{
  "Name": "Servicenow",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Azure_Sentinel.svg\"width=\"75px\"height=\"75px\">",
  "Description": "The ServiceNow ITSM solution for Microsoft Sentinel makes it easy to synchronize incidents between Microsoft Sentinel and [ServiceNow IT Service Management (ITSM)](https://www.servicenow.com/products/itsm.html). This can be achieved by either one of the following two options - \n\n**Option 1 (Recommended)**: Bi-directional incident sync using app hosted on ServiceNow store. This option includes the following key features:\n\n•\t\tRetrieve Microsoft Sentinel incidents and automate the creation of incidents in ServiceNow.\n\n•\tBi-directional sync of Status, Severity, Owner, Comments/Work notes, Entities and alerts.\n\n•\tDetails of alerts and entities added to Work Notes, to improve analyst experience.\n\n•\tFiltering of Microsoft Sentinel incidents, based on tags or custom filters.\n\n•\tSupport of multiple workspaces, with different incidents filters.\n\n•\tSupport any incident  custom table, status or severity fields.\n\nPlease note that this option doesn't require installation of content hub solution and will need to be installed and managed from ServiceNow store. Refer to [ServiceNow Store](https://aka.ms/sentinel-servicenow-appstore) for details on how to use this option.\n\n**Option 2**: Unidirectional sync from Microsoft Sentinel to ServiceNow. Install this solution that includes Microsoft Sentinel playbooks to help create, update (incident comments) and close incidents in ServiceNow when a corresponding incident is created, updated or closed in Microsoft Sentinel.",
  "Playbooks": [
    "Playbooks/Create-ServiceNow-record/alert-trigger/azuredeploy.json",
    "Playbooks/Create-ServiceNow-record/incident-trigger/azuredeploy.json",
    "Playbooks/ServiceNow-CreateAndUpdateIncident/azuredeploy.json"
  ],
  "Metadata": "SolutionMetadata.json",
  "BasePath": "C:\\Sentinel-Repos\\19.05.22\\Azure-Sentinel\\Solutions\\Servicenow",
  "Version": "2.0.2",
  "TemplateSpec": true
}