How do we go about Integrating Azure Setninel with Service Now

Techno89 61 Reputation points
2021-10-18T07:17:35.93+00:00

We use Service now for our incident reporting tool for various other service, How can we integrate Service now in Azure Sentinel. I have the rome version of Service Now, is it compatible ?

What all permission might be required for this ?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
971 questions
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,231 Reputation points Microsoft Employee
    2021-10-18T12:12:20.757+00:00

    @Techno89 Thanks for reaching out. Azure sentinel integration is compatible with Rome version of Service now.

    There are actually two ways of doing it, you can select either of them :

    1) Pull method

    It uses the Azure Sentinel API method. You can initiate this from the Service Now portal with Dedicated Azure Sentinel configuration. In this method you will need to create an application in Azure AD and grant it permission towards the log analytics workspace for your sentinel. All the details required for this have been given here :
    https://docs.servicenow.com/bundle/quebec-security-management/page/product/secops-integration-sir/secops-integration-ms-azure-sentinel/task/configure-microsoft-azure-portal.html

    You will need Service portal access, Azure AD admin credential for this process.

    Follow this for a step by step process :
    https://docs.servicenow.com/bundle/quebec-security-management/page/product/secops-integration-sir/secops-integration-ms-azure-sentinel/concept/microsoft-azure-sentinel-integration.html

    Video : https://www.youtube.com/watch?v=LEWqi98fv3o&t=160s

    2) Push method

    In here you can create a logic app to take the incident once they are generated and then create a record in Service Now.
    For this you need to have the permission for running the logic app and Service connection Instance information.
    Service now is a dedicated connector in logic app so this method would be simple for you. But keep in mind that every time the logic app is run, you will be charged towards your azure subscription.

    141386-image.png


    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

0 additional answers

Sort by: Most helpful