Prisma Cloud: How to Auto create a new ServiceNow incident when Alert state changes from Resolved to Open
4102
Created On 07/13/22 17:43 PM - Last Modified 04/17/24 19:23 PM
Objective
If a policy has already triggered an open alert that gets resolved, then this existing alert will not retrigger into ServiceNow. Unless you configure it to do so through the notification template.
Also, Prisma cloud will not import previously opened alerts into ServiceNow as new incidents.
Environment
- Prisma Cloud
- Integration- ServiceNow
Procedure
- Checkbox- Auto create a new ServiceNow incident when Alert state changes from Resolved to Open. The same alert ID will trigger a new incident in ServiceNow once this box is checked.
GUI Path: Settings > Integrations & Notifications > Add Notification Template > Add Template Details
- Make sure your notification template is attached to an alert rule.
GUI Path: Alerts > Add Alert Rule > Step 4. Configure Notifications > Add ServiceNow template
Additional Information
How to integrate ServiceNow with Prisma Cloud documentation here.