IoT Security
Integrate IoT Security with ServiceNow
Table of Contents
Expand All
|
Collapse All
IoT Security Docs
-
-
- Firewall Deployment Options for IoT Security
- Use a Tap Interface for DHCP Visibility
- Use a Virtual Wire Interface for DHCP Visibility
- Use SNMP Network Discovery to Learn about Devices from Switches
- Use Network Discovery Polling to Discover Devices
- Use ERSPAN to Send Mirrored Traffic through GRE Tunnels
- Use DHCP Server Logs to Increase Device Visibility
- Control Allowed Traffic for Onboarding Devices
- Support Isolated Network Segments
-
Integrate IoT Security with ServiceNow
Integrate IoT Security through Cortex XSOAR with ServiceNow
for asset management.
Where Can I Use This? | What Do I Need? |
---|---|
|
One of the following Cortex XSOAR setups:
|
Palo Alto Networks IoT Security can integrate through Cortex XSOAR with
the ServiceNow asset management solution, turning its static inventory into a
dynamic one. IoT Security forwards your inventory of connected devices
directly into ServiceNow to blend in with your existing devices. In addition, it
automatically sends security alerts and vulnerabilities as incidents to
ServiceNow for conversion into work orders. You can manually send
alerts and vulnerabilities as well.
For IoT Security to supplement the asset management capabilities of ServiceNow,
they must both be monitoring the devices and activities on the same network. So that
IoT Security can do this, one or more of the next-generation firewalls
that protect the network send network data logs to the Palo Alto Networks cloud
logging service, which streams metadata from these logs to IoT Security. As
IoT Security analyzes this information, it discovers and identifies
devices and tracks behaviors. IoT Security also detects device vulnerabilities
and generates security alerts when it detects that anomalous network activity has
occurred. Through Cortex XSOAR, IoT Security then sends ServiceNow
details about the device attributes in its inventory. Additionally, IoT Security sends ServiceNow any detected vulnerabilities and security alerts as incidents
for conversion into work orders.

Cortex XSOAR connects to ServiceNow through its API, not through a Service Graph
Connector.
Integrating with ServiceNow requires either a full-featured Cortex XSOAR server
or the purchase and activation of an IoT Security third-party integration add-on license, which comes with a free cohosted Cortex XSOAR instance. The basic
plan includes a license for three integration add-ons, one of which can be used for
ServiceNow. The advanced plan includes a license for all supported third-party
integrations.