↳ GitHub sourceSolution

Servicenow

Description

The ServiceNow ITSM solution for Microsoft Sentinel makes it easy to synchronize incidents between Microsoft Sentinel and [ServiceNow IT Service Management (ITSM)](https://www.servicenow.com/products/itsm.html). This can be achieved by either one of the following two options - **Option 1 (Recommended)**: Bi-directional incident sync using app hosted on ServiceNow store. This option includes the following key features: • Retrieve Microsoft Sentinel incidents and automate the creation of incidents in ServiceNow. • Bi-directional sync of Status, Severity, Owner, Comments/Work notes, Entities and alerts. • Details of alerts and entities added to Work Notes, to improve analyst experience. • Filtering of Microsoft Sentinel incidents, based on tags or custom filters. • Support of multiple workspaces, with different incidents filters. • Support any incident custom table, status or severity fields. Please note that this option doesn't require installation of content hub solution and will need to be installed and managed from ServiceNow store. Refer to [ServiceNow Store](https://aka.ms/sentinel-servicenow-appstore) for details on how to use this option. **Option 2**: Unidirectional sync from Microsoft Sentinel to ServiceNow. Install this solution that includes Microsoft Sentinel playbooks to help create, update (incident comments) and close incidents in ServiceNow when a corresponding incident is created, updated or closed in Microsoft Sentinel.
Version
2.0.2
Declared author / publisher
Microsoft - support@microsoft.com
Support tier
Microsoft

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
azure-sentinel-solution-servicenow
Additional source files 2Solutions/Servicenow/Data/Solution_Servicenow.jsonsolution-manifest ↗Solutions/Servicenow/SolutionMetadata.jsonsolution-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.