f6c75200107e299e0703c2602a",
"action_plan": "",
"response": "",
"issue_rating": "",
"location": ""
}
}
Get Incident or Security Incidents or GRC Issues or Custom Table Record
API Endpoint: <Instance URL>/api/now/table/<table>
Method: GET
Path Parameters
| Key | Value |
|---|---|
| table | incident sn_si_incident sn_grc_issue custom_table_name |
Parameters
| Key | Value |
|---|---|
| sysparm_fields | sys_id,state,severity,assigned_to |
| sysparm_query | sys_idIN<incident_sys_id> |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Sample API Response (Status Code: 200)
{
"result": [
{
"severity": "2",
"sys_id": "f25adc501b255a549f2eeb98b04bcb56",
"state": "10",
"assigned_to": {
"link": "https://<Instance URL>/api/now/table/sys_user/324sndm",
"value": "324sndm"
}
}
]
}
Sample API Response (GRC Issue) (Status Code: 200)
{
"result": [
{
"sys_id": "444a541847e5161034d5e0d3706d4326",
"impact": "3",
"state": "1",
"assigned_to": ""
}
]
}
Update Incident or Security Incident or GRC Issue or Custom Table record
API Endpoint: <Instance URL>/api/now/table/<table>
Method: PATCH
Path Parameters
| Key | Value |
|---|---|
| table | incident sn_si_incident sn_grc_issue custom_table_name |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Body
{
"work_notes": "Received new alert with Alert ID: $id and Alert Name: $alertName in Cloud Exchange."
}
Sample API Response (Status Code: 200)
{
"result": {
"parent": "",
"sla_suspended_reason": "",
"watch_list": "",
"upon_reject": "cancel",
"sys_updated_on": "2024-10-25 11:56:25",
"qualification_group": "",
"expected_end": "",
"enforce_restriction": "false",
"approval_history": "",
"source_ip": "",
"skills": "",
"number": "SIR1083059",
"problem": "",
"previous_agent": "",
"state": "10",
"sys_created_by": "user1.abc",
"template_workflow_invoked": "false",
"knowledge": "false",
"order": "",
"phish_email": "",
"cmdb_ci": "",
"delivery_plan": "",
"contract": "",
"impact": "3",
"active": "true",
"work_notes_list": "",
"vulnerability": "",
"priority": "4",
"sys_domain_path": "/",
"sla_suspended": "false",
"business_duration": "",
"group_list": "",
"special_access_write": "",
"dest_ip": "",
"mitre_platform": "",
"approval_set": "",
"risk_change": "up",
"malware_url": "",
"universal_request": "",
"last_updated_from_src": "automation",
"template": "",
"short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
"correlation_display": "",
"delivery_task": "",
"work_start": "",
"request_type": "",
"affected_user": "",
"other_ioc": "",
"additional_assignee_list": "",
"alert_sensor": "",
"assigned_vendor": "",
"service_offering": "",
"sys_class_name": "sn_si_incident",
"closed_by": "",
"follow_up": "",
"mitre_group": "",
"sla_suspended_on": "",
"estimated_end": "",
"vendor_reference": "",
"reassignment_count": "0",
"assigned_to": "",
"request_category": "",
"requested_due_by": "",
"mitre_malware": "",
"sla_suspended_for": "",
"business_criticality": "3",
"sla_due": "",
"opened_for": {
"link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
"value": "c813b7cb1b8342148f4aedb8b04bcb91"
},
"comments_and_work_notes": "",
"mitre_technique": "",
"special_access_read": "",
"substate": "",
"escalation": "0",
"upon_approval": "proceed",
"allowed_groups": "",
"correlation_id": "",
"asset": "",
"mitre_tool": "",
"spam": "false",
"referrer_url": "",
"made_sla": "true",
"mitre_tactic": "",
"is_catalog": "false",
"malware_hash": "",
"alert_rule": "",
"task_effective_number": "SIR1083059",
"external_url": "",
"sys_updated_by": "user1.abc",
"opened_by": {
"link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
"value": "c813b7cb1b8342148f4aedb8b04bcb91"
},
"user_input": "",
"sys_created_on": "2024-10-25 10:46:39",
"sys_domain": {
"link": "https://service-now.com/api/now/table/sys_user_group/global",
"value": "global"
},
"pir": "",
"route_reason": "",
"closed_at": "",
"allowed_members": "",
"business_service": "",
"attack_vector": "",
"time_worked": "",
"expected_start": "",
"opened_at": "2024-10-25 10:46:39",
"task_created": "false",
"x_cdsp_chroni_sir_chronicle_si": "",
"work_end": "",
"confidence_score": "",
"prediction": "",
"automation_activity": "",
"subcategory": "",
"work_notes": "",
"security_tags": "",
"risk_score_override": "false",
"initiated_from": "",
"close_code": "",
"assignment_group": {
"link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
"value": "<group_sys_id>"
},
"description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
"calendar_duration": "",
"close_notes": "",
"pir_respondents": "",
"sys_id": "f25adc501b255a549f2eeb98b04bcb56",
"contact_type": "",
"urgency": "3",
"secure_notes": "",
"company": "",
"new_pir_respondents": "",
"department": "",
"activity_due": "",
"severity": "2",
"comments": "",
"risk_score": "40",
"approval": "not requested",
"due_date": "",
"sys_mod_count": "2",
"parent_security_incident": "",
"sys_tags": "",
"billable": "false",
"mitre_data_source": "",
"caller": "",
"location": "",
"risk": "3",
"category": "",
"incident": "",
"change_request": "",
"security_incident_self": {
"link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
"value": "f25adc501b255a549f2eeb98b04bcb56"
}
}
}
Fetch Assignee Users
API Endpoint: <Instance URL>/api/now/table/sys_user
Method: GET
Parameters
| Key | Value |
|---|---|
| sysparm_query | sys_id,user_name |
| sysparm_fields | sys_idIN<user_sys_id> |
Headers
| Key | Value |
|---|---|
| User-Agent | netskope-ce-6.0.0-cto-servicenow-v2.2.0 |
| Authorization | Basic <username:password> |
Sample API Response (Status Code: 200)
{
"result": [
{
"sys_id": "800b174138d089c868d09de320f9833b",
"user_name": "user.abc"
}
]
}
Performance Matrix
These readings are collected on a Large CE Stack with these specifications.
Performed performance for Custom table on ServiceNow instance.
| Description | Specification |
|---|---|
| Stack details | Size: Large
RAM: 32 GB CPU: 16 Cores |
| Tickets Created Per Minute | ~ 160 Incidents/min |
User Agent
netskope-ce-6.0.0-cto-servicenow-v2.2.0
Workflow
- Create a new user in ServiceNow
- Assign a role to the user
- Configure the ServiceNow plugin
- Add a Business Rule for ServiceNow.
- Add a Queue for ServiceNow.
- Validate the plugin.
Watch a video
Click play to watch a video.
Create a New User
- Log in to ServiceNow.
- Go to System Security > Users and Groups > Users.
- Click New.

- Enter the required information and make a copy of the User ID. Click Submit.
- On the Users page, search for your user ID and click on your user (like shown below).

- Click Set Password.

- Click Generate. Copy the password, and then click Save Password and Close.

Assign Role to the User
- Scroll down to Roles and click Edit.

- Add roles per your requirements:
Roles required when Incidents is configured in the Destination Table parameter:- itil or sn_incident_write, sn_incident_read
personalize_dictionary
- sn_si.admin
- sn_grc.business_user (Users can only view issues that they have created themselves or have been assigned to them) admin (This permission is necessary to view all GRC Issues, regardless of creator or assignee)
- admin
- itil or sn_incident_write, sn_incident_read
- Click Save.

Note
Admin permission is only required for accessing all GRC issues irrespective of its creator and assignee.
- Click Update.

Configure the ServiceNow Plugin
- In Cloud Exchange, go to Settings > Plugin Store. Search for and select ServiceNow v2.2.0 (CTO) plugin box.

- Provide a Configuration Name and change the Sync Interval per your requirement.

- Click Next and enter the Authentication Parameters:
- Instance URL: ServiceNow Instance URL.
- Username: Instance username.
- Password: Instance password.
- Destination Table: Name of the table where incidents will be created.

- Enter the Configuration Parameters. For Custom Table, map these fields as per your requirement.
- Custom Table Name: Provide name of your custom table.
- Custom Status: Status field Column name of your custom table.
- Custom Severity: Severity field Column name of your custom table.
- Custom Assignee: Assignee field Column name of your custom table if it reference to the ‘sys_user_’ table of the ServiceNow.
- Custom Group: Group field Column name of your custom table if it reference to the ‘sys_user_group’ table of the ServiceNow.
- Custom Update: Update field Column name of your custom table. This field will be used to add a message when the dedup rule is executed.

Note
No fields will be mapped by default for the custom table in the Queue Configuration. However, if you specify the Custom Update field, a default mapping for Deduplication Map Fields will be provided during queue creation.
- Use Default Mappings: Select Yes for the No Queue option (No Queue uses default mappings for the queue, and does not require elevated access) on the Queue configuration page; otherwise, select No.
- Yes: These default mappings will be used for the No Queue option.
Target Fields Values Short Description Netskope $appCategory alert name: $alertName
Event Name: $alert_nameDescription Alert/Event ID: $id
Alert/Event App: $appAlert/Event
User: $userAlert
Name: $alertName
Alert Type: $alertType
Alert App Category: $appCategory
Event Name: $alert_name
Event Type: $eventType - No: You can create custom mappings.
- Yes: These default mappings will be used for the No Queue option.
- Select the mapping configuration from the following fields.
Following is the default mapping for status and severity mappings: To create a custom status, click Add at the bottom of the page.

Click Add New to create a Cloud Exchange field.
Provide the field name and click Add Field. Map it to the the status of your choice.


- Click Save.

Add a Ticket Orchestrator Business Rule for ServiceNow
Create a business rule based on the filters you need to create incidents in the ServiceNow plugin.
- In Ticket Orchestrator, got to Business Rules and click Create New Rule.
- Enter a Rule Name and build the appropriate filter query condition on the field(s) for the business rule. You can also enter the query manually by clicking Filter Query.
- Click Save.

Add a Ticket Orchestrator Queue for ServiceNow
- In Ticket Orchestrator, go to Queues and click Add Queue Configuration.
- Select the Business Rule, plugin Configuration, and Queue from the dropdowns.


Note
Target fields for Map Fields section will be fetched from the ServiceNow instance based on the destination table selected during the plugin configuration.
- Click Save and sync the queue if you already have the alerts/events pulled.

Validate the ServiceNow Plugin
Validate in Cloud Exchange
In order to validate the workflow, you must already have Netskope Alerts/Events.
- To view the list of tickets created on ServiceNow, go to Tickets in Ticket Orchestrator.

Note
Any status that is not mapped with corresponding Cloud Exchange fields will not sync the status of the ticket.
- Verify Ticket creation/sync by going to Logging.


Validate in ServiceNow
To validate the incident creation, go to Tickets in Ticket Orchestrator, and open on External Link of Ticket
Make sure you are logged in to ServiceNow.
Security Incident Ticket:

Incident Ticket:

GRC Issues Ticket:

Custom Table Ticket:

Troubleshooting the ServiceNow Plugin
Unable to update Destination table to Custom table during the plugin upgrade
When upgrading the plugin from old version to v2.1.0, you might encounter this error if you select the Custom Table in the Destination Table field:
CTO ServiceNow [CTO ServiceNow]: Validation error occurred. Custom Table Name is required Configuration Parameter.
What to do: You need to use the Skip button, then edit the plugin configuration from the plugins page to use the Custom table.
Unable to configure the CTO ServiceNow plugin
If you are unable to configure the ServiceNow plugin, it could be due to one of these reasons:
- Incorrect credentials provided.
- User does not have required permissions.
- Incorrect instance URL provided.
What to do:
- Make sure to provide the correct credentials. Follow the steps, to create a user.
- Make sure that the user has the required permissions. Follow the steps, to provide a role to the user.
- Make sure that the correct instance URL is provided.
Unable to create an Incident using the plugin
If you are unable to create an Incident in the plugin, it could be due to one of these reasons:
- No alerts or events are available in Cloud Exchange, or no new alerts or events are pulled.
- Business Rule has no alerts/events filtered.
- The user does not have a required role for creating incidents.
What to do: Find the root cause and select the best fit resolution.
- Check if the alerts/events are available in the Alerts/Events page, if no alerts/events are available the ticket won’t be created. Configure Tenant or other required configuration to create alerts/events in Ticket Orchestrator.
- Check the business rule and test it to confirm if it has any alerts filtered. If no alerts are available in the filtering, update the business rule.

- Ensure users have required roles. Follow the steps, to provide a role to the user.
Known Behavior
We have observed that in the Incidents table, when an incident is created and the Assignee field is mapped in the Queue mapping, the incident is automatically assigned the In Progress state, even when the incident event retrieved from the Netskope Tenant has a status of New.

