Integrate ServiceNow with Strata Cloud Manager
Focus
Strata Cloud Manager

Integrate ServiceNow with Strata Cloud Manager

Table of Contents

Integrate ServiceNow with Strata Cloud Manager

Learn how to integrate ServiceNow with Strata Cloud Manager.
Where Can I Use This?What Do I Need?
Strata Cloud Manager supports ServiceNow, an incident management platform that provides a common framework for managing incidents and notifying you about incidents through ServiceNow tickets. Any incident that Strata Cloud Manager creates will automatically create a ticket on ServiceNow. When Strata Cloud Manager scans your environment and detects a problem, it generates an incident and pushes it to ServiceNow as a ticket. Then, when you dismiss an incident, Strata Cloud Manager sends a state change notification to update the ticket status on ServiceNow.
ServiceNow has two types of integration: Bidirectional and unidirectional. A bidirectional integration means you’re pushing data to ServiceNow as well as getting data from ServiceNow. In a unidirectional integration, you’re only pushing data to ServiceNow.

Before You Proceed with ServiceNow Integration

ServiceNow integration might require cross-border data transfers. If your ServiceNow instance, your Strata Cloud Manager instance, or your Strata Cloud Manager interface users are located in multiple countries, you need to consent to and authorize any cross-border transfers of data.
When configuring your ServiceNow integration on the Strata Cloud Manager Notification Rule, you need the following:
  • Configured ServiceNow instance with administrative access
  • ServiceNow username and password with web access and specific roles to create incidents or query various tables
  • Client ID and Password created under Application Registry in order to authorize Strata Cloud Manager to access your ServiceNow Instance
  • URL of your ServiceNow instance
Bidirectional Integration in ServiceNow
Bidirectional integration has four fields in the ServiceNow Mapped Field, three of which are mandatory if you opt for bidirectional integration.
  • ServiceNow Ticket ID—Mandatory
  • ServiceNow Operational Status—Mandatory
  • ServiceNow Priority—Mandatory
  • ServiceNow Assigned To—Optional. This field could have information such as name or email address
If you enable bidirectional integration, you must ensure that any updates made to your final destination incident table are also updated back on the staging table configured in Strata Cloud Manager. Strata Cloud Manager has no visibility into your destination table; it can only read status changes if they are synced back to the configured staging table.

ServiceNow Schema and Data Flow

Your ServiceNow records include the same structured incident metadata available in webhooks, ensuring that automation workflows built on either channel receive consistent data. Strata Cloud Manager provides these fields, but it only sends fields that you have mapped in ServiceNow. See Configure OAuth for ServiceNow Integration with Strata Cloud Manager.
Strata Cloud Manager supports native integration with ServiceNow. This means you do not need to maintain extra scripts to integrate with ServiceNow. However, the schema elements from Strata Cloud Manager contain a lot more information than the standard out-of-the-box incident table in ServiceNow can support. Because there is no one-to-one mapping possible with the default incident table, you cannot directly integrate with the out-of-the-box incident table. Instead, you must push the data to a staging table first. You have two options for the staging table:
  • Use the system default out-of-the-box table: sys_import_set_row
  • Create a new custom table
After the data is in the staging table, you must use ServiceNow Transformation Maps to translate and transfer that data into your final destination incident table. Creating and managing these transformation maps must be done within ServiceNow and requires ServiceNow administrative knowledge.
Here are the fields for ServiceNow mapping:
FieldDescription
Incident IDUnique incident ID.
TitleTitle of the incident.
SeverityIncident severity, such as High, Medium, Low, Critical, Warning, and Informational.
StatusIncident status. Valid values are Raised, Cleared, RaisedChild, and ClearPending.
Raised TimeTime the incident was raised in the UTC format.
Last Updated TimeTime the incident was updated in the UTC format.
Tenant NameTenant Service Group (TSG) name.
CodeUnique code. It is in a flat namespace; for example, INC_CIE_AGENT_DISCONNECT.
CategoryCategory, such as RN (remote networks) or SC (service connection).
SubcategorySubcategory
Incident Details URL
URL link to the incident details page in Strata Cloud Manager.
Primary Impacted ObjectsPrimary impacted entity or entities associated with the incident. Each object contains key-value pairs identifying the impacted resource.
Related ObjectsAdditional impacted entities related to the incident. Provides supplementary context beyond the primary impacted objects.
Description Description of the incident.
ProductProduct associated with the incident, such as NGFW, Prisma Access, or Posture.
Clear ReasonReason for clearing the incident.
Correlated AlertsAlerts related to the incident. Each alert contains the alert_id and title.
Parent Incidents
Parent incidents associated with the current incident. Each object contains the incident_id.
Child Incidents
Child incidents associated with the current incident. Each object contains the incident_id.
TSG ID
Tenant ID.
Custom Field
Static name-value pairs for custom ServiceNow fields
Allows setting static values for custom ServiceNow table columns, used to populate customer-specific or business-specific ServiceNow fields with constant values.
Subtenant IDSubtenant ID.
Cleared TimeTime the incident was cleared in the UTC format.

Configure OAuth for ServiceNow Integration with Strata Cloud Manager

OAuth authentication provides a secure, industry-standard method for Strata Cloud Manager to connect to ServiceNow instances without requiring the transmission or storage of user credentials. This authentication framework enables your organization to maintain strict security controls while automating incident management workflows between your Palo Alto Networks platform and ServiceNow.
When you configure OAuth authentication for ServiceNow notifications, the system establishes trust through a token-based mechanism rather than traditional username and password combinations.
  1. Create a new ServiceNow User with specific roles to read and write to the various tables needed for the integration.
    1. Navigate to Users under Security > Users and Groups.
    2. Enter all the required details and submit your changes.
      The Web service access only check box is checked by default.
    3. Search for the newly created user. Select the Roles tab in the table at the bottom of the page and click Edit. You will need to give the user permissions for the following three roles: itil, sn_incident_read, and sn_incident_write. Save your changes.
    4. Click Set Password on the User page. In the pop-up window, click Generate and Save Password. Make sure to copy the password to a secure location along with the User ID.
      This information will be used to populate the ServiceNow User credentials in Strata Cloud Manager.
  2. Create a Web OAuth client (Inbound):
    1. Navigate to All > System OAuth > Application Registry.
    2. Select New Integration and then select New Inbound Integration Experience.
    3. Select OAuth - Client Credential grant.
      The ServiceNow interface for this may vary depending on your ServiceNow version, but selecting OAuth - Client Credential grant is required.
    4. Add a Name for the OAuth and create a Client Secret. The Client Secret can also be left blank if an auto-generated secret is wanted. Click Submit and then navigate back to the Application Registry entry and save both the Client ID and Client Secret. This information will be used under the Client credential forms in Strata Cloud Manager. See Configure a ServiceNow Notification Profile.
  3. Configure the staging table.
    1. Navigate to All > System Definition > Tables & Columns.
    2. If creating a custom table, click Create Table and enter all required information. If using the default sys_import_set_row table, proceed to edit it.
    3. Verify that your staging table columns align with the required Strata Cloud Manager metadata fields. For instance, when adding the incident_id string column, ensure the character limit is sufficiently large; using a higher string size is recommended to accommodate the extensive data often found in primary impacted or related object fields. Check ServiceNow for the exact column names (for example, custom fields will have a u_ prefix like u_incident_id, while system fields will not).
  4. Set up Transformation Maps on ServiceNow.
    Configure a Transformation Map in ServiceNow to take the data from your staging table (for example, sys_import_set_row) and write it to your final destination incident table. Refer to ServiceNow documentation for more information.

ServiceNow Integration FAQs

Use these frequently asked questions (FAQs) to troubleshoot common issues when integrating Strata™ Cloud Manager with ServiceNow.
  • Can you directly integrate with the out-of-the-box incidents table in ServiceNow?
    No. Strata Cloud Manager sends more information than the standard out-of-the-box incident table schema can accept. You must push data to a staging table first (such as sys_import_set_row or a custom table), and then use a ServiceNow Transformation Map to move the data to your final incidents table.
  • Why are ticket updates in ServiceNow not reflecting back in Strata Cloud Manager?
    Strata Cloud Manager only has visibility into the specific staging table you configured in the Notification Profile. If you are making state changes or reassigning tickets in your final destination table, you must ensure those changes sync back to the staging table so Strata Cloud Manager can read them.
  • What should you do if you receive a 500 error when clicking Test ServiceNow Account Connect?
    A 500-level error indicates an issue on the ServiceNow side (for example, incorrect permissions, OAuth configuration issues, or table access issues). Before contacting support, you can use an external API testing tool to simulate a write request directly to your ServiceNow instance using your configured OAuth credentials. This will help you verify if the issue is with your ServiceNow configuration or the Strata Cloud Manager integration.