Netskope LogoNetskope Logo
  • セキュリティサービス
  • AIサービス
  • ネットワークサービス
  • 分析サービス
  • 統合
  • getting-started.svg始める
    • サポート
    • コミュニティ
    • Netskope.com
    © 2026 無断転載を禁じます。Netskope 株式会社
    トップページ
    Netskope Cloud Exchange
    チケットオーケストレーターモジュール
    サードパーティ製チケットオーケストレータープラグインの設定
    ServiceNow 用 Ticket Orchestrator プラグイン

    ServiceNow 用 Ticket Orchestrator プラグイン

    リリースノート

    2.3.0 (Required minimum CE version for this is 6.0.0)

    Added

    • マネージャーへのチケット割り当てのサポートを追加しました。
    • エラーログの解決方法を追加しました。

    Changed

    • 保守性を向上させるために、検証チェックを更新し、コードをリファクタリングしました。

    2.2.0

    Added

    • カスタムステータスおよび重大度フィールドのマッピングのサポートを追加しました(カスタムテーブルモード)。

    2.1.0

    Added

    • カスタムテーブルの宛先のサポートを追加しました。

    Changed

    • 選択された宛先テーブルに基づいて、構成パラメータのステッパーを動的にするようにしました。

    2.0.0

    Added

    • GRC Issue テーブルのサポートが追加されました。
    • エンドポイントおよびインシデントイベントのサポートを追加しました。
    • 重大度と担当者の両方の古い値と新しい値を保存するためのサポートを追加しました。

    Changed

    • 古い値と新しい値の両方を保存するようにストレージ動作を変更しました。

    1.1.0

    Added

    • キュー構成に「No Queue」オプションを追加しました。
    • チケットの作成/更新リクエストに対する再試行メカニズムを追加しました。
    • ページネーションのサポートを追加しました。

    1.0.2

    Added

    • 元のチケットへのメタデータの追加のサポートを追加しました。

    Changed

    • デフォルトのフィールドマッピングを変更しました。

    1.0.0

    Added

    • 初回リリース。

    このドキュメントでは、ServiceNow v2.3.0プラグインを Netskope Cloud Exchange プラットフォームの Ticket Orchestrator モジュールで構成する方法について説明します。このプラグインは、ServiceNowプラットフォームの Incident > All ページでのインシデントの作成、Security Incident > Incidents > Show All Incidents ページでのセキュリティインシデントの作成、ポリシー and Compliance > Issues > All Issues ページでのGRC問題の作成、および Custom Table Record ページでのレコードの作成に使われます。また、インシデント/問題の更新と、それらのステータスの同期もサポートしています。このプラグインはServiceNowのDLP Incident Response製品と同じではなく、そのソリューションと連携もしません。

    前提条件

    この設定を完了するには、以下が必要です。

    • Netskopeテナント(または、例えば本番環境と開発/テスト環境など、複数のテナント)。
    • テナントプラグインとチケットオーケストレータープラグインがすでに構成されているCloud Exchangeテナント。
    • アカウントを持つServiceNowインスタンス。
    • GRCインシデントを作成するには、GRC: ポリシー and Compliance Management(App id: sn_compliance)プラグインをServiceNowインスタンスにインストールする必要があります。
    • プラグインに必要な権限は、itil または sn_incident_write、sn_incident_read personalize_dictionary、sn_si.admin、sn_grc.business_user、admin です。
    • 次のホストへの接続: https://<instance-name>.service-now.com 。
    ServiceNowプラグインのサポート

    このプラグインは、ServiceNowプラットフォームの Incident > All ページでのインシデントの作成、Security Incident > Incidents > Show All Incidents ページでのセキュリティインシデントの作成、ポリシー and Compliance > Issues > All Issues ページでのGRC問題の作成、および Custom Table Record ページでのレコードの作成に使われます。また、インシデント/問題の更新と、それらのステータスの同期もサポートしています。このプラグインはServiceNowのDLP Incident Response製品と同じではなく、そのソリューションと連携もしません。

    デスクリプションサポートされている型
    チケットのサポートされるアラートタイプすべて
    チケットのサポートされているイベントタイプすべて
    マッピング
    キューマッピング
    対象分野Values
    ショートデスクリプション
    • Netskope $appCategory alert name: $alertName
    • イベント名:$alert_name
    デスクリプション
    • アラート/イベントID: $id
    • アラート/イベントアプリ:$appAlert/Event
    • ユーザー: $userAlert
    • Name: $alertName
    • アラートタイプ:$alertType
    • アラートアプリカテゴリ:$appCategory
    • イベント名:$alert_name
    • イベントタイプ:$eventType
    Default Status Mappings

    このマッピングは、Netskope CEステータスをServiceNowステータスにマッピングするために使用されます。System Definitions > Tables> [Table Name] > [Status Column Name] > Choicesにアクセスして、利用可能なServiceNowのステータスを確認できます。

    Cloud ExchangeステータスValueServiceNowのステータス
    新しい1新しい
    進行中2進行中
    保留中3保留中
    Closed7Closed
    Deleted–(デフォルトは空白になります)
    ServiceNow でカスタム フィールドを作成してマッピングできます。
    その他–(Default will be blank)
    Default Severity Mappings

    このマッピングは、Netskope CEの重大度をServiceNowの重大度にマッピングするために使用されます。System Definitions > Tables > [Table Name] > [Severity Column Name] > Choicesにアクセスすると、利用可能なServiceNowの重大度の値を確認できます。

    Cloud Exchange重要度ValueServiceNowの重要度
    致命的–(Default will be blank)

    ServiceNowでは、マッピング用のカスタムフィールドを作成できます。

    高い1高い
    中くらい2中くらい
    低い3低い
    情報提供–(Default will be blank)

    ServiceNowでは、マッピング用のカスタムフィールドを作成できます。

    その他–(Default will be blank)
    ServiceNowプラグインのデフォルトのステータスと重要度のマッピングは、プラットフォーム内でこれらのフィールドをカスタマイズできるため、異なる場合があります。対応する Netskope CE フィールドにマッピングされていないステータスまたは重要度は、その他としてマークされます。
    デフォルトテーブルのキュー構成でサポートされるフィールド

    ServiceNowでインシデントを作成する際にマッピングできる、デフォルトテーブルのキュー構成でサポートされているフィールドの一覧を以下に示します。

    セキュリティインシデント
    フィールド名フィールドタイプ
    Malware hashString
    MITRE ATT&CK Procedure (Malware)String
    最終更新日(ソースから)Choice
    NumberString
    Platforms(MITRE)String
    保護者のセキュリティインシデントReference
    影響を受けるユーザーReference
    アラートルールString
    新しい回答者Glide_list
    マシンラーニングの予測String
    宛先IPアドレスString
    ProblemReference
    サービスReference
    実効数String
    サービス内容Reference
    拒否 gotoReference
    Malware URLString
    割り当てられたReference
    EscalationInteger
    勤務時間Timer
    追加譲受人リストGlide_list
    相関IDString
    MITRE ATT&CK TacticString
    Phish 電子メールReference
    VariablesVariables
    アラートセンサーReference
    追加コメントJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    ウォッチリストGlide_list
    SLA dueDue_date
    ContractReference
    アクティブBoolean
    州Integer
    作業メモJournal_input
    閉鎖Reference
    フォローアップGlide_date_time
    構成アイテムReference
    承認履歴Journal
    営業期間Glide_duration
    LocationReference
    ユーザー入力User_input
    送信元IPアドレスString
    変更依頼Reference
    RiskInteger
    ワークフロー活動Reference
    リスクの変化String
    MITRE ATT&CK Data SourceString
    作業メモ一覧Glide_list
    SkillsGlide_list
    攻撃ベクトルGlide_list
    MITRE ATT&CK TechniqueString
    許可されたグループGlide_list
    自動化活動Journal
    ビジネスへの影響Integer
    閉じるコードString
    読む アクセスGlide_list
    特権アクセスGlide_list
    リスクスコアInteger
    セキュリティタグGlide_list
    重大度Integer
    セキュリティインシデント自己診断Reference
    IncidentReference
    コメントと作業メモJournal_list
    MITRE ATT&CK Adversary GroupString
    デスクリプションString
    ImpactInteger
    ClosedGlide_date_time
    グループ一覧Glide_list
    Activity dueDue_date
    MITRE ATT&CK Procedure (Tool)String
    評価を依頼するGlide_list
    許可されたメンバーGlide_list
    ParentReference
    優先度Integer
    最後のメモString
    再割り当て数Integer
    Due dateGlide_date_time
    OrderInteger
    ショートデスクリプションString
    CompanyReference
    承認セットGlide_date_time
    オープンしたReference
    コンタクトタイプString
    SLA製Boolean
    ポストインシデントレポートHtml
    割り当てグループReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    相関表示String
    その他のIoCString
    参照元URLString
    信頼度スコアDecimal
    DepartmentGlide_list
    VulnerabilityReference
    配達業務Reference
    Actual endGlide_date_time
    ユニバーサルリクエストReference
    始めるGlide_date_time
    Actual startGlide_date_time
    承認後String
    転居理由Integer
    制限を強制するBoolean
    外部URLUrl
    配送計画Reference
    拒否された場合String
    リスクスコアを上書きするBoolean
    Incident
    フィールド名フィールドタイプ
    ビジネスへの影響String
    推定原因String
    再開カウントInteger
    NumberString
    親の事件Reference
    サービスReference
    変更依頼Reference
    実効数String
    サービス内容Reference
    インシデント状態Integer
    解決時間Integer
    拒否 gotoReference
    元のテーブルTable_name
    解決済みReference
    クロニクル事件Reference
    割り当てられたReference
    EscalationInteger
    勤務時間Timer
    追加譲受人リストGlide_list
    相関IDString
    VariablesVariables
    子どもの事件Integer
    追加コメントJournal_input
    UrgencyInteger
    OpenedGlide_date_time
    ウォッチリストGlide_list
    SLA dueDue_date
    ContractReference
    アクティブBoolean
    州Integer
    作業メモJournal_input
    閉鎖Reference
    フォローアップGlide_date_time
    構成アイテムReference
    承認履歴Journal
    営業期間Glide_duration
    LocationReference
    ユーザー入力User_input
    カテゴリString
    ビジネス解決時間Integer
    OriginDocument_id
    ワークフロー活動Reference
    変化によって引き起こされるReference
    作業メモ一覧Glide_list
    閉じるコードString
    SkillsGlide_list
    ResolvedGlide_date_time
    Splunk URLUrl
    最後に再開したのはGlide_date_time
    ProblemReference
    CallerReference
    SubcategoryString
    コメントと作業メモJournal_list
    デスクリプションString
    ImpactInteger
    ClosedGlide_date_time
    グループ一覧Glide_list
    Activity dueDue_date
    ParentReference
    優先度Integer
    最後のメモString
    再割り当て数Integer
    Due dateGlide_date_time
    OrderInteger
    ショートデスクリプションString
    CompanyReference
    承認セットGlide_date_time
    オープンしたReference
    コンタクトタイプString
    SLA製Boolean
    保留理由Integer
    割り当てグループReference
    ApprovalString
    DurationGlide_duration
    KnowledgeBoolean
    相関表示String
    配達業務Reference
    Actual endGlide_date_time
    ユニバーサルリクエストReference
    始めるGlide_date_time
    NotifyInteger
    Actual startGlide_date_time
    承認後String
    重大度Integer
    転居理由Integer
    配送計画Reference
    拒否された場合String
    最終再開日Reference
    GRCに関する課題
    フィールド名フィールドタイプ
    再養育グループはBoolean
    権限文書Reference
    アイテムReference
    課題管理者Reference
    問題評価Reference
    管理方法String
    DocumentReference
    ExplanationString
    RecommendationString
    行動計画Html
    SubstateString
    親の問題Reference
    管理目標/リスク記述書Reference
    EntityReference
    機能領域Glide_list
    ユーザー階層ステータスString
    グループBoolean
    問題グループ規則Reference
    課題管理者グループReference
    分類String
    許可されたグループGlide_list
    問題の発生源Glide_list
    ユーザー階層2Reference
    ユーザー階層 1Reference
    ポリシーReference
    ConfidentialBoolean
    ResponseInteger
    確定日Glide_date_time
    問題の種類String
    許可されたユーザーGlide_list
    手動で作成Boolean
    グループレベルString
    Actual endGlide_date_time
    CompanyReference
    NumberString
    ImpactInteger
    ショートデスクリプションString
    承認セットGlide_date_time
    デスクリプションString
    ClosedGlide_date_time
    オープンしたReference
    SLA製Boolean
    グループ一覧Glide_list
    コンタクトタイプString
    Activity dueDue_date
    ワークフロー活動Reference
    拒否 gotoReference
    拒否された場合String
    ContractReference
    EscalationInteger
    実効数String
    アクティブBoolean
    作業メモJournal_input
    割り当てられたReference
    勤務時間Timer
    ビジネスサービスReference
    州Integer
    追加譲受人リストGlide_list
    フォローアップGlide_date_time
    相関IDString
    作業メモ一覧Glide_list
    ユニバーサルリクエストReference
    閉鎖Reference
    配送計画Reference
    承認後String
    ParentReference
    最後のメモString
    割り当てグループReference
    DurationGlide_duration
    優先度Integer
    ApprovalString
    Due dateGlide_date_time
    相関表示String
    再割り当て数Integer
    OrderInteger
    KnowledgeBoolean
    サービス内容Reference
    配達業務Reference
    構成アイテムReference
    コメントと作業メモJournal_list
    UrgencyInteger
    承認履歴Journal
    追加コメントJournal_input
    OpenedGlide_date_time
    営業期間Glide_duration
    ユーザー入力User_input
    VariablesVariables
    ウォッチリストGlide_list
    LocationReference
    SLA dueDue_date
    Actual startGlide_date_time
    始めるGlide_date_time
    転居理由Integer
    SkillsGlide_list
    権限
    • ワークフローのURLにデータを送信する権限。
      • 宛先テーブルパラメータでインシデントが構成されている場合に必要となる役割:
        • itil or sn_incident_write, sn_incident_read
        • personalize_dictionary
      • [宛先テーブル] パラメータでセキュリティインシデントが構成されている場合に必要なロール: sn_si.admin
      • 宛先テーブルパラメータでGRC課題を設定する際に必要なロール:
        • sn_grc.business_user (ユーザーは、自身が作成した課題、または自身に割り当てられた課題のみを表示できます)
        • 管理者(この権限は、作成者や担当者に関係なく、すべてのGRC課題を表示するために必要です)
      • 宛先テーブルパラメータでカスタムテーブルを設定する場合に必須となる役割:
        • admin
    APIの詳細

    List of APIs used

    APIエンドポイント方法Use case
    /api/now/table/sys _辞書得るインシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルフィールドを取得します。
    /api/now/table/sys _ユーザーグループ得るServiceNowグループをキューとして取得する
    /api/now/table/<table>役職インシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルレコードを作成します。
    /api/now/table/<table>得るインシデント、セキュリティインシデント、GRC問題、またはカスタムテーブルレコードを取得します
    /api/now/table/<table>/<incident_id>パッチインシデント、セキュリティインシデント、GRC課題、またはカスタムテーブルレコードの更新
    /api/now/table/sys _ユーザー得る担当者ユーザーの取得

    Get Incident or Security Incident or GRC Issue or Custom Table Fields

    API Endpoint: <Instance URL>/api/now/table/sys_dictionary

    Method: 得る

    Parameters

    鍵Value
    sysparm_queryname=<table_name>^ORname=task^internal_type!=collection
    For Custom Table: name=<custom_table_name>
    sysparm_fields列ラベル、要素
    sysparm_limit1000
    sysparm_offset0

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.1.0-cto-servicenow-v2.3.0
    AuthorizationBasic <username:password>

    Sample API Response (Security Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Malware hash",
                "element": "malware_hash"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Malware)",
                "element": "mitre_malware"
            },
            {
                "column_label": "Last Updated From Source",
                "element": "last_updated_from_src"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Platforms(MITRE)",
                "element": "mitre_platform"
            },
            {
                "column_label": "Parent security incident",
                "element": "parent_security_incident"
            },
            {
                "column_label": "Affected user",
                "element": "affected_user"
            },
            {
                "column_label": "Alert Rule",
                "element": "alert_rule"
            },
            {
                "column_label": "New respondents",
                "element": "new_pir_respondents"
            },
            {
                "column_label": "Machine learning Prediction",
                "element": "prediction"
            },
            {
                "column_label": "Destination IP",
                "element": "dest_ip"
            },
            {
                "column_label": "Problem",
                "element": "problem"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Malware URL",
                "element": "malware_url"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "MITRE ATT&CK Tactic",
                "element": "mitre_tactic"
            },
            {
                "column_label": "Phish Email",
                "element": "phish_email"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Alert Sensor",
                "element": "alert_sensor"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Source IP",
                "element": "source_ip"
            },
            {
                "column_label": "Change request",
                "element": "change_request"
            },
            {
                "column_label": "Risk",
                "element": "risk"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Risk change",
                "element": "risk_change"
            },
            {
                "column_label": "MITRE ATT&CK Data Source",
                "element": "mitre_data_source"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Attack Vector",
                "element": "attack_vector"
            },
            {
                "column_label": "MITRE ATT&CK Technique",
                "element": "mitre_technique"
            },
            {
                "column_label": "Allowed groups",
                "element": "allowed_groups"
            },
            {
                "column_label": "Automation activity",
                "element": "automation_activity"
            },
            {
                "column_label": "Business impact",
                "element": "business_criticality"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Read access",
                "element": "special_access_read"
            },
            {
                "column_label": "Privileged access",
                "element": "special_access_write"
            },
            {
                "column_label": "Risk score",
                "element": "risk_score"
            },
            {
                "column_label": "Security tags",
                "element": "security_tags"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Security incident self",
                "element": "security_incident_self"
            },
            {
                "column_label": "Incident",
                "element": "incident"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "MITRE ATT&CK Adversary Group",
                "element": "mitre_group"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "MITRE ATT&CK Procedure (Tool)",
                "element": "mitre_tool"
            },
            {
                "column_label": "Request assessments",
                "element": "pir_respondents"
            },
            {
                "column_label": "Allowed members",
                "element": "allowed_members"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Post incident report",
                "element": "pir"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Other IoC",
                "element": "other_ioc"
            },
            {
                "column_label": "Referrer URL",
                "element": "referrer_url"
            },
            {
                "column_label": "Confidence score",
                "element": "confidence_score"
            },
            {
                "column_label": "Department",
                "element": "department"
            },
            {
                "column_label": "Vulnerability",
                "element": "vulnerability"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Enforce restriction",
                "element": "enforce_restriction"
            },
            {
                "column_label": "External URL",
                "element": "external_url"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Override risk score",
                "element": "risk_score_override"
            }
        ]
    }
    

    Sample API Response (Incident) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Business impact",
                "element": "business_impact"
            },
            {
                "column_label": "Probable cause",
                "element": "cause"
            },
            {
                "column_label": "Reopen count",
                "element": "reopen_count"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Parent Incident",
                "element": "parent_incident"
            },
            {
                "column_label": "Service",
                "element": "business_service"
            },
            {
                "column_label": "Change Request",
                "element": "rfc"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Incident state",
                "element": "incident_state"
            },
            {
                "column_label": "Resolve time",
                "element": "calendar_stc"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Origin table",
                "element": "origin_table"
            },
            {
                "column_label": "Resolved by",
                "element": "resolved_by"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Child Incidents",
                "element": "child_incidents"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Category",
                "element": "category"
            },
            {
                "column_label": "Chronicle Incident",
                "element": "x_cdsp_chroni_itsm_chronicle_incident_ref"
            },
            {
                "column_label": "Business resolve time",
                "element": "business_stc"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Origin",
                "element": "origin_id"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Caused by Change",
                "element": "caused_by"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Close code",
                "element": "close_code"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            },
            {
                "column_label": "Resolved",
                "element": "resolved_at"
            },
            {
                "column_label": "Splunk URL",
                "element": "x_splu2_splunk_ser_splunk_url"
            },
            {
                "column_label": "Last reopened at",
                "element": "reopened_time"
            },
            {
                "column_label": "Problem",
                "element": "problem_id"
            },
            {
                "column_label": "Caller",
                "element": "caller_id"
            },
            {
                "column_label": "Subcategory",
                "element": "subcategory"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "On hold reason",
                "element": "hold_reason"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Notify",
                "element": "notify"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Severity",
                "element": "severity"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Last reopened by",
                "element": "reopened_by"
            }
        ]
    }
    

    Sample API Response (GRC Issues) (Status Code: 200)

    
    {
        "result": [
            {
                "column_label": "Is reparenting group",
                "element": "is_reparenting_group"
            },
            {
                "column_label": "Authority document",
                "element": "authority_document"
            },
            {
                "column_label": "Item",
                "element": "item"
            },
            {
                "column_label": "Issue manager",
                "element": "issue_manager"
            },
            {
                "column_label": "Issue rating",
                "element": "issue_rating"
            },
            {
                "column_label": "Management method",
                "element": "management_method"
            },
            {
                "column_label": "Document",
                "element": "document"
            },
            {
                "column_label": "Explanation",
                "element": "explanation"
            },
            {
                "column_label": "Recommendation",
                "element": "recommendation"
            },
            {
                "column_label": "Action plan",
                "element": "action_plan"
            },
            {
                "column_label": "Substate",
                "element": "substate"
            },
            {
                "column_label": "Parent issue",
                "element": "parent_issue"
            },
            {
                "column_label": "Control objective/Risk statement",
                "element": "content"
            },
            {
                "column_label": "Entity",
                "element": "profile"
            },
            {
                "column_label": "Functional domain",
                "element": "functional_domain"
            },
            {
                "column_label": "User hierarchy status",
                "element": "user_hierarchy_status"
            },
            {
                "column_label": "Is group",
                "element": "is_group"
            },
            {
                "column_label": "Issue group rule",
                "element": "issue_group_rule"
            },
            {
                "column_label": "Issue manager group",
                "element": "issue_manager_group"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Classification",
                "element": "classification"
            },
            {
                "column_label": "Allowed groups",
                "element": "confidential_user_groups"
            },
            {
                "column_label": "Issue source",
                "element": "issue_source"
            },
            {
                "column_label": "User hierarchy 2",
                "element": "user_hierarchy_2"
            },
            {
                "column_label": "User hierarchy 1",
                "element": "user_hierarchy_1"
            },
            {
                "column_label": "Policy",
                "element": "policy"
            },
            {
                "column_label": "Confidential",
                "element": "is_confidential"
            },
            {
                "column_label": "Response",
                "element": "response"
            },
            {
                "column_label": "Confirmed date",
                "element": "confirmed_date"
            },
            {
                "column_label": "Issue type",
                "element": "issue_type"
            },
            {
                "column_label": "Allowed users",
                "element": "confidential_users"
            },
            {
                "column_label": "Created manually",
                "element": "created_manually"
            },
            {
                "column_label": "Group level",
                "element": "group_level"
            },
            {
                "column_label": "Actual end",
                "element": "work_end"
            },
            {
                "column_label": "Company",
                "element": "company"
            },
            {
                "column_label": "Task type",
                "element": "sys_class_name"
            },
            {
                "column_label": "Number",
                "element": "number"
            },
            {
                "column_label": "Impact",
                "element": "impact"
            },
            {
                "column_label": "Short description",
                "element": "short_description"
            },
            {
                "column_label": "Approval set",
                "element": "approval_set"
            },
            {
                "column_label": "Description",
                "element": "description"
            },
            {
                "column_label": "Closed",
                "element": "closed_at"
            },
            {
                "column_label": "Opened by",
                "element": "opened_by"
            },
            {
                "column_label": "Made SLA",
                "element": "made_sla"
            },
            {
                "column_label": "Group list",
                "element": "group_list"
            },
            {
                "column_label": "Contact type",
                "element": "contact_type"
            },
            {
                "column_label": "Activity due",
                "element": "activity_due"
            },
            {
                "column_label": "Created by",
                "element": "sys_created_by"
            },
            {
                "column_label": "Workflow activity",
                "element": "wf_activity"
            },
            {
                "column_label": "Rejection goto",
                "element": "rejection_goto"
            },
            {
                "column_label": "Upon reject",
                "element": "upon_reject"
            },
            {
                "column_label": "Contract",
                "element": "contract"
            },
            {
                "column_label": "Escalation",
                "element": "escalation"
            },
            {
                "column_label": "Effective number",
                "element": "task_effective_number"
            },
            {
                "column_label": "Active",
                "element": "active"
            },
            {
                "column_label": "Work notes",
                "element": "work_notes"
            },
            {
                "column_label": "Assigned to",
                "element": "assigned_to"
            },
            {
                "column_label": "Time worked",
                "element": "time_worked"
            },
            {
                "column_label": "Business service",
                "element": "business_service"
            },
            {
                "column_label": "Domain Path",
                "element": "sys_domain_path"
            },
            {
                "column_label": "State",
                "element": "state"
            },
            {
                "column_label": "Additional assignee list",
                "element": "additional_assignee_list"
            },
            {
                "column_label": "Follow up",
                "element": "follow_up"
            },
            {
                "column_label": "Sys ID",
                "element": "sys_id"
            },
            {
                "column_label": "Correlation ID",
                "element": "correlation_id"
            },
            {
                "column_label": "Created",
                "element": "sys_created_on"
            },
            {
                "column_label": "Work notes list",
                "element": "work_notes_list"
            },
            {
                "column_label": "Universal Request",
                "element": "universal_request"
            },
            {
                "column_label": "Closed by",
                "element": "closed_by"
            },
            {
                "column_label": "Domain",
                "element": "sys_domain"
            },
            {
                "column_label": "Delivery plan",
                "element": "delivery_plan"
            },
            {
                "column_label": "Upon approval",
                "element": "upon_approval"
            },
            {
                "column_label": "Parent",
                "element": "parent"
            },
            {
                "column_label": "Close notes",
                "element": "close_notes"
            },
            {
                "column_label": "Assignment group",
                "element": "assignment_group"
            },
            {
                "column_label": "Duration",
                "element": "calendar_duration"
            },
            {
                "column_label": "Priority",
                "element": "priority"
            },
            {
                "column_label": "Approval",
                "element": "approval"
            },
            {
                "column_label": "Due date",
                "element": "due_date"
            },
            {
                "column_label": "Updated by",
                "element": "sys_updated_by"
            },
            {
                "column_label": "Correlation display",
                "element": "correlation_display"
            },
            {
                "column_label": "Updates",
                "element": "sys_mod_count"
            },
            {
                "column_label": "Reassignment count",
                "element": "reassignment_count"
            },
            {
                "column_label": "Order",
                "element": "order"
            },
            {
                "column_label": "Knowledge",
                "element": "knowledge"
            },
            {
                "column_label": "Service offering",
                "element": "service_offering"
            },
            {
                "column_label": "Delivery task",
                "element": "delivery_task"
            },
            {
                "column_label": "Configuration item",
                "element": "cmdb_ci"
            },
            {
                "column_label": "Comments and Work notes",
                "element": "comments_and_work_notes"
            },
            {
                "column_label": "Urgency",
                "element": "urgency"
            },
            {
                "column_label": "Approval history",
                "element": "approval_history"
            },
            {
                "column_label": "Additional comments",
                "element": "comments"
            },
            {
                "column_label": "Opened",
                "element": "opened_at"
            },
            {
                "column_label": "Business duration",
                "element": "business_duration"
            },
            {
                "column_label": "User input",
                "element": "user_input"
            },
            {
                "column_label": "Variables",
                "element": "variables"
            },
            {
                "column_label": "Watch list",
                "element": "watch_list"
            },
            {
                "column_label": "Location",
                "element": "location"
            },
            {
                "column_label": "SLA due",
                "element": "sla_due"
            },
            {
                "column_label": "Updated",
                "element": "sys_updated_on"
            },
            {
                "column_label": "Actual start",
                "element": "work_start"
            },
            {
                "column_label": "Expected start",
                "element": "expected_start"
            },
            {
                "column_label": "Transfer reason",
                "element": "route_reason"
            },
            {
                "column_label": "Skills",
                "element": "skills"
            }
        ]
    }
    


    Get ServiceNow groups as Queue

    API Endpoint: <Instance URL>/api/now/table/sys_user_group

    Method: 得る

    Parameters

    鍵Value
    sysparm_fields名前、sys_id
    sysparm_limit1000
    sysparm_offset0

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.1.0-cto-servicenow-v2.3.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    {
        "result": [
            {
                "sys_id": "01336b6347332100158b949b6c9a71b5",
                "name": "Finance Vendors"
            },
            ….
        ]
    }

    Create Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: 役職

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.1.0-cto-servicenow-v2.3.0
    AuthorizationBasic <username:password>

    Body

    
    {
        "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
        "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
        "assignment_group": "<group_sys_id>"
    }
    

    Sample API Response (Security Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:39",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "0",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    

    Sample API Response (Incident) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "made_sla": "true",
            "caused_by": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:44:54",
            "child_incidents": "0",
            "hold_reason": "",
            "origin_table": "",
            "task_effective_number": "INC0923990",
            "approval_history": "",
            "skills": "",
            "number": "INC0923990",
            "resolved_by": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:44:54",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "state": "1",
            "route_reason": "",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "calendar_stc": "",
            "x_cdsp_chroni_itsm_chronicle_incident_ref": "",
            "closed_at": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "business_service": "",
            "business_impact": "",
            "priority": "5",
            "sys_domain_path": "/",
            "rfc": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:44:54",
            "business_duration": "",
            "group_list": "",
            "work_end": "",
            "caller_id": "",
            "reopened_time": "",
            "resolved_at": "",
            "approval_set": "",
            "subcategory": "",
            "work_notes": "",
            "universal_request": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "close_code": "",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "additional_assignee_list": "",
            "business_stc": "",
            "cause": "",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "origin_id": "",
            "calendar_duration": "",
            "close_notes": "",
            "notify": "1",
            "service_offering": "",
            "sys_class_name": "incident",
            "closed_by": "",
            "follow_up": "",
            "parent_incident": "",
            "sys_id": "d1f994dc1be15a549f2eeb98b04bcb71",
            "contact_type": "",
            "reopened_by": "",
            "incident_state": "1",
            "urgency": "3",
            "problem_id": "",
            "company": "",
            "reassignment_count": "0",
            "activity_due": "",
            "assigned_to": "",
            "severity": "3",
            "comments": "",
            "approval": "not requested",
            "sla_due": "",
            "comments_and_work_notes": "",
            "due_date": "",
            "sys_mod_count": "0",
            "reopen_count": "0",
            "sys_tags": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "correlation_id": "",
            "location": "",
            "category": "inquiry"
        }
    }
    

    Sample API Response (GRC Issue) (Status Code: 201)

    
    {
        "result": {
            "parent": "",
            "shadow": "false",
            "watch_list": "",
            "authority_document": "",
            "recommendation": "",
            "wbs": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 10:46:11",
            "explanation": "",
            "approval_history": "",
            "rollup": "false",
            "skills": "",
            "number": "IPT0020059",
            "schedule_start_date": "2024-10-25 10:46:11",
            "capex_cost": "0",
            "state": "1",
            "sys_created_by": "user1.abc",
            "knowledge": "false",
            "order": "",
            "work_duration": "",
            "item": "",
            "budget_cost": "0",
            "cmdb_ci": "",
            "dependency": "",
            "contract": "",
            "impact": "3",
            "key_milestone": "false",
            "profile": "",
            "remaining_effort": "",
            "active": "true",
            "work_notes_list": "",
            "functional_domain": "",
            "classification": "",
            "priority": "4",
            "sys_domain_path": "/",
            "version": "",
            "business_duration": "",
            "group_list": "",
            "override_status": "false",
            "approval_set": "",
            "critical_path": "false",
            "status": "green",
            "universal_request": "",
            "end_date": "2024-10-26 10:46:11",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "work_start": "",
            "top_task": {
                "link": "https://service-now.com/api/now/table/planned_task/444a541847e5161034d5e0d3706d4326",
                "value": "444a541847e5161034d5e0d3706d4326"
            },
            "parent_issue": "",
            "time_constraint": "asap",
            "document": "",
            "additional_assignee_list": "",
            "service_offering": "",
            "sys_class_name": "sn_grc_issue",
            "closed_by": "",
            "follow_up": "",
            "calculation_type": "automatic",
            "confidential_user_groups": "",
            "reassignment_count": "0",
            "schedule_end_date": "2024-10-26 10:46:11",
            "assigned_to": "",
            "policy": "",
            "start_date": "2024-10-25 10:46:11",
            "mpp_task_id": "",
            "sub_tree_root": "",
            "sla_due": "",
            "comments_and_work_notes": "",
            "remaining_duration": "",
            "has_conflict": "false",
            "substate": "",
            "allow_dates_outside_schedule": "false",
            "escalation": "0",
            "upon_approval": "proceed",
            "issue_manager": "",
            "correlation_id": "",
            "group_level": "",
            "made_sla": "true",
            "user_hierarchy_2": "",
            "user_hierarchy_1": "",
            "wbs_order": "",
            "task_effective_number": "IPT0020059",
            "work_effort": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/dadb5bc43be9d210c71edd6aa5e45a1b",
                "value": "dadb5bc43be9d210c71edd6aa5e45a1b"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:11",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "route_reason": "",
            "start_date_derived_from": "",
            "orig_sys_id": "",
            "closed_at": "",
            "is_reparenting_group": "false",
            "level": "",
            "business_service": "",
            "confidential_users": "",
            "is_confidential": "false",
            "relation_applied": "",
            "time_worked": "",
            "expected_start": "",
            "issue_group_rule": "",
            "opened_at": "2024-10-25 10:46:11",
            "task": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name​IPT0020059",
            "work_end": "",
            "run_calc_brs": "true",
            "work_notes": "",
            "work_cost": "0",
            "assignment_group": "",
            "orig_top_task_id": "",
            "user_hierarchy_status": "2",
            "software_model": "",
            "created_manually": "true",
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "effort": "",
            "calendar_duration": "",
            "end_date_derived_from": "",
            "close_notes": "",
            "content": "",
            "duration": "1970-01-02 00:00:00",
            "issue_manager_group": "",
            "sys_id": "444a541847e5161034d5e0d3706d4326",
            "contact_type": "",
            "urgency": "3",
            "constraint_date": "",
            "company": "",
            "end": "2024-10-25",
            "activity_due": "",
            "comments": "",
            "cost": "0",
            "approval": "not requested",
            "due_date": "",
            "issue_type": "",
            "start": "2024-10-25",
            "sys_mod_count": "0",
            "management_method": "",
            "confirmed_date": "",
            "model_id": "",
            "opex_cost": "0",
            "sys_tags": "",
            "time_zone": "",
            "html_description": "",
            "percent_complete": "0",
            "is_group": "false",
            "milestone": "false",
            "issue_source": "44ab97f6c75200107e299e0703c2602a",
            "action_plan": "",
            "response": "",
            "issue_rating": "",
            "location": ""
        }
    }
    


    Get Incident or Security Incidents or GRC Issues or Custom Table Record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: 得る

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Parameters

    鍵Value
    sysparm_fieldssys_id、状態、重大度、割り当て先
    sysparm_querysys_idIN<incident_sys_id>

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.1.0-cto-servicenow-v2.3.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "severity": "2",
                "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
                "state": "10",
                "assigned_to": {
                    "link": "https://<Instance URL>/api/now/table/sys_user/324sndm",
                    "value": "324sndm"
                }
            }
        ]
    }
    

    Sample API Response (GRC Issue) (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "444a541847e5161034d5e0d3706d4326",
                "impact": "3",
                "state": "1",
                "assigned_to": ""
            }
        ]
    }
    

    Update Incident or Security Incident or GRC Issue or Custom Table record

    API Endpoint: <Instance URL>/api/now/table/<table>

    Method: パッチ

    Path Parameters

    鍵Value
    tableインシデント sn_si_incident sn_grc_issue custom_table_name

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.0.0-cto-servicenow-v2.2.0
    AuthorizationBasic <username:password>

    Body

    
    {
        "work_notes": "Received new alert with Alert ID: $id and Alert Name: $alertName in Cloud Exchange."
    }
    

    Sample API Response (Status Code: 200)

    
    {
        "result": {
            "parent": "",
            "sla_suspended_reason": "",
            "watch_list": "",
            "upon_reject": "cancel",
            "sys_updated_on": "2024-10-25 11:56:25",
            "qualification_group": "",
            "expected_end": "",
            "enforce_restriction": "false",
            "approval_history": "",
            "source_ip": "",
            "skills": "",
            "number": "SIR1083059",
            "problem": "",
            "previous_agent": "",
            "state": "10",
            "sys_created_by": "user1.abc",
            "template_workflow_invoked": "false",
            "knowledge": "false",
            "order": "",
            "phish_email": "",
            "cmdb_ci": "",
            "delivery_plan": "",
            "contract": "",
            "impact": "3",
            "active": "true",
            "work_notes_list": "",
            "vulnerability": "",
            "priority": "4",
            "sys_domain_path": "/",
            "sla_suspended": "false",
            "business_duration": "",
            "group_list": "",
            "special_access_write": "",
            "dest_ip": "",
            "mitre_platform": "",
            "approval_set": "",
            "risk_change": "up",
            "malware_url": "",
            "universal_request": "",
            "last_updated_from_src": "automation",
            "template": "",
            "short_description": "Netskope $appCategory alert name: $alertName, Event Name: $alert_name",
            "correlation_display": "",
            "delivery_task": "",
            "work_start": "",
            "request_type": "",
            "affected_user": "",
            "other_ioc": "",
            "additional_assignee_list": "",
            "alert_sensor": "",
            "assigned_vendor": "",
            "service_offering": "",
            "sys_class_name": "sn_si_incident",
            "closed_by": "",
            "follow_up": "",
            "mitre_group": "",
            "sla_suspended_on": "",
            "estimated_end": "",
            "vendor_reference": "",
            "reassignment_count": "0",
            "assigned_to": "",
            "request_category": "",
            "requested_due_by": "",
            "mitre_malware": "",
            "sla_suspended_for": "",
            "business_criticality": "3",
            "sla_due": "",
            "opened_for": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "comments_and_work_notes": "",
            "mitre_technique": "",
            "special_access_read": "",
            "substate": "",
            "escalation": "0",
            "upon_approval": "proceed",
            "allowed_groups": "",
            "correlation_id": "",
            "asset": "",
            "mitre_tool": "",
            "spam": "false",
            "referrer_url": "",
            "made_sla": "true",
            "mitre_tactic": "",
            "is_catalog": "false",
            "malware_hash": "",
            "alert_rule": "",
            "task_effective_number": "SIR1083059",
            "external_url": "",
            "sys_updated_by": "user1.abc",
            "opened_by": {
                "link": "https://service-now.com/api/now/table/sys_user/c813b7cb1b8342148f4aedb8b04bcb91",
                "value": "c813b7cb1b8342148f4aedb8b04bcb91"
            },
            "user_input": "",
            "sys_created_on": "2024-10-25 10:46:39",
            "sys_domain": {
                "link": "https://service-now.com/api/now/table/sys_user_group/global",
                "value": "global"
            },
            "pir": "",
            "route_reason": "",
            "closed_at": "",
            "allowed_members": "",
            "business_service": "",
            "attack_vector": "",
            "time_worked": "",
            "expected_start": "",
            "opened_at": "2024-10-25 10:46:39",
            "task_created": "false",
            "x_cdsp_chroni_sir_chronicle_si": "",
            "work_end": "",
            "confidence_score": "",
            "prediction": "",
            "automation_activity": "",
            "subcategory": "",
            "work_notes": "",
            "security_tags": "",
            "risk_score_override": "false",
            "initiated_from": "",
            "close_code": "",
            "assignment_group": {
                "link": "https://service-now.com/api/now/table/sys_user_group/<group_sys_id>",
                "value": "<group_sys_id>"
            },
            "description": "Alert/Event ID: $id\nAlert/Event App: $app\nAlert/Event User: $user\n\nAlert Name: $alertName\nAlert Type: $alertType\nAlert App Category: $appCategory\n\nEvent Name: $alert_name\nEvent Type: $eventType",
            "calendar_duration": "",
            "close_notes": "",
            "pir_respondents": "",
            "sys_id": "f25adc501b255a549f2eeb98b04bcb56",
            "contact_type": "",
            "urgency": "3",
            "secure_notes": "",
            "company": "",
            "new_pir_respondents": "",
            "department": "",
            "activity_due": "",
            "severity": "2",
            "comments": "",
            "risk_score": "40",
            "approval": "not requested",
            "due_date": "",
            "sys_mod_count": "2",
            "parent_security_incident": "",
            "sys_tags": "",
            "billable": "false",
            "mitre_data_source": "",
            "caller": "",
            "location": "",
            "risk": "3",
            "category": "",
            "incident": "",
            "change_request": "",
            "security_incident_self": {
                "link": "https://service-now.com/api/now/table/sn_si_incident/f25adc501b255a549f2eeb98b04bcb56",
                "value": "f25adc501b255a549f2eeb98b04bcb56"
            }
        }
    }
    


    Fetch Assignee Users

    API Endpoint: <Instance URL>/api/now/table/sys_user

    Method: 得る

    Parameters

    鍵Value
    sysparm_querysys_id、user_name
    sysparm_fieldssys_idIN<user_sys_id>

    Headers

    鍵Value
    ユーザーエージェントnetskope-ce-6.1.0-cto-servicenow-v2.3.0
    AuthorizationBasic <username:password>

    Sample API Response (Status Code: 200)

    
    {
        "result": [
            {
                "sys_id": "800b174138d089c868d09de320f9833b",
                "user_name": "user.abc"
            }
        ]
    }
    

    パフォーマンスマトリックス

    これらの測定値は、以下の仕様を満たす大型CEスタックで収集されたものです。

    ServiceNowインスタンス上のカスタムテーブルのパフォーマンス:

    デスクリプション仕様
    スタックの詳細サイズ:大
    RAM:32 GB
    CPU:16コア
    1分あたりに作成されるチケット数約160件/分
    ユーザーエージェント

    netskope-ce-6.1.0-cto-servicenow-v2.3.0

    ワークフロー
    1. ServiceNowでユーザーを作成し、ユーザーにロールを割り当てます。
    2. ServiceNowプラグインを構成します。
    3. ビジネスルールを設定します。
    4. キューを設定します。
    5. プラグインを検証してください。

    ビデオを見る

    再生ボタンをクリックして動画をご覧ください。

     

    新しいユーザーを作成する

    1. ServiceNowインスタンスにログインしてください。

    2. 行く System Security > Users and Groups > Users.

    3. Click New.

    4. 必要な情報を入力し、User ID. を確認してください。Submit. をクリックします。

    5. UsersページでユーザーIDを検索し、以下に示すようにユーザーをクリックします。

    6. Set Passwordをクリックしてください。

    7. Generateをクリックします。パスワードをコピーします。

    ユーザーに役割を割り当てる

    1. 下にスクロールしてRolesをクリックし、 Editをクリックしてください。

    2. 要件に応じてロールを追加します:

      Roles required when Incidents is configured in the Destination Table parameter:

      • itil または sn_incident_write、sn_incident_read 
      • personalize_dictionary

      Role required when Security Incidents is configured in the Destination Table parameter: 

      • sn_si.admin

      Roles required when GRC Issues is configured in the Destination Table parameter: 

      • sn_grc.business_user (ユーザーは、自身が作成した課題、または自身に割り当てられた課題のみを閲覧できます。)
      • admin (この権限は、作成者や担当者に関わらず、すべてのGRC課題を閲覧するために必要です。)

      Role required when Custom Table is configured in the Destination Table parameter: 

      • admin
    3. Click Save.

      管理者権限は、作成者や担当者に関係なく、すべてのGRC課題にアクセスするためにのみ必要です。
    4. Updateをクリックしてください。

    ServiceNowプラグインの設定

    1. Cloud Exchange で、 Settings > Plugin Storeに移動します。ServiceNow v2.3.0 (CTO)プラグインを検索して選択してください。

    2. 構成名を指定し、必要に応じて同期間隔を変更してください。

    3. Nextをクリックして認証パラメータを入力してください。

      • インスタンス URL: ServiceNow インスタンス URL。
      • ユーザー名:インスタンスのユーザー名。
      • パスワード:インスタンスパスワード。
      • 送信先テーブル:インシデントが作成されるテーブルの名前。
    4. 設定パラメータを入力してください。カスタムテーブルの場合は、要件に応じてこれらのフィールドをマッピングしてください。

      • Custom Table Name:カスタムテーブルの名前を指定します。
      • Custom Status: カスタムテーブルのステータスフィールドの列名。
      • Custom Severity:重大度フィールド(カスタムテーブルの列名)
      • Custom Assignee: ServiceNow の sys_user_ テーブルを参照しているカスタムテーブルの担当者 (Assignee) フィールドの列名。
      • Custom Group: ServiceNowの sys_user_group テーブルを参照している場合の、カスタムテーブルのグループフィールドの列名。
      • Custom Update:カスタムテーブルのフィールド「Column name」を更新します。このフィールドは、重複排除ルールが実行されたときにメッセージを追加するために使用されます。
      キュー構成のカスタムテーブルでは、デフォルトではフィールドはマッピングされません。ただし、カスタム更新フィールドを指定すると、キュー作成時に重複排除マップフィールドのデフォルトマッピングが提供されます。
    5. Use Default Mappings: Select Yes for the No Queue option (No Queue uses default mappings for the queue, and does not require elevated access) on the Queue configuration page; otherwise, select No.

      Yes: これらのデフォルトマッピングは、[No Queue] オプションに使用されます。

      ターゲットフィールドValue
      ショートデスクリプションNetskope $appCategory アラート名: $alertNameイベント名: $alert_name
      デスクリプションアラート/イベントID:$idAlert/Event
      アプリ:$appAlert/Event
      ユーザー:$userAlert
      名前:$alertName
      アラートタイプ:$alertType
      アラートアプリカテゴリ:$appCategory
      イベント名:$alert_nameイベントタイプ:$eventType

      No: カスタムマッピングを作成できます。

    6. 次のフィールドのステータスおよび重要度のマッピングのデフォルトマッピングを選択します:

      カスタムステータスを作成するには、ページ下部のAddをクリックしてください。

      Add NewをクリックしてCloud Exchangeフィールドを作成します。

      フィールド名を入力して、 Add Fieldをクリックしてください。お好みのステータスにマッピングしてください。

    7. Saveをクリックしてください。

    ServiceNow用のTicket Orchestratorビジネスルールを構成する

    ServiceNow プラグインでインシデントを作成する必要があるフィルターに基づいて、ビジネスルールを構成します。

    1. Ticket OrchestratorでBusiness Rulesに移動し、 Create New Ruleをクリックします。
    2. テキストボックスに適したルール名を入力し、ビジネスルールのフィールドに適切なフィルタークエリ条件を構築します。Filter Queryを押して、手動でクエリを入力することもできます。
    3. Saveをクリックしてください。 

    ServiceNow用のTicket Orchestratorキューを構成する

    1. Ticket Orchestratorで、Queues に移動して Add Queue Configuration をクリックします。ドロップダウンから「Business Rule」、「Plugin Configuration」、「Queue」を選択します。

      マップフィールドセクションのターゲットフィールドは、プラグイン設定時に選択された宛先テーブルに基づいて、ServiceNowインスタンスから取得されます。
    2. 既にアラート/イベントを取得済みの場合、 Saveをクリックしてキューを同期してください。

      「Map Field」セクションで Assigned to Manager フィールドを利用できます。マッピングされると、チケットはServiceNow上のアラートユーザーのマネージャーに割り当てられます。マネージャーを解決できない場合は、マッピングされた担当者自身のアカウントにフォールバックされます。

    ServiceNowプラグインを検証する

    Cloud Exchangeで検証する

    ワークフローを検証するには、Netskope Alerts/Eventsが既にインストールされている必要があります。

    ServiceNowで作成されたチケットの一覧を表示するには、チケット オーケストレーターのTickets に移動します。

    対応するCloud Exchangeフィールドにマッピングされていないステータスは、チケットのステータスと同期されません。

    Logging に移動して、チケットの作成と同期を確認します。

    ServiceNowで検証する

    インシデントの作成を検証するには、Ticket Orchestrator でTicketsに移動し、チケット
    の外部リンクを開きます。ServiceNow にログインしていることを確認してください。

    Security Incident Ticket:

    Incident Ticket:

    GRC Issues Ticket:

    Custom Table Ticket:

    ServiceNowプラグインのトラブルシューティング

    プラグインのアップグレード中に宛先テーブルをカスタムテーブルに更新できませんでした

    プラグインを旧バージョンからv2.1.0にアップグレードする場合、「宛先テーブル」フィールドで「カスタムテーブル」を選択した場合、このエラーが発生する可能性があります。

    
    CTO ServiceNow [CTO ServiceNow]: Validation error occurred. Custom Table Name is required Configuration Parameter.
    

    What to do: スキップボタンをクリックし、プラグインページからプラグイン設定を編集して、 カスタムテーブルに移動する必要があります。

    CTO ServiceNowプラグインを構成できません

    ServiceNowプラグインの設定ができない場合、以下のいずれかの理由が考えられます。

    • 間違ったクレデンシャルが提供されました。
    • ユーザーに必要な権限がありません。
    • インスタンスURLが正しくありません。

    What to do:

    1. 正しいクレデンシャルが入力されていることを確認してください。ユーザーを作成するには、次の 手順に従います。
    2. ユーザーに必要な権限が付与されていることを確認してください。ユーザーにロールを割り当てるには、次の 手順に従います。
    3. 正しいインスタンスURLが指定されていることを確認してください。
    インシデントを作成できませんプラグインを使用します

    プラグインでインシデントを作成できない場合、以下のいずれかの理由が考えられます。

    • Cloud Exchangeにアラートやイベントが存在しない、または新しいアラートやイベントが取得されていない。
    • ビジネスルールには、フィルタリングされたアラート/イベントがありません。
    • ユーザーには、インシデントを作成するために必要な役割がありません。

    What to do: 根本原因を特定し、最適な解決策を選択してください。

    1. アラート/イベントページでアラート/イベントが利用可能かどうかを確認してください。アラート/イベントが利用できない場合は、チケットは作成されません。Ticket Orchestratorでアラート/イベントを作成するには、テナントまたはその他の必要な設定を構成します。
    2. ビジネスルールを確認し、テストして、アラートがフィルタリングされているかどうかを確認してください。フィルタリングでアラートが利用できない場合は、ビジネスルールを更新してください。
    3. ユーザーに必要な役割が付与されていることを確認してください。ユーザーに役割を付与するには、以下の手順に従ってください。
    Getting the error Custom Table Name is a required Configuration Parameter and values are getting clear, or Use Default Mappings field not retaining its value if changed

    カスタムテーブルを使用しており、[構成パラメータ]で[次へ]をクリックしたときに、値が空白になり、エラー Custom Table Name is a required Configuration Parameter が発生する場合。

    OR

    デフォルトのテーブルのいずれかを使用している場合は、[構成パラメータ] で [次へ] をクリックし、[Use Default Mapping] を Yes に設定します。この場合、[Use Default Mapping] の値は保持されません。

    Perform these steps to resolve the issue:

    カスタムテーブルの場合:

    1. 宛先テーブルで Custom Table を選択し、Next をクリックします。
    2. 構成パラメータのすべての値を指定してください。
    3. ([次へ]をクリックせずに)Save をクリックします。
    4. マッピングを編集するには、プラグインを編集してマッピングを直接更新できます。

    その他のテーブル:

    1. 宛先テーブルで Any Table を Select し、「次へ」をクリックします。
    2. キューの設定中にデフォルトのマッピングを使用するには、「Use Default Mapping」で Yes を選択します。
    3. ([次へ]をクリックせずに)Save をクリックします。
    4. マッピングを編集するには、プラグインを編集してマッピングを直接更新できます。

    既知の行動

    • インシデントテーブルにおいて、インシデントが作成され、キューマッピングで担当者フィールドがマップされている場合、Netskopeテナントから取得したインシデントイベントのステータスが 新しい であっても、インシデントに自動的に In Progress 状態が割り当てられることが確認されています。
    • ServiceNow インスタンスに任意のユーザーへの割り当てをブロックするビジネスルールが構成されている場合、プラグインでインシデントの作成時にエラーが発生することが確認されています。
    このトピックでは
    • ServiceNow 用 Ticket Orchestrator プラグイン