PANW IoT Incident Handling with ServiceNow
This playbook creates a ServiceNow ticket after the incident is enriched by Palo Alto Networks IoT security portal (previously Zingbox Cloud).
- Pack
- PaloAltoNetworks_IoT
- Tasks
- 12
Inputs
- IoTConfigListName — The list name defined in the XSOAR Lists for the RACI and ServiceNow calculation.
- CreateServiceNowTicket — Determines if a ServiceNow ticket should be created based on the RACI calculation. Set to True to create an incident.
Outputs
- PaloAltoNetworksIoT — This path will have field "device" for the device details and "raci" if the command "iot-security-get-raci" has output.
- ServiceNow.Record — The ServiceNow record after creating the ServiceNow ticket.
Commands used
- iot-security-get-device
- servicenow-create-record