Chapter 12: ServiceNow Integration
As you have read so far, Azure Sentinel is a powerful solution for gathering logs and threat intelligence, and for discovering threats across your entire environment. However, this is only part of the solution required to run a Security Operations Center (SOC). When a security alert is raised in Azure Sentinel, the SOC may need assistance from several other teams in order to investigate the issue, mitigate the threat, and remediate any impact caused.
In order to coordinate these activities, organizations utilize a service management platform, such as ServiceNow, to create cases and track the progress being made by each team. While this chapter is focused on the specifics of using the ServiceNow platform, the procedures may be modified for use on a different platform if it supports integration with Azure Sentinel and Azure Logic Apps.
The process of case management begins by generating alerts within Azure Sentinel; then, those alerts are used...