Integrate Device Security through Cortex XSOAR with ServiceNow
for asset management.
Where Can I Use This?
What Do I Need?
Device Security (Managed by Strata Cloud Manager)
(Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise Plus,
Industrial OT, or Medical)
Device Security X subscription
One of the following Cortex XSOAR setups:
A free, cohosted, limited-featured
Cortex XSOAR instance
A full-featured Cortex XSOAR server
Palo Alto Networks Device Security can integrate through Cortex XSOAR with
the ServiceNow asset management solution, turning its static inventory into a
dynamic one. Device Security forwards your inventory of connected devices
directly into ServiceNow to blend in with your existing devices. In addition, you
can manually send alerts and vulnerabilities as incidents to
ServiceNow for conversion into work orders.
For Device Security to supplement the asset management capabilities of ServiceNow,
they must both be monitoring the devices and activities on the same network. So that
Device Security can do this, one or more of the next-generation firewalls
that protect the network send network data logs to the Palo Alto Networks cloud
logging service, which streams metadata from these logs to Device Security. As
Device Security analyzes this information, it discovers and identifies
devices and tracks behaviors. Device Security also detects device vulnerabilities
and generates security alerts when it detects that anomalous network activity has
occurred. Through Cortex XSOAR, Device Security then sends ServiceNow
details about the device attributes in its inventory. Additionally, from
Device Security, you can send ServiceNow any detected
vulnerabilities and security alerts as incidents for conversion into work orders.
Cortex XSOAR connects to ServiceNow through its API, not through a Service Graph
Connector.