PANW Device Security Incident Handling with ServiceNow
This playbook creates a ServiceNow ticket after the incident is enriched by Palo Alto Networks Device Security portal (previously Zingbox Cloud).
- Pack
- PaloAltoNetworks_DeviceSecurity
- Tasks
- 12
Inputs
- DeviceSecurityConfigListName — The list name defined in the Cortex XSOAR lists for the RACI and ServiceNow calculation.
- CreateServiceNowTicket — Whether a ServiceNow ticket should be created based on the RACI calculation. Set to True to create an incident.
Outputs
- PaloAltoNetworksDeviceSecurity — Contains the device details and the RACI information if the device-security-get-raci command has output.
- ServiceNow.Record — The ServiceNow record after creating the ServiceNow ticket.
Commands used
- device-security-get-device
- servicenow-create-record