question

Techno89 avatar image
0 Votes"
Techno89 asked vipulsparsh-MSFT answered

How do we go about Integrating Azure Setninel with Service Now

We use Service now for our incident reporting tool for various other service, How can we integrate Service now in Azure Sentinel. I have the rome version of Service Now, is it compatible ?

What all permission might be required for this ?

microsoft-sentinel
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

vipulsparsh-MSFT avatar image
0 Votes"
vipulsparsh-MSFT answered

@Techno89 Thanks for reaching out. Azure sentinel integration is compatible with Rome version of Service now.

There are actually two ways of doing it, you can select either of them :

1) Pull method

It uses the Azure Sentinel API method. You can initiate this from the Service Now portal with Dedicated Azure Sentinel configuration. In this method you will need to create an application in Azure AD and grant it permission towards the log analytics workspace for your sentinel. All the details required for this have been given here :
https://docs.servicenow.com/bundle/quebec-security-management/page/product/secops-integration-sir/secops-integration-ms-azure-sentinel/task/configure-microsoft-azure-portal.html

You will need Service portal access, Azure AD admin credential for this process.

Follow this for a step by step process :
https://docs.servicenow.com/bundle/quebec-security-management/page/product/secops-integration-sir/secops-integration-ms-azure-sentinel/concept/microsoft-azure-sentinel-integration.html

Video : https://www.youtube.com/watch?v=LEWqi98fv3o&t=160s


2) Push method


In here you can create a logic app to take the incident once they are generated and then create a record in Service Now.
For this you need to have the permission for running the logic app and Service connection Instance information.
Service now is a dedicated connector in logic app so this method would be simple for you. But keep in mind that every time the logic app is run, you will be charged towards your azure subscription.

141386-image.png




Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.



image.png (86.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.