Integrate ServiceNow with Strata Cloud Manager
Learn how to integrate ServiceNow with Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
- One of the following licenses:
|
Strata Cloud Manager supports ServiceNow, an incident management platform that
provides a common framework for managing incidents and notifying you about incidents
through ServiceNow tickets. Any incident that Strata Cloud Manager creates will
automatically create a ticket on ServiceNow. When Strata Cloud Manager scans your
environment and detects a problem, it generates an incident and pushes it to ServiceNow
as a ticket. Then, when you dismiss an incident, Strata Cloud Manager sends a state
change notification to update the ticket status on ServiceNow.
ServiceNow has two types of integration: Bidirectional and unidirectional. A
bidirectional integration means you’re pushing data to ServiceNow as well as getting
data from ServiceNow. In a unidirectional integration, you’re only pushing data to
ServiceNow.
Before You Proceed with ServiceNow Integration
ServiceNow integration might require cross-border data transfers. If your
ServiceNow instance, your Strata Cloud Manager instance, or your Strata Cloud
Manager interface users are located in multiple countries, you need to consent to
and authorize any cross-border transfers of data.
When configuring your ServiceNow integration on the Strata Cloud Manager
Notification Rule, you need the following:
Configured ServiceNow instance with administrative access
ServiceNow username and password with web access and specific roles
to create incidents or query various tables
Client ID and Password created under Application Registry in order
to authorize Strata Cloud Manager to access your ServiceNow Instance
URL of your ServiceNow instance
Bidirectional Integration in ServiceNow
Bidirectional integration has four fields in the ServiceNow Mapped
Field, three of which are mandatory if you opt for bidirectional integration.
ServiceNow Ticket ID—Mandatory
ServiceNow Operational Status—Mandatory
ServiceNow Priority—Mandatory
ServiceNow Assigned To—Optional. This field could have
information such as name or email address
If you enable bidirectional integration, you must
ensure that any updates made to your final destination incident table are also
updated back on the staging table configured in Strata Cloud Manager. Strata Cloud
Manager has no visibility into your destination table; it can only read status
changes if they are synced back to the configured staging table.
ServiceNow Schema and Data Flow
Your ServiceNow records include the same structured incident metadata available in
webhooks, ensuring that automation workflows built on either channel receive
consistent data. Strata Cloud Manager provides these fields, but it only sends
fields that you have mapped in ServiceNow. See
Configure OAuth for ServiceNow Integration with Strata Cloud Manager.
Strata Cloud Manager supports native integration with ServiceNow. This means you do
not need to maintain extra scripts to integrate with ServiceNow. However, the schema
elements from Strata Cloud Manager contain a lot more information than the standard
out-of-the-box incident table in ServiceNow can support. Because there is no
one-to-one mapping possible with the default incident table, you cannot directly
integrate with the out-of-the-box incident table. Instead, you must push the data
to a staging table first. You have two options for the staging table:
- Use the system default out-of-the-box table: sys_import_set_row
- Create a new custom table
After the data is in the staging table, you must use ServiceNow Transformation Maps
to translate and transfer that data into your final destination incident table.
Creating and managing these transformation maps must be done within ServiceNow and
requires ServiceNow administrative knowledge.
Here are the fields for ServiceNow mapping:
| Field | Description |
| Incident ID | Unique incident ID. |
| Title | Title of the incident. |
| Severity | Incident severity, such as High, Medium, Low, Critical,
Warning, and Informational. |
| Status | Incident status. Valid values are Raised, Cleared,
RaisedChild, and ClearPending. |
| Raised Time | Time the incident was raised in the UTC format. |
| Last Updated Time | Time the incident was updated in the UTC
format. |
| Tenant Name | Tenant Service Group (TSG) name. |
| Code | Unique code. It is in a flat namespace; for example,
INC_CIE_AGENT_DISCONNECT. |
| Category | Category, such as RN (remote networks) or SC (service
connection). |
| Subcategory | Subcategory |
|
Incident Details URL
| URL link to the incident details page in Strata Cloud
Manager. |
| Primary Impacted Objects | Primary impacted entity or entities associated with the
incident. Each object contains key-value pairs identifying the
impacted resource. |
| Related Objects | Additional impacted entities related to the incident.
Provides supplementary context beyond the primary impacted
objects. |
| Description | Description of the incident. |
| Product | Product associated with the incident, such as NGFW,
Prisma Access, or Posture. |
| Clear Reason | Reason for clearing the incident. |
| Correlated Alerts | Alerts related to the incident. Each alert contains the
alert_id and title. |
|
Parent Incidents
| Parent incidents associated with the current incident.
Each object contains the incident_id. |
|
Child Incidents
| Child incidents associated with the current incident.
Each object contains the incident_id. |
|
Custom Field
|
Static name-value pairs for custom ServiceNow
fields
Allows setting static values for custom ServiceNow
table columns, used to populate customer-specific or
business-specific ServiceNow fields with constant values.
|
| Subtenant ID | Subtenant ID. |
| Cleared Time | Time the incident was cleared in the UTC
format. |
Configure OAuth for ServiceNow Integration with Strata Cloud Manager
OAuth authentication provides a secure, industry-standard method for Strata
Cloud Manager to connect to ServiceNow instances without requiring the transmission
or storage of user credentials. This authentication framework enables your
organization to maintain strict security controls while automating incident
management workflows between your Palo Alto Networks platform and ServiceNow.
When you configure OAuth authentication for ServiceNow notifications, the
system establishes trust through a token-based mechanism rather than traditional
username and password combinations.
Create a new ServiceNow User with specific roles to read and write to the
various tables needed for the integration.
Navigate to Users under Security > Users and
Groups.
Enter all the required details and submit your changes.
The Web service access only check box
is checked by default.
Search for the newly created user. Select the Roles tab in the table
at the bottom of the page and click Edit. You will need to give the
user permissions for the following three roles: itil,
sn_incident_read, and sn_incident_write. Save your changes.
Click Set Password on the User page. In the pop-up window,
click Generate and Save Password. Make sure to copy
the password to a secure location along with the User ID.
This information will be used to populate the ServiceNow User
credentials in Strata Cloud Manager.
Create a Web OAuth client (Inbound):
Navigate to All > System OAuth > Application
Registry.
Select New Integration and then select
New Inbound Integration Experience.
Select OAuth - Client Credential grant.
The ServiceNow interface for this may
vary depending on your ServiceNow version, but selecting
OAuth - Client Credential grant is
required.
Add a
Name for the OAuth and create a
Client Secret.
The
Client Secret can also be left blank if an auto-generated
secret is wanted. Click
Submit and then navigate back to the
Application Registry entry and save both the
Client ID and
Client Secret. This information will be used under the
Client credential forms in Strata Cloud Manager. See
Configure a ServiceNow Notification Profile.
Configure the staging table.
- Navigate to All > System Definition > Tables &
Columns.
If creating a custom table, click Create Table
and enter all required information. If using the default
sys_import_set_row table, proceed to edit it.
Verify that your staging table columns align with the required Strata
Cloud Manager metadata fields. For instance, when adding the
incident_id string column, ensure the character
limit is sufficiently large; using a higher string size is
recommended to accommodate the extensive data often found in primary
impacted or related object fields. Check ServiceNow for the exact
column names (for example, custom fields will have a
u_ prefix like u_incident_id,
while system fields will not).
Set up Transformation Maps on ServiceNow.
Configure a Transformation Map in ServiceNow to take the data from your
staging table (for example,
sys_import_set_row) and write
it to your final destination incident table. Refer to
ServiceNow documentation for more
information.
ServiceNow Integration FAQs
Use these frequently asked questions (FAQs) to troubleshoot common issues when
integrating Strata™ Cloud Manager with ServiceNow.
Can you directly integrate with the out-of-the-box incidents table in
ServiceNow?
No. Strata Cloud Manager sends more information than the standard
out-of-the-box incident table schema can accept. You must push data to a
staging table first (such as sys_import_set_row or a custom
table), and then use a ServiceNow Transformation Map to move the data to
your final incidents table.
Why are ticket updates in ServiceNow not reflecting back in Strata Cloud
Manager?
Strata Cloud Manager only has visibility into the specific staging table you
configured in the Notification Profile. If you are making state changes or
reassigning tickets in your final destination table, you must ensure those
changes sync back to the staging table so Strata Cloud Manager can read
them.
What should you do if you receive a 500 error when clicking Test ServiceNow
Account Connect?
A 500-level error indicates an issue on the ServiceNow side (for example,
incorrect permissions, OAuth configuration issues, or table access issues).
Before contacting support, you can use an external API testing tool to
simulate a write request directly to your ServiceNow instance using your
configured OAuth credentials. This will help you verify if the issue is with
your ServiceNow configuration or the Strata Cloud Manager integration.