The ExtraHop for ServiceNow bundle enables you to automatically generate an event in ServiceNow when a detection is identified by the Discover appliance. By adding this bundle, you can integrate the data found on the wire by the ExtraHop system directly into your existing ServiceNow workflows.
The bundle contains a trigger that creates the events in ServiceNow and a dashboard where you can see how many events were created during the selected time interval and the related detections by category and by title.
- (1) Triggers
- ServiceNow Detection Event Trigger
- (2) Dashboards
- ServiceNow - Detection Events Setup
- ServiceNow - Detection Events
This bundle requires a connection to the cloud-based ExtraHop Machine Learning Service, and security detections require an ExtraHop Reveal(x) subscription.
- Your ExtraHop Discover appliance must have firmware version 7.4.2 or later.
- You must have a connection to the cloud-based ExtraHop Machine Learning Service.
- You must have administrator privileges on both your ExtraHop appliance and your ServiceNow instance.
Install the bundle
- Download the bundle on this page.
- Log into the ExtraHop Web UI and complete the following procedures, which are available in the ExtraHop Web UI Guide.
- Upload a bundle
- Apply a Bundle
Add a user account to ServiceNow
Create a user on your ServiceNow instance to allow the ExtraHop system to create events.
- Log into your ServiceNow instance with administrator privileges.
- Select the menu item System Security - Users.
- Click New.
- Specify the following user settings:
- User ID: extrahop
- First Name: ExtraHop
- Last Name: ExtraHop
- Password: Specify a password. This password is required for the next section when you configure the Discover appliance.
- Click Submit.
- Click on the new user extrahop.
- On the Roles tab, click Edit…
- Add the following roles to the Roles List for the extrahop user: rest_service, web_service_admin, and evt_mgmt_integration.
- Click Save.
Configure the Discover appliance
You must configure an Open Data Stream (ODS) on your Discover appliance before you can send events to ServiceNow.
- Log into the ExtraHop Admin UI on your Discover appliance.
- In the System Configuration section, click Open Data Streams.
- Click Add Target.
- Specify the following settings:
- Target Type: HTTP
- Name: If this target is the first HTTP ODS you have created on the appliance, leave the default value. Otherwise, type servicenow as the ODS name.
- Host: The hostname or IP address of your ServiceNow instance.
- Port: 443
- Type: HTTPS
- Authentication: Basic
- User: extrahop
- Password: Specify the password you configured for the extrahop user on your ServiceNow instance.
- Click Test to verify that the settings you specified are correct. Resolve any errors before saving the configuration.
- Click Save.
Enable the ServiceNow trigger
- Log into the Web UI on the Discover appliance.
- Click the System Settings icon .
- Click Triggers.
- Select the checkbox next to the ServiceNow Detection Event Trigger and then click Enable.
- Close the System Settings window.
After you have configured the ServiceNow bundle, navigate to Dashboards > Dashboard Inbox and click the ServiceNow - Detection Events dashboard to see the related charts. It might take some time before the charts show data, depending on when a detection is identified.