How to automate ServiceNow incident creation in Cortex
Prerequisites
Before getting started:- Create the following secrets in Cortex:
- A ServiceNow access token named
servicenow_token - A token for name of your ServiceNow domain named
servicenow_domain
- A ServiceNow access token named
- You must have the
Edit Workflowspermission to create the Workflow, and theExecute Workflow runspermission to run it.
Step 1: Create the Workflow
You can create a Workflow in the Cortex UI or via the Cortex CLI.- Cortex CLI
- Cortex UI
Add the Workflow via CLI
You can use the Cortex CLI to add the example Workflow to your workspace. This allows you to quickly set up the example configuration then iterate on it for your own use case. Expand the tile below to learn more:Import the Workflow via CLI
Import the Workflow via CLI
- Save the Workflow example YAML file below:
- Use the Cortex CLI to run this command, using the path to your Workflow YAML file:
cortex workflows create -f <path-to-your-workflow.yaml>
Step 2: Run the Workflow
- In the list of Workflows, locate the “Create ServiceNow incident” Workflow and click Run.
- The Workflow pauses to collect a response from the user during the User Input block. The user enters a short description, description, severity, urgency, and impact.
- The HTTP Request block runs, which obtains the ServiceNow Sys_ID of the user who initiated the Workflow in Cortex.
- The Data transformation blocks run, transforming the data to get the Sys_ID of the service and its entity descriptor from Cortex.
- In the final HTTP Request block, it sends a payload to the ServiceNow API including the information entered by the user during the first step, and the data that was pulled from the SysID and entity descriptor. An incident is opened in ServiceNow.
Install Cortex’s ServiceNow Incidents plugin
To further highlight visibility of ServiceNow incidents in Cortex, you can also install the ServiceNow Incidents plugin. After installing, you can view incidents within a ServiceNow tab directly on an entity’s details page: