<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ServiceNow CMDB  data to XSIAM in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248024#M346</link>
    <description>&lt;P class="mb-2 whitespace-pre-wrap"&gt;Hi,&lt;/P&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;We have integrated XSIAM with ServiceNow CMDB. We want to pull critical assets from the CMDB into XSIAM using an API and we have to do feature field configuration for these critical assets. Currently, I only see an option to upload a static file in the feature field configuration ( Host/ User/IPaddress)&lt;/P&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;Could someone please help with the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;How to get CMDB data from ServiceNow using an API and keep it as a dynamic list in XSIAM?&lt;/LI&gt;
&lt;LI&gt;How can this dynamic list be used for feature field configuration?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2026 08:23:26 GMT</pubDate>
    <dc:creator>A.Velusamy</dc:creator>
    <dc:date>2026-02-12T08:23:26Z</dc:date>
    <item>
      <title>ServiceNow CMDB  data to XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248024#M346</link>
      <description>&lt;P class="mb-2 whitespace-pre-wrap"&gt;Hi,&lt;/P&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;We have integrated XSIAM with ServiceNow CMDB. We want to pull critical assets from the CMDB into XSIAM using an API and we have to do feature field configuration for these critical assets. Currently, I only see an option to upload a static file in the feature field configuration ( Host/ User/IPaddress)&lt;/P&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;Could someone please help with the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;How to get CMDB data from ServiceNow using an API and keep it as a dynamic list in XSIAM?&lt;/LI&gt;
&lt;LI&gt;How can this dynamic list be used for feature field configuration?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="mb-2 whitespace-pre-wrap"&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 08:23:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248024#M346</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-02-12T08:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: ServiceNow CMDB  data to XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248392#M350</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1401872841"&gt;@A.Velusamy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="0" data-end="322"&gt;Integrating ServiceNow CMDB data into Cortex XSIAM to identify critical assets involves several components. While the &lt;STRONG data-start="118" data-end="163"&gt;"Featured Hosts, Users, and IP addresses"&lt;/STRONG&gt; list in Case Configuration currently relies on manual updates, you can achieve dynamic asset identification using XSIAM’s ingestion and grouping capabilities.&lt;/P&gt;
&lt;HR data-start="324" data-end="327" /&gt;
&lt;H4 data-start="329" data-end="391"&gt;1. Getting CMDB Data via API and Creating a Dynamic Dataset&lt;/H4&gt;
&lt;P data-start="393" data-end="554"&gt;To pull CMDB data from ServiceNow and maintain it in XSIAM, you must use the &lt;STRONG data-start="470" data-end="500"&gt;ServiceNow Event Collector&lt;/STRONG&gt; rather than the standard ServiceNow CMDB Integration.&lt;/P&gt;
&lt;H5 data-start="556" data-end="580"&gt;Integration Choice:&lt;/H5&gt;
&lt;P data-start="581" data-end="852"&gt;-The ServiceNow CMDB Integration is designed for automation and enrichment commands (fetching data on demand within a playbook) and does not create persistent datasets.&lt;BR data-start="748" data-end="751" /&gt;-The &lt;STRONG data-start="755" data-end="785"&gt;ServiceNow Event Collector&lt;/STRONG&gt; is the correct tool for continuous ingestion and dataset creation.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H5 data-start="854" data-end="878"&gt;Dataset Generation:&lt;/H5&gt;
&lt;P data-start="879" data-end="990"&gt;-Once configured, XSIAM automatically creates datasets based on the selected ServiceNow tables using the format:&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;&lt;SPAN class="language-xml"&gt;servicenow_cmdb_&lt;SPAN class="hljs-tag"&gt;&amp;lt;&lt;SPAN class="hljs-name"&gt;table_name&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;gt;_raw
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H5 data-start="1034" data-end="1067"&gt;Identifying Critical Assets:&lt;/H5&gt;
&lt;P data-start="1068" data-end="1252"&gt;Ensure you are using the &lt;STRONG data-start="1093" data-end="1109"&gt;system names&lt;/STRONG&gt; of the ServiceNow fields (e.g., &lt;CODE data-start="1142" data-end="1160"&gt;u_critical_asset&lt;/CODE&gt;) rather than the display names to ensure the data is captured correctly in the raw dataset.&lt;/P&gt;
&lt;HR data-start="1254" data-end="1257" /&gt;
&lt;H4 data-start="1259" data-end="1316"&gt;2. Handling Reference Fields (URLs vs. Display Values):&lt;/H4&gt;
&lt;P data-start="1318" data-end="1504"&gt;A known limitation in default ingestion is that ServiceNow often returns system links or IDs (&lt;CODE data-start="1412" data-end="1421"&gt;sys_ids&lt;/CODE&gt;) instead of human-readable values for reference fields like “Owned By” or “Asset.”&lt;/P&gt;
&lt;P data-start="1506" data-end="1531"&gt;To resolve this, you can:&lt;/P&gt;
&lt;H5 data-start="1533" data-end="1548"&gt;XQL Joins:&lt;/H5&gt;
&lt;P data-start="1549" data-end="1667"&gt;Use an XQL query to join the CMDB raw table with the ServiceNow user or asset tables to replace IDs with actual names.&lt;/P&gt;
&lt;H5 data-start="1669" data-end="1689"&gt;API Parameters:&lt;/H5&gt;
&lt;P data-start="1690" data-end="1824"&gt;When using commands in the Playground or Playbooks, use the &lt;CODE data-start="1750" data-end="1778"&gt;sysparm_display_value=true&lt;/CODE&gt; parameter to fetch actual names. For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-[calc(var(--sticky-padding-top)+9*var(--spacing))]"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN class="hljs-punctuation"&gt;!&lt;/SPAN&gt;servicenow-&lt;SPAN class="hljs-keyword"&gt;query&lt;/SPAN&gt;-computers computername&lt;SPAN class="hljs-punctuation"&gt;=&lt;/SPAN&gt;ExampleName systemparams&lt;SPAN class="hljs-punctuation"&gt;=&lt;/SPAN&gt;&lt;SPAN class="hljs-string"&gt;"sysparmdisplayvalue=true;sysparmexcludereference_link=True"&lt;/SPAN&gt; raw-response&lt;SPAN class="hljs-punctuation"&gt;=&lt;/SPAN&gt;&lt;SPAN class="hljs-literal"&gt;true&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;H5 data-start="1980" data-end="1999"&gt;Parsing Rules&lt;/H5&gt;
&lt;P data-start="2000" data-end="2095"&gt;Implement User Defined Parsing Rules to extract specific values from the ingested JSON objects.&lt;/P&gt;
&lt;HR data-start="2097" data-end="2100" /&gt;
&lt;H4 data-start="2102" data-end="2156"&gt;3. Using CMDB Data for Featured Field Configuration:&lt;/H4&gt;
&lt;P data-start="2158" data-end="2401"&gt;Currently, there is no public API endpoint to programmatically add or remove entries from the &lt;STRONG data-start="2252" data-end="2266"&gt;"Featured"&lt;/STRONG&gt; lists (Hosts, Users, IP addresses) within Case Configuration. Managing this list remains a manual process via UI entry or file upload.&lt;/P&gt;
&lt;HR data-start="2403" data-end="2406" /&gt;
&lt;H4 data-start="2408" data-end="2456"&gt;Recommended Alternative: Dynamic Asset Groups:&lt;/H4&gt;
&lt;P data-start="2458" data-end="2563"&gt;Instead of the "Featured" list, use &lt;STRONG data-start="2494" data-end="2518"&gt;Dynamic Asset Groups&lt;/STRONG&gt;, which are designed for this exact use case.&lt;/P&gt;
&lt;H5 data-start="2565" data-end="2588"&gt;Define Attributes:&lt;/H5&gt;
&lt;P data-start="2589" data-end="2726"&gt;Identify the attributes in your ingested CMDB dataset that signify a "critical" status (e.g., a specific tag or a high criticality flag).&lt;/P&gt;
&lt;H5 data-start="2728" data-end="2755"&gt;Create Dynamic Groups:&lt;/H5&gt;
&lt;P data-start="2756" data-end="2850"&gt;Navigate to &lt;STRONG data-start="2768" data-end="2790"&gt;Inventory &amp;gt; Groups&lt;/STRONG&gt; and create a group using filters based on these attributes.&lt;/P&gt;
&lt;H5 data-start="2852" data-end="2869"&gt;Asset Roles:&lt;/H5&gt;
&lt;P data-start="2870" data-end="3025"&gt;You can also use &lt;STRONG data-start="2887" data-end="2916"&gt;Asset Roles Configuration&lt;/STRONG&gt; to classify these critical assets (e.g., "crown jewels"). This improves UEBA precision and incident scoring.&lt;/P&gt;
&lt;H4 data-start="3027" data-end="3053"&gt;Workflow Integration:&lt;/H4&gt;
&lt;P data-start="3054" data-end="3090"&gt;These dynamic groups can be used in:&lt;/P&gt;
&lt;UL data-start="3092" data-end="3375"&gt;
&lt;LI data-start="3092" data-end="3187"&gt;
&lt;P data-start="3094" data-end="3187"&gt;&lt;STRONG data-start="3094" data-end="3132"&gt;Scope-Based Access Control (SBAC):&lt;/STRONG&gt; Restrict or prioritize visibility for specific teams&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3188" data-end="3301"&gt;
&lt;P data-start="3190" data-end="3301"&gt;&lt;STRONG data-start="3190" data-end="3211"&gt;Incident Scoring:&lt;/STRONG&gt; Automatically increase the score of incidents involving assets in your "Critical" group&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="3302" data-end="3375"&gt;
&lt;P data-start="3304" data-end="3375"&gt;&lt;STRONG data-start="3304" data-end="3326"&gt;Scheduled Queries:&lt;/STRONG&gt; Monitor activity specifically for those assets&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="3377" data-end="3550"&gt;To automate the direct mapping of the raw ServiceNow dataset fields to the specific normalized attributes that drive dynamic Asset Groups, configure custom enrichment logic.&lt;/P&gt;
&lt;P data-start="3377" data-end="3550"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="3552" data-end="3733" data-is-last-node="" data-is-only-node=""&gt;If your organization strictly requires automation of the "Featured" list via API, you will need to submit a formal Feature Request (FR) through your Palo Alto Networks account team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 13:29:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248392#M350</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-17T13:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: ServiceNow CMDB  data to XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248577#M351</link>
      <description>&lt;P&gt;Thanks Subashkar. This is really helpful. We have used another one ServiceNow CMDB integration ( pulls the data)&amp;nbsp; instead of&amp;nbsp;Servicenow Event Collector.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 10:07:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1248577#M351</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-02-19T10:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: ServiceNow CMDB  data to XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1249941#M371</link>
      <description>&lt;P&gt;Hi, I have some followup questions on this below points which you have mentioned in the last post. Now i have the CMDB data but i won't be able to call those attributes which says "critical" in Dynamic group creation, becase this attribute is not available in Dynamic group.&amp;nbsp; Can you please provide your thoughts on this.&lt;/P&gt;
&lt;H5 id="toc-hId--217559207" data-end="2588" data-start="2565"&gt;&lt;EM&gt;Define Attributes:&lt;/EM&gt;&lt;/H5&gt;
&lt;P data-end="2726" data-start="2589"&gt;&lt;EM&gt;Identify the attributes in your ingested CMDB dataset that signify a "critical" status (e.g., a specific tag or a high criticality flag).&lt;/EM&gt;&lt;/P&gt;
&lt;H5 id="toc-hId--2025013670" data-end="2755" data-start="2728"&gt;&lt;EM&gt;Create Dynamic Groups:&lt;/EM&gt;&lt;/H5&gt;
&lt;P data-end="2850" data-start="2756"&gt;&lt;EM&gt;Navigate to&amp;nbsp;&lt;STRONG data-end="2790" data-start="2768"&gt;Inventory &amp;gt; Groups&lt;/STRONG&gt;&amp;nbsp;and create a group using filters based on these attribute&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 09:50:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/servicenow-cmdb-data-to-xsiam/m-p/1249941#M371</guid>
      <dc:creator>A.Velusamy</dc:creator>
      <dc:date>2026-03-11T09:50:31Z</dc:date>
    </item>
  </channel>
</rss>

