Forum Discussion
Logicapp to sync incident status between sentinel to Servicenow.
- May 26, 2021
No problem
Understood, so i think here is a solution which ynchronize Incident closure from Sentinel to ServiceNow. By implementing it you should be able to close an Incident in AS and have it automatically close in SNow
https://eldar.cloud/2021/04/24/azure-sentinel-incident-sync-with-servicenow/
https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-incident-bi-directional-sync-with-servicenow/ba-p/1667771
A playbook to close AS incident from snow is available here :
https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Close-SentinelIncident-fromSNOW
Above playbook will sync, when a close is triggered from Service now but not vice versa.
- ibnmbodjiMay 26, 2021Iron Contributor
No problem
Understood, so i think here is a solution which ynchronize Incident closure from Sentinel to ServiceNow. By implementing it you should be able to close an Incident in AS and have it automatically close in SNow
https://eldar.cloud/2021/04/24/azure-sentinel-incident-sync-with-servicenow/- Nazan2045Sep 08, 2021Former Employee
ibnmbodji It seems the Logic App is no longer available, do you have the updated link? Thank you
- Sayeed_PatelOct 05, 2021Copper Contributor
Hello,
I'm trying to connect Logic Apps to ServiceNow and get/post information. Is there a guide that can help me do that?
- narameshJun 01, 2021Copper ContributorThank you so much for your help. I shall check this out.
- woottsJun 10, 2021Iron Contributor
Hi all this is an interesting topic and something I am keen to know more about. So.....
We have a situation whereby we create an incident in ServiceNow (SIR) from an incident in Sentinel. which on a 1 on 1 basis is great. We close the incident in SIR it closes in Sentinel and the main platform which provided the information.
Then scenario 2
Incident is created in SIR. Another Alert is triggered which by example M365D says is linked to this and creates a Multi Stage / Main incident consisting of the initial incident and any that follow.
The problem being we dont want to close the first incident as that is being worked on. But Sentinel closes it (automatically) and states no entities and no alerts attached. As these have been moved to the main incident which is now compiling all the alerts as they flow through.
How do we get it to update the very first incident and not populate a new incident ID. Or even overwrite the initial Incident in SIR with a new name, new information from the now main incident.
hope that makes at least some sense.