ServiceNow TISC Import Observables from TISC

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook leverages the ServiceNow TISC API to import IP, Domain, URL, and Hash observables from TISC Workspace to Microsoft ThreatIntelligenceIndicator log analytics table. The imported observables can be seen under the Threat Intelligence tab in Microsoft Sentinel Workspace.

Attribute Value
Type Playbook
Solution ServiceNow TISC
Source View on GitHub

Logic App Connectors

This playbook uses 1 Logic App connector / built-in action:

Connector / Action Type Connections Actions
ServiceNowTISCCustomConnector Custom 1 1
Action parameters (URLs, paths, function IDs)

ServiceNowTISCCustomConnector (Custom)

Action Method Endpoint Other
Import_Observables_in_Indicator_STIX_format_TISC_API post /api/sn_sec_tisc/threat_intel_data/observables_indicator_stix_format

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to ServiceNow TISC