Netskope LogoNetskope Logo
  • セキュリティサービス
  • AIサービス
  • ネットワークサービス
  • 分析サービス
  • 統合
  • getting-started.svg始める
    • サポート
    • コミュニティ
    • Netskope.com
    © 2026 無断転載を禁じます。Netskope 株式会社
    トップページ
    Netskope Cloud Exchange
    チケットオーケストレーターモジュール
    サードパーティ製チケットオーケストレータープラグインの設定
    ServiceNow 用 Ticket Orchestrator プラグイン

    ServiceNow 用 Ticket Orchestrator プラグイン

    このドキュメントでは、ServiceNow v2.2.0 プラグインを Netskope Cloud Exchange プラットフォームの Ticket Orchestrator モジュールと連携させる方法について説明します。このプラグインは、ServiceNow プラットフォームの[インシデント > すべて]ページでインシデントを作成し、 [セキュリティ インシデント] > [インシデント] > [すべてのインシデントを表示]ページでセキュリティ インシデントを作成し、 [ポリシーとコンプライアンス] > [問題] > [すべての問題]ページで GRC 問題を作成し、ServiceNow プラットフォームのカスタム テーブルレコード ページでレコードを作成するために使用します。 また、インシデント/問題の更新やステータスの同期もサポートしています。このプラグインは、ServiceNowのDLPインシデントレスポンス製品とは異なり、また、そのソリューションとは連携しません。

    前提条件

    この設定を完了するには、以下が必要です。

    • Netskopeテナント(または、例えば本番環境と開発/テスト環境など、複数のテナント)。
    • Netskope Cloud Exchangeテナントには、テナントプラグインとチケットオーケストレータープラグインが既に設定済みです。
    • ServiceNowアカウント。
    • プラグインに必要な権限は、 itilまたはsn_incident_write 、 sn_incident_read 、 personalize_dictionary 、sn_si.admin,、 admin sn_grc.business_user, 。
    • 以下のホストへの接続: https://<instance>.service-now.com/ 
    • GRC課題を作成するには、ServiceNowインスタンスにGRC:ポリシーおよびコンプライアンス管理(アプリID: sn_compliance)プラグインをインストールする必要があります。
    ServiceNowプラグインのサポート

    このプラグインは ServiceNow のインシデント、セキュリティインシデント、GRC 課題、およびカスタムテーブルレコードにインシデントを作成するためのものです。

    チケットでサポートされているアラートの種類チケットでサポートされているイベントの種類
    侵害されたクレデンシャル、ポリシー、マルサイト、マルウェア、DLP、セキュリティ評価、ウォッチリスト、検疫、修復、UBA、CTEP、デバイス、コンテンツエンドポイント、インシデント
    マッピング
    キューマッピング
    対象分野Values
    ショートデスクリプションNetskope $appCategory アラート名: $alertName
    イベント名: $alert_name
    デスクリプションアラート/イベントID: $id

    アラート/イベントアプリ: $appAlert/Event ユーザー: $userAlert 名前: $alertNameAlert タイプ: $alertTypeAlert アプリカテゴリ: $appCategoryEvent 名前: $alert_nameEvent タイプ: $eventType

    Default Status Mappings

    このマッピングは、 Netskope CE ステータスを ServiceNow ステータスにマッピングするために使用されます。 利用可能な ServiceNow ステータスは、[システム定義] > [テーブル] > [テーブル名] > [ステータス列名] > [選択肢]に移動することで確認できます。

    Cloud ExchangeステータスValueServiceNowのステータス
    新しい1新しい
    進行中2進行中
    保留中3保留中
    Closed7Closed
    Deleted–(デフォルトは空白になります)
    ServiceNow でカスタム フィールドを作成してマッピングできます。
    その他–(Default will be blank)
    Default Severity Mappings

    このマッピングはNetskope CEの重要度をServiceNowの重要度にマッピングするためのものです。 利用可能な ServiceNow の重要度値は、[システム定義] > [テーブル] > [テーブル名] > [重要度列名] > [選択肢]に移動することで確認できます。

    Cloud Exchange重要度ValueServiceNowの重要度
    致命的–(Default will be blank)

    ServiceNowでは、マッピング用のカスタムフィールドを作成できます。

    高い1高い
    中くらい2中くらい
    低い3低い
    情報提供–(Default will be blank)

    ServiceNowでは、マッピング用のカスタムフィールドを作成できます。

    その他–(Default will be blank)

    注記

    ServiceNowプラグインにおけるデフォルトのステータスと重要度のマッピングは、プラットフォーム内でこれらのフィールドをカスタマイズできるため、異なる場合があります。対応する Netskope CE フィールドにマッピングされていないステータスまたは重大度は、その他としてマークされます。

    デフォルトテーブルのキュー構成でサポートされるフィールド

    ServiceNowでインシデントを作成する際にマッピングできる、デフォルトテーブルのキュー構成でサポートされているフィールドの一覧を以下に示します。

    セキュリティインシデント
    フィールド名フィールドタイプ
    Malware hashString
    MITRE ATT&CK Procedure (Malware)String
    最終更新日(ソースから)Choice
    NumberString
    Platforms(MITRE)String
    保護者のセキュリティインシデントReference
    影響を受けるユーザーReference
    アラートルールString
    新しい回答者Glide_list
    マシンラーニングの予測String
    宛先IPアドレスString
    ProblemReference
    サービスReference
    実効数String
    サービス内容Reference
    拒否 gotoReference
    Malware URLString
    割り当てられたReference
    EscalationInteger
    勤務時間Timer
    追加譲受人リストGlide_list
    相関IDString
    MITRE ATT&CK TacticString
    Phish 電子メールReference
    VariablesVariables
    アラートセンサーReference
    追加コメントJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    ウォッチリストGlide_list
    SLA dueDue_date
    ContractReference
    アクティブBoolean
    州Integer
    作業メモJournal_input
    閉鎖Reference
    フォローアップGlide_date_time
    構成アイテムReference
    承認履歴Journal
    営業期間Glide_duration
    LocationReference
    ユーザー入力User_input
    送信元IPアドレスString
    変更依頼Reference
    RiskInteger
    ワークフロー活動Reference
    リスクの変化String
    MITRE ATT&CK Data SourceString
    作業メモ一覧Glide_list
    SkillsGlide_list
    攻撃ベクトルGlide_list
    MITRE ATT&CK TechniqueString
    許可されたグループGlide_list
    自動化活動Journal
    ビジネスへの影響Integer
    閉じるコードString
    読む アクセスGlide_list
    特権アクセスGlide_list
    リスクスコアInteger
    セキュリティタグGlide_list
    重大度Integer
    セキュリティインシデント自己診断Reference
    IncidentReference
    コメントと作業メモJournal_list
    MITRE ATT&CK Adversary GroupString
    デスクリプションString
    ImpactInteger
    ClosedGlide_date_time
    グループ一覧Glide_list
    Activity dueDue_date
    MITRE ATT&CK Procedure (Tool)String
    評価を依頼するGlide_list
    許可されたメンバーGlide_list
    ParentReference
    優先度Integer
    最後のメモString
    再割り当て数Integer
    Due dateGlide_date_time
    OrderInteger
    ショートデスクリプションString
    CompanyReference
    承認セットGlide_date_time
    オープンしたReference
    コンタクトタイプString
    SLA製Boolean
    ポストインシデントレポートHtml
    割り当てグループReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    相関表示String
    その他のIoCString
    参照元URLString
    信頼度スコアDecimal
    DepartmentGlide_list
    VulnerabilityReference
    配達業務Reference
    Actual endGlide_date_time
    ユニバーサルリクエストReference
    始めるGlide_date_time
    Actual startGlide_date_time
    承認後String
    転居理由Integer
    制限を強制するBoolean
    外部URLUrl
    配送計画Reference
    拒否された場合String
    リスクスコアを上書きするBoolean
    Incident
    フィールド名フィールドタイプ
    ビジネスへの影響String
    推定原因String
    再開カウントInteger
    NumberString
    親の事件Reference
    サービスReference
    変更依頼Reference
    実効数String
    サービス内容Reference
    インシデント状態Integer
    解決時間Integer
    拒否 gotoReference
    元のテーブルTable_name
    解決済みReference
    クロニクル事件Reference
    割り当てられたReference
    EscalationInteger
    勤務時間Timer
    追加譲受人リストGlide_list
    相関IDString
    VariablesVariables
    子どもの事件Integer
    追加コメントJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    ウォッチリストGlide_list
    SLA dueDue_date
    ContractReference
    アクティブBoolean
    州Integer
    作業メモJournal_input
    閉鎖Reference
    フォローアップGlide_date_time
    構成アイテムReference
    承認履歴Journal
    営業期間Glide_duration
    LocationReference
    ユーザー入力User_input
    カテゴリString
    ビジネス解決時間Integer
    OriginDocument_id
    ワークフロー活動Reference
    変化によって引き起こされるReference
    作業メモ一覧Glide_list
    閉じるコードString
    SkillsGlide_list
    ResolvedGlide_date_time
    Splunk URLUrl
    最後に再開したのはGlide_date_time
    ProblemReference
    CallerReference
    SubcategoryString
    コメントと作業メモJournal_list
    デスクリプションString
    ImpactInteger
    ClosedGlide_date_time
    グループ一覧Glide_list
    Activity dueDue_date
    ParentReference
    優先度Integer
    最後のメモString
    再割り当て数Integer
    Due dateGlide_date_time
    OrderInteger
    ショートデスクリプションString
    CompanyReference
    承認セットGlide_date_time
    オープンしたReference
    コンタクトタイプString
    SLA製Boolean
    保留理由Integer
    割り当てグループReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    相関表示String
    配達業務Reference
    Actual endGlide_date_time
    ユニバーサルリクエストReference
    始めるGlide_date_time
    NotifyInteger
    Actual startGlide_date_time
    承認後String
    重大度Integer
    転居理由Integer
    配送計画Reference
    拒否された場合String
    最終再開日Reference
    GRCに関する課題
    フィールド名フィールドタイプ
    再養育グループはBoolean
    権限文書Reference
    アイテムReference
    課題管理者Reference
    問題評価Reference
    管理方法String
    DocumentReference
    ExplanationString
    RecommendationString
    行動計画Html
    SubstateString
    親の問題Reference
    管理目標/リスク記述書Reference
    EntityReference
    機能領域Glide_list
    ユーザー階層ステータスString
    グループBoolean
    問題グループ規則Reference
    課題管理者グループReference
    分類String
    許可されたグループGlide_list
    問題の発生源Glide_list
    ユーザー階層2Reference
    ユーザー階層 1Reference
    ポリシーReference
    ConfidentialBoolean
    ResponseInteger
    確定日Glide_date_time
    問題の種類String
    許可されたユーザーGlide_list
    手動で作成Boolean
    グループレベルString
    Actual endGlide_date_time
    CompanyReference
    NumberString
    ImpactInteger
    ショートデスクリプションString
    承認セットGlide_date_time
    デスクリプションString
    ClosedGlide_date_time
    オープンしたReference
    SLA製Boolean
    グループ一覧Glide_list
    コンタクトタイプString
    Activity dueDue_date
    ワークフロー活動Reference
    拒否 gotoReference
    拒否された場合String
    ContractReference
    EscalationInteger
    実効数String
    アクティブBoolean
    作業メモJournal_input
    割り当てられたReference
    勤務時間Timer
    ビジネスサービスReference
    州Integer
    追加譲受人リストGlide_list
    フォローアップGlide_date_time
    相関IDString
    作業メモ一覧Glide_list
    ユニバーサルリクエストReference
    閉鎖Reference
    配送計画Reference
    承認後String
    ParentReference
    最後のメモString
    割り当てグループReference
    DurationGlide_duration
    優先度Integer
    ApprovalString
    Due dateGlide_date_time
    相関表示String
    再割り当て数Integer
    OrderInteger
    KnowledgeBoolean
    サービス内容Reference
    配達業務Reference
    構成アイテムReference
    コメントと作業メモJournal_list
    UrgencyInteger
    承認履歴Journal
    追加コメントJournal_input
    OpenedGlide_date_time
    営業期間Glide_duration
    ユーザー入力User_input
    VariablesVariables
    ウォッチリストGlide_list
    LocationReference
    SLA dueDue_date
    Actual startGlide_date_time
    始めるGlide_date_time
    転居理由Integer
    SkillsGlide_list
    権限
    • ワークフローのURLにデータを送信する権限。
      • 宛先テーブルパラメータでインシデントが構成されている場合に必要となる役割:
        • itil or sn_incident_write, sn_incident_read
        • personalize_dictionary
      • セキュリティインシデントが宛先テーブルパラメータで構成されている場合に必須となる役割:
        • sn_si.admin
      • 宛先テーブルパラメータでGRC課題を設定する際に必要なロール:
        • sn_grc.business_user (ユーザーは、自身が作成した課題、または自身に割り当てられた課題のみを表示できます)
        • 管理者(この権限は、作成者や担当者に関係なく、すべてのGRC課題を表示するために必要です)
      • 宛先テーブルパラメータでカスタムテーブルを設定する場合に必須となる役割:
        • admin
    APIの詳細

    List of APIs used

    APIエンドポイント方法使うケース
    /api/now/table/sys _辞書得るインシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルフィールドを取得します。
    /api/now/table/sys _ユーザーグループ得るServiceNowグループをキューとして取得する
    /api/now/table/<table>役職インシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルレコードを作成します。
    /api/now/table/<table>得るインシデント、セキュリティインシデント、GRC問題、またはカスタムテーブルレコードを取得します
    /api/now/table/ <table>/<incident_id>パッチインシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルレコードの更新
    /api/now/table/sys _ユーザー得る担当者ユーザーの取得

    Get Incident or Security Incident or GRC Issue or Custom Table Fields

    API Endpoint: <Instance URL>/api/今/table/sys_dictionary

    Method: 得る

    Parameters

    鍵Value
    sysparm_queryname=<table_name>^ORname=task^internal_type!=collection カスタムテーブルの場合: name=<custom_table_name>
    sysparm_fields列ラベル、要素
    sysparm_limit1000
    sysparm_offset0

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Sample API Response (Security Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Malware hash",
                "element": "malware_hash"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Malware)",
                "element": "mitre_malware"
            },
            {
                "column_label": "Last Updated From Source",
                "element": "last_updated_from_src"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Platforms(MITRE)",
                "element": "mitre_platform"
            },
            {
                "column_label": "Parent security incident",
                "element": "parent_security_incident"
            },
            {
                "column_label": "Affected user",
                "element": "affected_user"
            },
            {
                "column_label": "Alert Rule",
                "element": "alert_rule"
            },
            {
                "column_label": "New respondents",
                "element": "new_pir_respondents"
            },
            {
                "column_label": "Machine learning Prediction",
                "element": "prediction"
            },
            {
                "column_label": "Destination IP",
                "element": "dest_ip"
            },
            {
                "column_label": "Problem",
                "element": "problem"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Malware URL",
                "element": "malware_url"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "MITRE ATT&CK Tactic",
                "element": "mitre_tactic"
            },
            {
                "column_label": "Phish Email",
                "element": "phish_email"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Alert Sensor",
                "element": "alert_sensor"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Source IP",
                "element": "source_ip"
            },
            {
                "column_label": "Change request",
                "element": "change_request"
            },
            {
                "column_label": "Risk",
                "element": "risk"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Risk change",
                "element": "risk_change"
            },
            {
                "column_label": "MITRE ATT&CK Data Source",
                "element": "mitre_data_source"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Attack Vector",
                "element": "attack_vector"
            },
            {
                "column_label": "MITRE ATT&CK Technique",
                "element": "mitre_technique"
            },
            {
                "column_label": "Allowed groups",
                "element": "allowed_groups"
            },
            {
                "column_label": "Automation activity",
                "element": "automation_activity"
            },
            {
                "column_label": "Business impact",
                "element": "business_criticality"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Read access",
                "element": "special_access_read"
            },
            {
                "column_label": "Privileged access",
                "element": "special_access_write"
            },
            {
                "column_label": "Risk score",
                "element": "risk_score"
            },
            {
                "column_label": "Security tags",
                "element": "security_tags"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Security incident self",
                "element": "security_incident_self"
            },
            {
                "column_label": "Incident",
                "element": "incident"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "MITRE ATT&CK Adversary Group",
                "element": "mitre_group"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Tool)",
                "element": "mitre_tool"
            },
            {
                "column_label": "Request assessments",
                "element": "pir_respondents"
            },
            {
                "column_label": "Allowed members",
                "element": "allowed_members"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Post incident report",
                "element": "pir"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Other IoC",
                "element": "other_ioc"
            },
            {
                "column_label": "Referrer URL",
                "element": "referrer_url"
            },
            {
                "column_label": "Confidence score",
                "element": "confidence_score"
            },
            {
                "column_label": "Department",
                "element": "department"
            },
            {
                "column_label": "Vulnerability",
                "element": "vulnerability"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Enforce restriction",
                "element": "enforce_restriction"
            },
            {
                "column_label": "External URL",
                "element": "external_url"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Override risk score",
                "element": "risk_score_override"
            }
        ]
    }
    

    Sample API Response (Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Business impact",
                "element": "business_impact"
            },
            {
                "column_label": "Probable cause",
                "element": "cause"
            },
            {
                "column_label": "Reopen count",
                "element": "reopen_count"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Parent Incident",
                "element": "parent_incident"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Change Request",
                "element": "rfc"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Incident state",
                "element": "incident_state"
            },
            {
                "column_label": "Resolve time",
                "element": "calendar_stc"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Origin table",
                "element": "origin_table"
            },
            {
                "column_label": "Resolved by",
                "element": "resolved_by"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Child Incidents",
                "element": "child_incidents"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Category",
                "element": "category"
            },
            {
                "column_label": "Chronicle Incident",
                "element": "x_cdsp_chroni_itsm_chronicle_incident_ref"
            },
            {
                "column_label": "Business resolve time",
                "element": "business_stc"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Origin",
                "element": "origin_id"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Caused by Change",
                "element": "caused_by"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Resolved",
                "element": "resolved_at"
            },
            {
                "column_label": "Splunk URL",
                "element": "x_splu2_splunk_ser_splunk_url"
            },
            {
                "column_label": "Last reopened at",
                "element": "reopened_time"
            },
            {
                "column_label": "Problem",
                "element": "problem_id"
            },
            {
                "column_label": "Caller",
                "element": "caller_id"
            },
            {
                "column_label": "Subcategory",
                "element": "subcategory"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "On hold reason",
                "element": "hold_reason"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Notify",
                "element": "notify"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Last reopened by",
                "element": "reopened_by"
            }
        ]
    }
    

    Sample API Response (GRC Issues) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Is reparenting group",
                "element": "is_reparenting_group"
            },
            {
                "column_label": "Authority document",
                "element": "authority_document"
            },
            {
                "column_label": "Item",
                "element": "item"
            },
            {
                "column_label": "Issue manager",
                "element": "issue_manager"
            },
            {
                "column_label": "Issue rating",
                "element": "issue_rating"
            },
            {
                "column_label": "Management method",
                "element": "management_method"
            },
            {
                "column_label": "Document",
                "element": "document"
            },
            {
                "column_label": "Explanation",
                "element": "explanation"
            },
            {
                "column_label": "Recommendation",
                "element": "recommendation"
            },
            {
                "column_label": "Action plan",
                "element": "action_plan"
            },
            {
                "column_label": "Substate",
                "element": "substate"
            },
            {
                "column_label": "Parent issue",
                "element": "parent_issue"
            },
            {
                "column_label": "Control objective/Risk statement",
                "element": "content"
            },
            {
                "column_label": "Entity",
                "element": "profile"
            },
            {
                "column_label": "Functional domain",
                "element": "functional_domain"
            },
            {
                "column_label": "User hierarchy status",
                "element": "user_hierarchy_status"
            },
            {
                "column_label": "Is group",
                "element": "is_group"
            },
            {
                "column_label": "Issue group rule",
                "element": "issue_group_rule"
            },
            {
                "column_label": "Issue manager group",
                "element": "issue_manager_group"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Classification",
                "element": "classification"
            },
            {
                "column_label": "Allowed groups",
                "element": "confidential_user_groups"
            },
            {
                "column_label": "Issue source",
                "element": "issue_source"
            },
            {
                "column_label": "User hierarchy 2",
                "element": "user_hierarchy_2"
            },
            {
                "column_label": "User hierarchy 1",
                "element": "user_hierarchy_1"
            },
            {
                "column_label": "Policy",
                "element": "policy"
            },
            {
                "column_label": "Confidential",
                "element": "is_confidential"
            },
            {
                "column_label": "Response",
                "element": "response"
            },
            {
                "column_label": "Confirmed date",
                "element": "confirmed_date"
            },
            {
                "column_label": "Issue type",
                "element": "issue_type"
            },
            {
                "column_label": "Allowed users",
                "element": "confidential_users"
            },
            {
                "column_label": "Created manually",
                "element": "created_manually"
            },
            {
                "column_label": "Group level",
                "element": "group_level"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Business service",
                "element": "business_service"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            }
        ]
    }
    


    Get ServiceNow groups as Queue

    API Endpoint: <Instance URL>/api/今/table/sys_user_group

    Method: 得る

    Parameters

    鍵Value
    sysparm_fields名前、sys_id
    sysparm_limit1000
    sysparm_offset0

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Sample API Response (Status Code: 200)

    
    { "result": [ { "sys_id": "01336b6347332100158b949b6c9a71b5", "name": "Finance Vendors" }, …. ] }
    

    Create Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/今/table/<table>

    Method: 役職

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Body

    
    {
        "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
        "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
        "assignment_group": "<group_sys_id>"
    }
    

    Sample API Response (Security Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:39",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "0",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    

    Sample API Response (Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "made_sla": "true",
            "caused_by": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:44:54",
            "child_incidents": "0",
            "hold_reason": "",
            "origin_table": "",
            "task_effective_number": "INC0923990",
            "approval_history": "",
            "skills": "",
            "number": "INC0923990",
            "resolved_by": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:44:54",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "state": "1",
            "route_reason": "",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "calendar_stc": "",
            "x_cdsp_chroni_itsm_chronicle_incident_ref": "",
            "closed_at": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "business_service": "",
            "business_impact": "",
            "priority": "5",
            "sys_domain_path": "/",
            "rfc": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:44:54",
            "business_duration": "",
            "group_list": "",
            "work_end": "",
            "caller_id": "",
            "reopened_time": "",
            "resolved_at": "",
            "approval_set": "",
            "subcategory": "",
            "work_notes": "",
            "universal_request": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "close_code": "",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "additional_assignee_list": "",
            "business_stc": "",
            "cause": "",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "origin_id": "",
            "calendar_duration": "",
            "close_notes": "",
            "notify": "1",
            "service_offering": "",
            "sys_class_name": "incident",
            "closed_by": "",
            "follow_up": "",
            "parent_incident": "",
            "sys_id": "d1f994dc1be15a549f2eeb98b04bcb71",
            "contact_type": "",
            "reopened_by": "",
            "incident_state": "1",
            "urgency": "3",
            "problem_id": "",
            "company": "",
            "reassignment_count": "0",
            "activity_due": "",
            "assigned_to": "",
            "severity": "3",
            "comments": "",
            "approval": "not requested",
            "sla_due": "",
            "comments_and_work_notes": "",
            "due_date": "",
            "sys_mod_count": "0",
            "reopen_count": "0",
            "sys_tags": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "correlation_id": "",
            "location": "",
            "category": "inquiry"
        }
    }
    

    Sample API Response (GRC Issue) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "shadow": "false",
            "watch_list": "",
            "authority_document": "",
            "recommendation": "",
            "wbs": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:11",
            "explanation": "",
            "approval_history": "",
            "rollup": "false",
            "skills": "",
            "number": "IPT0020059",
            "schedule_start_date": "2024-10-25 10:46:11",
            "capex_cost": "0",
            "state": "1",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "work_duration": "",
            "item": "",
            "budget_cost": "0",
            "cmdb_ci": "",
            "dependency": "",
            "contract": "",
            "impact": "3",
            "key_milestone": "false",
            "profile": "",
            "remaining_effort": "",
            "active": "true",
            "work_notes_list": "",
            "functional_domain": "",
            "classification": "",
            "priority": "4",
            "sys_domain_path": "/",
            "version": "",
            "business_duration": "",
            "group_list": "",
            "override_status": "false",
            "approval_set": "",
            "critical_path": "false",
            "status": "green",
            "universal_request": "",
            "end_date": "2024-10-26 10:46:11",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "work_start": "",
            "top_task": {
                "link": "https://service-now.com/api/now/table/planned_task/444a541847e5161034d5e0d3706d4326",
                "value": "444a541847e5161034d5e0d3706d4326"
            },
            "parent_issue": "",
            "time_constraint": "asap",
            "document": "",
            "additional_assignee_list": "",
            "service_offering": "",
            "sys_class_name": "sn_grc_issue",
            "closed_by": "",
            "follow_up": "",
            "calculation_type": "automatic",
            "confidential_user_groups": "",
            "reassignment_count": "0",
            "schedule_end_date": "2024-10-26 10:46:11",
            "assigned_to": "",
            "policy": "",
            "start_date": "2024-10-25 10:46:11",
            "mpp_task_id": "",
            "sub_tree_root": "",
            "sla_due": "",
            "comments_and_work_notes": "",
            "remaining_duration": "",
            "has_conflict": "false",
            "substate": "",
            "allow_dates_outside_schedule": "false",
            "escalation": "0",
            "upon_approval": "proceed",
            "issue_manager": "",
            "correlation_id": "",
            "group_level": "",
            "made_sla": "true",
            "user_hierarchy_2": "",
            "user_hierarchy_1": "",
            "wbs_order": "",
            "task_effective_number": "IPT0020059",
            "work_effort": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/dadb5bc43be9d210c71edd6aa5e45a1b",
                "value": "dadb5bc43be9d210c71edd6aa5e45a1b"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:11",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "route_reason": "",
            "start_date_derived_from": "",
            "orig_sys_id": "",
            "closed_at": "",
            "is_reparenting_group": "false",
            "level": "",
            "business_service": "",
            "confidential_users": "",
            "is_confidential": "false",
            "relation_applied": "",
            "time_worked": "",
            "expected_start": "",
            "issue_group_rule": "",
            "opened_at": "2024-10-25 10:46:11",
            "task": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name​IPT0020059",
            "work_end": "",
            "run_calc_brs": "true",
            "work_notes": "",
            "work_cost": "0",
            "assignment_group": "",
            "orig_top_task_id": "",
            "user_hierarchy_status": "2",
            "software_model": "",
            "created_manually": "true",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "effort": "",
            "calendar_duration": "",
            "end_date_derived_from": "",
            "close_notes": "",
            "content": "",
            "duration": "1970-01-02 00:00:00",
            "issue_manager_group": "",
            "sys_id": "444a541847e5161034d5e0d3706d4326",
            "contact_type": "",
            "urgency": "3",
            "constraint_date": "",
            "company": "",
            "end": "2024-10-25",
            "activity_due": "",
            "comments": "",
            "cost": "0",
            "approval": "not requested",
            "due_date": "",
            "issue_type": "",
            "start": "2024-10-25",
            "sys_mod_count": "0",
            "management_method": "",
            "confirmed_date": "",
            "model_id": "",
            "opex_cost": "0",
            "sys_tags": "",
            "time_zone": "",
            "html_description": "",
            "percent_complete": "0",
            "is_group": "false",
            "milestone": "false",
            "issue_source": "44ab97f6c75200107e299e0703c2602a",
            "action_plan": "",
            "response": "",
            "issue_rating": "",
            "location": ""
        }
    }
    


    Get Incident or Security Incidents or GRC Issues or Custom Table Record

    API Endpoint: <Instance URL>/api/今/table/<table>

    Method: 得る

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Parameters

    鍵Value
    sysparm_fieldssys_id、状態、重大度、割り当て先
    sysparm_querysys_idIN<incident_sys_id>

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "severity": "2",
                "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
                "state": "10",
                "assigned_to": {
                    "link": "https://<Instance URL>/api/now/table/sys_user/324sndm",
                    "value": "324sndm"
                }
            }
        ]
    }
    

    Sample API Response (GRC Issue) (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "444a541847e5161034d5e0d3706d4326",
                "impact": "3",
                "state": "1",
                "assigned_to": ""
            }
        ]
    }
    

    Update Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/今/table/<table>

    Method: パッチ

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Body

    
    {
        "work_notes": "Received new alert with Alert ID: $id and Alert Name: $alertName in Cloud Exchange."
    }
    

    Sample API Response (Status Code: 200)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 11:56:25",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "automation",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "2",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    


    Fetch Assignee Users

    API Endpoint: <Instance URL>/api/今/table/sys_user

    Method: 得る

    Parameters

    鍵Value
    sysparm_querysys_id、user_name
    sysparm_fieldssys_idIN<user_sys_id>

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    Authorization基本<username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "800b174138d089c868d09de320f9833b",
                "user_name": "user.abc"
            }
        ]
    }
    

    パフォーマンスマトリックス

    これらの測定値は、以下の仕様を満たす大型CEスタックで収集されたものです。

    ServiceNowインスタンス上のカスタムテーブルに対してパフォーマンスを実行しました。

    デスクリプション仕様
    スタックの詳細サイズ:L

    RAM: 32 GB

    CPU: 16コア

    1分あたりに作成されるチケット数約160件/分

    ユーザーエージェント

    netskope-ce-6.0.0-cto-servicenow-v2.2.0

    ワークフロー

    1. ServiceNowで新しいユーザーを作成する
    2. ユーザーに役割を割り当てる
    3. ServiceNowプラグインを設定する
    4. ServiceNow用のビジネスルールを追加します。
    5. ServiceNow用のキューを追加します。
    6. プラグインを検証してください。

    ビデオを見る

    再生ボタンをクリックして動画をご覧ください。

     

    新しいユーザーを作成する

    1. ServiceNowにログインしてください。
    2. 行く System Security > Users and Groups > Users.
    3. Click New.
    4. 必要な情報を入力し、ユーザーIDのコピーを作成してください。クリック Submit.
    5. ユーザーページで、ユーザーIDを検索し、該当するユーザーをクリックしてください(下図参照)。
    6. S et Password .
      をクリックしてください
    7. Generateをクリックしてください。パスワードをコピーしてから、 Save PasswordとCloseをクリックしてください。

    ユーザーに役割を割り当てる

    1. Scroll down to Roles and click Edit.
    2. Add roles per your requirements:
      Roles required when Incidents is configured in the Destination Table parameter:
      • itil またはsn_incident_write 、 sn_incident_read
        personalize_dictionary
      Role required when Security Incidents is configured in the Destination Table parameter:
      • sn_si.admin
      Roles required when GRC Issues is configured in the Destination Table parameter:
      • sn_grc.business_user (ユーザーは、自身が作成した、または自身に割り当てられた課題のみを表示できます) admin (この権限は、作成者や担当者に関係なく、すべての GRC 課題を表示するために必要です)
      Role required when Custom Table is configured in the Destination Table parameter:
      • admin
    3. Click Save.

      注記

      管理者権限は、作成者や担当者に関係なく、すべてのGRC課題にアクセスするためにのみ必要です。

    4. Update .
      をクリックしてください

    ServiceNowプラグインの設定

    1. Cloud Exchangeで Settings > Plugin Storeに行ってください。ServiceNow v2.2.0 (CTO)プラグインボックスを検索して選択します。
    2. 構成名を指定し、必要に応じて同期間隔を変更してください。
    3. Nextをクリックして認証パラメータを入力してください。
      • Instance URL: ServiceNowインスタンスのURL。
      • Usernameインスタンスのユーザー名。
      • Passwordインスタンスパスワード。
      • Destination Table: インシデントが作成されるテーブルの名前。
    4. 設定パラメータを入力してください。カスタムテーブルの場合は、要件に応じてこれらのフィールドをマッピングしてください。
      • Custom Table Name: カスタムテーブルの名前を入力してください。
      • Custom Status: ステータスフィールド:カスタムテーブルの列名。
      • Custom Severity: 重要度フィールド:カスタムテーブルの列名。
      • Custom Assignee: 担当者フィールド ServiceNow の 'sys_user_' テーブルを参照している場合は、カスタムテーブルの列名を指定します。
      • Custom Group: グループフィールド ServiceNow の 'sys_user_group' テーブルを参照する場合、カスタムテーブルの列名を指定します。
      • Custom Update: 更新フィールド:カスタムテーブルの列名。このフィールドは 重複排除ルールが実行されたときにメッセージを追加するために使用されます。

      注記

      キュー構成のカスタムテーブルでは、デフォルトではフィールドはマッピングされません。ただし、カスタム更新フィールドを指定すると、キュー作成時に重複排除マップフィールドのデフォルトマッピングが提供されます。

    5. Use Default Mappings: キュー構成ページで、キューなしオプション(キューなし デフォルトのマッピングで、管理者権限は不要)にはYes Select 。それ以外の場合は、 Noを選択します。
      • はい: これらのデフォルトのマッピングは、「キューなし」オプションで使用されます。
        対象分野Values
        ショートデスクリプションNetskope $appCategory アラート名: $alertName
        イベント名: $alert_name
        デスクリプションアラート/イベントID: $id
        アラート/イベントアプリ: $appAlert/Event
        ユーザー: $userAlert
        名前: $alertName
        アラートタイプ: $alertType
        アラートアプリカテゴリ: $appCategory
        イベント名: $alert_name
        イベントタイプ: $eventType
      • いいえ。カスタムマッピングを作成できます。
    6. 以下のフィールドからマッピング構成Select 。
      以下は、ステータスと重大度マッピングのデフォルトマッピングです:
      カスタムステータスを作成するには、ページ下部のAddをクリックしてください。
      Add NewをクリックしてCloud Exchangeフィールドを作成できます。
      フィールド名を入力して、 Add Fieldをクリックしてください。お好みのステータスにマッピングしてください。
    7. Save .
      をクリックしてください

    ServiceNow 用の Ticket Orchestrator ビジネスルールを追加する

    ServiceNowプラグインでインシデントを作成するために必要なフィルターに基づいて、ビジネスルールを作成します。

    1. Ticket OrchestratorでBusiness Rulesに移動し、 Create New Ruleをクリックします。
    2. ルール名を入力し、ビジネスルールの対象となるフィールドに対して適切なフィルタクエリ条件を作成します。Filter Queryをクリックしてクエリを手動で入力することもできます。
    3. Save .
      をクリックしてください

    ServiceNow 用のチケットオーケストレーターキューを追加する

    1. Ticket OrchestratorでQueuesに移動し、 Add Queue Configurationをクリックします。
    2. ドロップダウンメニューから、ビジネスルール、プラグイン設定、キューSelect 。

      注記

      マップフィールドセクションのターゲットフィールドは、プラグイン設定時に選択された宛先テーブルに基づいて、ServiceNowインスタンスから取得されます。

    3. アラート/イベントが既に取得済みの場合は、 Saveをクリックしてキューを同期してください。

    ServiceNowプラグインを検証する

    Cloud Exchangeで検証する

    ワークフローを検証するには、Netskope Alerts/Eventsが既にインストールされている必要があります。

    • ServiceNowで作成されたチケットの一覧を表示するには、チケット レーターのTickets に移動してください。

    注記

    対応するCloud Exchangeフィールドにマッピングされていないステータスは、チケットのステータスと同期されません。

    • Logging .
      にアクセスして、チケットの作成/同期を確認してください。

    ServiceNowで検証する

    インシデントの作成を検証するには、Ticket Orchestrator でTicketsに移動し、チケット
    の外部リンクを開きます。ServiceNow にログインしていることを確認してください。

    セキュリティインシデントチケット:

    インシデントチケット:

    GRC発行チケット:

    カスタムテーブルチケット:

    ServiceNowプラグインのトラブルシューティング

    プラグインのアップグレード中に宛先テーブルをカスタムテーブルに更新できませんでした

    プラグインを旧バージョンからv2.1.0にアップグレードする場合、「宛先テーブル」フィールドで「カスタムテーブル」を選択した場合、このエラーが発生する可能性があります。

    
    CTO ServiceNow [CTO ServiceNow]: Validation error occurred. Custom Table Name is required Configuration Parameter.
    

    What to do: スキップボタンをクリックし、プラグインページからプラグイン設定を編集して、 カスタムテーブルに移動する必要があります。

    CTO ServiceNowプラグインを構成できません

    ServiceNowプラグインの設定ができない場合、以下のいずれかの理由が考えられます。

    • 間違ったクレデンシャルが提供されました。
    • ユーザーに必要な権限がありません。
    • インスタンスURLが正しくありません。

    What to do:

    1. 必ず正しいクレデンシャルを入力してください。 ユーザーを作成するには、以下の手順に従ってください。
    2. ユーザーが必要な権限を持っていることを確認してください。ユーザーに役割を付与するには、以下の手順に従ってください。
    3. 正しいインスタンスURLが指定されていることを確認してください。
    インシデントを作成できませんプラグインを使用します

    プラグインでインシデントを作成できない場合、以下のいずれかの理由が考えられます。

    • Cloud Exchangeにアラートやイベントが存在しない、または新しいアラートやイベントが取得されていない。
    • ビジネスルールには、フィルタリングされたアラート/イベントがありません。
    • ユーザーには、インシデントを作成するために必要な役割がありません。

    What to do: 根本原因を特定し、最適な解決策を選択してください。

    1. アラート/イベントページでアラート/イベントが利用可能かどうかを確認してください。アラート/イベントが利用できない場合は、チケットは作成されません。Ticket Orchestratorでアラート/イベントを作成するには、テナントまたはその他の必要な設定を構成します。
    2. ビジネスルールを確認し、テストして、アラートがフィルタリングされているかどうかを確認してください。フィルタリングでアラートが利用できない場合は、ビジネスルールを更新してください。
    3. ユーザーに必要な役割が付与されていることを確認してください。ユーザーに役割を付与するには、以下の手順に従ってください。

    既知の動作

    インシデント テーブルでは、インシデントが作成され、キュー マッピングで担当者フィールドがマッピングされると、 Netskopeテナントから取得したインシデント イベントのステータスが「新規」であっても、インシデントに自動的に「進行中」ステータスが割り当てられることが確認されています。

    このトピックでは
    • ServiceNow 用 Ticket Orchestrator プラグイン