.png)

ServiceNow Security Operations Integration Guide
Integrate ServiceNow Security Operations with security, vulnerability, threat intelligence, and IT operations systems through REST APIs, configurable outbound calls, imports, and workflows.
ServiceNow Security Operations integration options at a glance
ServiceNow Security Operations is primarily integrated through ServiceNow platform REST APIs, application-specific Security Operations APIs, Table APIs, Import Set APIs, and the Attachment API. ServiceNow also supports SOAP web services for legacy scenarios and can initiate outbound REST calls through REST messages, Flow Designer actions, business rules, notifications, and selected event-driven workflows. These mechanisms do not represent universal webhook coverage; available events depend on the application and instance configuration. Martini can consume ServiceNow JSON or XML APIs, expose REST endpoints for ServiceNow to call, orchestrate polling or inbound workflows, transform security data, and process batch or attachment-based exchanges.
| Integration point | Supported by ServiceNow Security Operations? | Common use cases | How Martini supports it |
|---|---|---|---|
| REST APIs | Yes | Use the Table API, Import Set API, Attachment API, and application-specific Security Operations APIs to create, query, update, enrich, and synchronize security records. Application-specific APIs should be preferred where available. | Martini can consume ServiceNow REST endpoints, expose REST APIs for ServiceNow callbacks, map JSON payloads, apply business rules, and orchestrate reusable workflows. |
| SOAP APIs | Yes | ServiceNow SOAP web services support legacy enterprise consumers and platform access where a consuming system requires SOAP rather than REST. | Martini can consume ServiceNow SOAP services and transform XML responses or requests within workflows. REST is generally preferable for new integrations. |
| Webhooks / outbound callbacks | Limited | ServiceNow can make outbound REST calls or notifications through configured REST messages, Flow Designer actions, business rules, and selected event logic. Coverage is not universal across Security Operations objects. | Martini can expose controlled REST endpoints for ServiceNow to call, validate inbound payloads, correlate events, and invoke downstream workflows. |
| Bulk / async / batch APIs | Limited | Import Set APIs and asynchronous platform processing support higher-volume ingestion of vulnerability findings, indicators, and other security data. Processing behavior varies by application and configuration. | Martini can batch, transform, submit, and reconcile Import Set loads, including handling delayed processing and row-level errors. |
| File / attachment APIs | Yes | The Attachment API supports upload, download, and management of files associated with Security Incidents, Security Cases, Tasks, and other records, subject to permissions and instance configuration. | Martini can retrieve or send attachments through separate API calls, associate them with parent records, and apply file-size, retry, and optional-versus-required rules. |
| Events and change notifications | Limited | Business rules, platform events, notifications, Flow Designer triggers, and outbound integration actions can initiate synchronization for selected record changes and workflow transitions. | Martini can receive configured HTTP notifications or use scheduled polling when event coverage is incomplete. Workflows can filter states, deduplicate events, and retrieve the current record. |
| Authentication | Yes | ServiceNow supports Basic Authentication, OAuth 2.0, and selected mutual TLS or certificate-based architectures. Roles, ACLs, scopes, and application permissions still govern access. | Martini can store credentials securely, configure authenticated API consumption, expose secured APIs, and separate environment-specific authentication settings. |
| Database access | No | Direct external access to the underlying ServiceNow database is not a normal supported integration method. APIs, imports, exports, and approved reporting mechanisms should be used instead. | Martini should integrate through ServiceNow APIs or approved file and export mechanisms rather than attempting direct database access. |
How ServiceNow Security Operations exposes data and business events
ServiceNow REST APIs
ServiceNow REST is the primary integration mechanism for Security Operations. Depending on the release and installed applications, integrations can use the Table API, application-specific APIs, Import Set API, and Attachment API. Exact tables, fields, roles, and paths must be verified in the target instance.
Martini implementation pattern
Martini authenticates to the ServiceNow REST endpoint, retrieves or receives the required resource, maps ServiceNow JSON into a canonical model, applies correlation and business rules, and writes to the target system or back to ServiceNow. Application-specific APIs are preferred where documented; Table API use requires careful handling of ACLs, mandatory fields, and business-rule side effects.
Implementation sequence
ServiceNow outbound REST and callbacks
ServiceNow can initiate outbound REST requests through REST messages, Flow Designer actions, business rules, notifications, and configured integration logic. This provides selected event-driven notification capability rather than universal webhooks for every Security Operations object.
Martini implementation pattern
Martini exposes a secured REST API that ServiceNow can call when a configured record change or workflow transition occurs. The Martini workflow validates the notification, retrieves the current ServiceNow record when the event payload is incomplete, deduplicates the event, and continues downstream processing.
Implementation sequence
ServiceNow Import Set APIs
Import Set APIs and related asynchronous processing support batch-oriented ingestion, including high-volume vulnerability findings and indicators. Processing and validation may occur after submission, and product-specific behavior varies.
Martini implementation pattern
Martini retrieves source findings, normalizes them into the Import Set structure, submits bounded batches, and records the import response. A follow-up workflow can inspect processing results, separate row-level validation errors from transport failures, and retry only safe failures.
Implementation sequence
ServiceNow SOAP APIs
ServiceNow supports SOAP web services for configured tables and platform functionality. SOAP remains relevant for legacy consumers, although REST is generally recommended for new Security Operations integrations.
Martini implementation pattern
Martini consumes the ServiceNow SOAP service, parses XML responses, maps the result into the canonical model, and invokes the same orchestration and error-handling logic used by REST workflows. XML validation and namespace handling are kept separate from business mappings.
Implementation sequence
ServiceNow Attachment API
The Attachment API supports file upload, download, and management for ServiceNow records such as Security Incidents, Security Cases, and Tasks, subject to permissions and instance configuration.
Martini implementation pattern
Martini first resolves the parent ServiceNow record, then transfers the attachment through a separate API call. The workflow can apply size and content rules, retry interrupted transfers, and decide whether an attachment is optional, mandatory, synchronized once, or replaced on source change.
Implementation sequence
Common ServiceNow Security Operations integration patterns
Pattern 1: Synchronize security incidents with a SIEM
When to use this pattern
Use this pattern when ServiceNow Security Operations and a SIEM must share qualifying alerts, investigation context, assignment, and lifecycle state. It supports either configured outbound notifications from ServiceNow or scheduled retrieval when event coverage is incomplete.
Integration direction
Example Mapping
| ServiceNow Security Operations Field | Canonical Field | Target Field |
|---|---|---|
| source_alert_id | externalAlertId | correlation identifier |
| severity | normalizedSeverity | priority |
| assignment_group | owningTeam | assignment group |
| status | lifecycleState | state |
Martini implementation pattern
Martini receives or polls qualifying alerts, normalizes severity and entity data, searches for an existing Security Incident using a stable source identifier, and creates or updates the record. Reverse synchronization returns only approved state changes, while loop prevention, validation, bounded retries, and dead-letter handling protect both systems.
Martini capabilities used
- workflows
- API consumption
- API exposure
- data mapping
- business rules
- error handling
Pattern 2: Ingest vulnerability findings
When to use this pattern
Use this pattern for scheduled or batch ingestion from vulnerability management platforms into ServiceNow Vulnerable Items. It is appropriate when findings must be normalized, deduplicated, associated with assets, and routed for remediation.
Integration direction
Example Mapping
| ServiceNow Security Operations Field | Canonical Field | Target Field |
|---|---|---|
| finding_id | sourceFindingId | external identifier |
| cve | vulnerabilityIdentifier | CVE |
| asset_id | affectedAsset | Configuration Item |
| severity | normalizedSeverity | priority |
Martini implementation pattern
A scheduled Martini workflow retrieves incremental findings with an overlap window, normalizes CVEs, assets, severity, ownership, and due dates, and submits bounded REST or Import Set batches. It persists source-to-ServiceNow relationships, reconciles asynchronous results, retries transient failures, and routes invalid rows for review.
Martini capabilities used
- scheduled workflows
- API consumption
- batch orchestration
- data mapping
- business rules
- error handling
Pattern 3: Enrich and distribute threat indicators
When to use this pattern
Use this pattern when threat intelligence indicators need to be imported into ServiceNow or distributed from ServiceNow to selected security tools. It is useful for coordinating indicator type, confidence, source, and expiration semantics.
Integration direction
Example Mapping
| ServiceNow Security Operations Field | Canonical Field | Target Field |
|---|---|---|
| indicator_value | indicatorValue | indicator |
| indicator_type | indicatorType | type |
| confidence | confidenceScore | confidence |
| expiration | expiresAt | expiration |
Martini implementation pattern
Martini receives or retrieves indicators, validates type-specific formats, normalizes confidence and timestamps, and uses source plus indicator identity for deduplication. It then creates or updates Threat Indicators and optionally distributes selected results downstream, applying expiration and source-authority rules before publication.
Martini capabilities used
- workflows
- API consumption
- data mapping
- validation
- business rules
- error handling
Pattern 4: Coordinate vulnerability remediation with ITSM
When to use this pattern
Use this pattern when a Vulnerable Item or security finding must create or update an ITSM Incident, Change, Problem, or Task while the security record remains the source of risk and compliance context.
Integration direction
Example Mapping
| ServiceNow Security Operations Field | Canonical Field | Target Field |
|---|---|---|
| vulnerable_item_id | securityFindingId | correlation identifier |
| assignment_group | remediationTeam | assignment group |
| due_date | remediationDueDate | planned completion |
| remediation_state | workState | task state |
Martini implementation pattern
Martini evaluates eligible security findings, applies ownership and severity rules, and creates or updates the corresponding ITSM work item. It correlates both records, maps lifecycle transitions explicitly, and prevents conflicting updates by defining which system owns risk state, work state, comments, and assignment.
Martini capabilities used
- workflow orchestration
- API consumption
- data mapping
- business rules
- correlation
- error handling
Applications commonly integrated with ServiceNow Security Operations
ServiceNow Security Operations commonly participates in security operations, vulnerability management, threat intelligence, and remediation workflows. The exact integration scope depends on the licensed ServiceNow applications, installed plugins, release, and configuration.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| Microsoft Sentinel | Exchange security incidents, alerts, entities, investigation context, and response status between the SIEM and ServiceNow workflows. | Microsoft Sentinel → Martini → ServiceNow Security Operations | Martini receives or polls Sentinel alerts, normalizes entities and severity, correlates them with existing ServiceNow Security Incidents, and applies state and assignment rules before creating or updating records. It can return selected ServiceNow status changes to Sentinel while preventing update loops through stable source identifiers. |
| Splunk Enterprise | Send notable events and security alerts to ServiceNow while returning assignment, investigation, or resolution status to Splunk. | Splunk Enterprise → Martini → ServiceNow Security Operations | A Martini workflow consumes selected Splunk events, maps alert context and priority to Security Incidents, performs idempotent upserts, and sends lifecycle updates back to Splunk. Validation, retry, and correlation logic isolate transient API failures from invalid security data. |
| CrowdStrike Falcon | Import endpoint detections, host context, and response information into Security Operations for investigation and coordinated response. | CrowdStrike Falcon → Martini → ServiceNow Security Operations | Martini retrieves or receives selected Falcon detections, maps host and detection identifiers to ServiceNow fields, enriches records where required, and creates or updates Security Incidents or related tasks. The workflow retains the Falcon detection ID for deduplication and controlled status propagation. |
| Tenable | Import vulnerability findings, affected assets, severity, and remediation information into Vulnerability Response. | Tenable → Martini → ServiceNow Security Operations | A scheduled Martini workflow retrieves incremental Tenable findings, normalizes CVE identifiers, assets, severity, and due dates, and loads them through the relevant ServiceNow REST or Import Set API. It records source identifiers and handles row-level import errors separately from transport failures. |
| Qualys | Synchronize vulnerability detections, assets, severity, and remediation status with ServiceNow Vulnerability Response. | Qualys → Martini → ServiceNow Security Operations | Martini polls Qualys using a persisted time window or source cursor, transforms finding and asset data, and upserts ServiceNow Vulnerable Items. Business rules determine whether remediation status is returned to Qualys, while bounded retries handle throttling and transient errors. |
| Microsoft Defender XDR | Create or update ServiceNow security incidents from Defender alerts and synchronize selected investigation or response status. | Microsoft Defender XDR → Martini → ServiceNow Security Operations | Martini receives or retrieves qualifying Defender alerts, maps entities and severity to Security Incidents, and applies correlation and routing rules. A reverse workflow can publish selected ServiceNow state changes after checking the original Defender alert identifier. |
| ServiceNow ITSM | Link Security Operations incidents and vulnerability remediation work to ITSM Incidents, Problems, Changes, and Tasks. | ServiceNow Security Operations → Martini → ServiceNow ITSM | Martini orchestrates cross-application workflows that preserve the security finding as the source record while creating or updating ITSM work items. It maps ownership, priority, assignment, comments, and lifecycle states with explicit rules to prevent conflicting updates. |
| Jira Software | Transfer selected security remediation tasks to engineering teams and return issue status or assignee information. | ServiceNow Security Operations → Martini → Jira Software | Martini selects eligible Security Incident Tasks or remediation records, maps them to Jira issues, stores the Jira key against the ServiceNow source, and synchronizes approved status fields back to ServiceNow. Validation and retry handling distinguish Jira workflow conflicts from temporary transport failures. |
How to build a ServiceNow Security Operations integration in Martini
Objective
Establish authenticated access to the target ServiceNow instance and verify that the integration identity can access the required Security Operations APIs, tables, fields, and related platform objects.
Instructions in Martini
- Choose OAuth 2.0, Basic Authentication, or an approved certificate-based pattern
- Store credentials and environment-specific values in secure configuration
- Use a dedicated integration user with least-privilege roles and scopes
- Verify ACLs, application permissions, domain context, and REST access settings
Objective
Select an event-driven or scheduled initiation method based on the required latency and the actual notification coverage available in the ServiceNow instance.
Instructions in Martini
- Use a configured ServiceNow outbound REST call or notification when selected events are reliable
- Expose a secured Martini REST API for ServiceNow to call
- Use a scheduler for polling when event coverage is incomplete
- Define the authoritative system and state transitions before enabling synchronization
Objective
Receive the event payload or retrieve the complete current ServiceNow resource using bounded queries, pagination, and incremental synchronization boundaries.
Instructions in Martini
- Use application-specific APIs where available
- Use filters such as sys_updated_on, sys_id, state, source, or assignment group
- Persist a cursor, timestamp, or unique identifier between runs
- Use an overlap window for time-based polling and deduplicate results
Objective
Coordinate retrieval, enrichment, validation, transformation, target writes, and outcome recording in a reusable Martini workflow.
Instructions in Martini
- Separate transport, mapping, business rules, and target-write logic
- Branch for create, update, ignore, and exception outcomes
- Retrieve related Users, Groups, Configuration Items, or Tasks only when required
- Keep source identifiers and correlation relationships in the workflow state or persistence layer
Objective
Convert ServiceNow JSON or XML and security-tool payloads into a canonical model that handles differing identifiers, states, severities, timestamps, and ownership values.
Instructions in Martini
- Normalize severity, priority, lifecycle state, indicator type, and time zone
- Map source alert, finding, or indicator identifiers to stable target relationships
- Validate mandatory fields and choice values before submission
- Handle attachments through separate API operations when required
Objective
Apply integration-specific ownership, routing, deduplication, lifecycle, and loop-prevention rules before changing either system.
Instructions in Martini
- Use source identifiers rather than display values for idempotency
- Define which system owns assignment, priority, comments, and lifecycle state
- Prevent updates generated by the integration from re-triggering an infinite loop
- Route ambiguous mappings and invalid records for controlled review
Common ServiceNow Security Operations data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Security Incidents | Create, update, enrich, route, correlate, and synchronize security incidents and their lifecycle state. | Microsoft Sentinel, Splunk Enterprise, Microsoft Defender XDR, ServiceNow ITSM | Martini maps alert context, severity, assignment, comments, and state; stores source identifiers for idempotent upserts and prevents update loops. |
| Security Incident Tasks | Track investigation, response, and remediation work assigned to security teams. | Jira Software, ServiceNow ITSM, engineering workflow systems | Martini applies task eligibility and ownership rules, maps assignments and due dates, and synchronizes approved status changes with retry and validation handling. |
| Vulnerable Items | Represent vulnerability findings, affected configuration items, ownership, priority, remediation state, and due dates. | Tenable, Qualys, ServiceNow ITSM, remediation platforms | Martini normalizes scanner identifiers, CVEs, assets, severity, and dates, then submits records through the relevant REST or Import Set API with row-level reconciliation. |
| Threat Indicators | Store indicators such as IP addresses, domains, hashes, URLs, confidence, source, and expiration context. | Threat intelligence platforms, Microsoft Sentinel, Splunk Enterprise, endpoint security tools | Martini maps indicator types and confidence values, deduplicates using source and indicator identifiers, and distributes selected indicators to downstream tools. |
| Security Cases | Coordinate security investigations and case-level activity where the licensed Security Operations applications provide case management. | SIEM platforms, threat intelligence tools, ServiceNow ITSM | Martini verifies the target instance's case API and fields, maps participants and lifecycle state, and handles related records and attachments separately where required. |
| Security findings and remediation records | Correlate scanner findings with assets, remediation tasks, ownership, and risk status. | Tenable, Qualys, Jira Software, ServiceNow ITSM | Martini normalizes source-specific findings into a canonical model, applies deduplication and prioritization rules, and creates or updates target remediation work. |
Authentication and security considerations
Authentication and authorization
ServiceNow supports Basic Authentication, OAuth 2.0, and selected mutual TLS or certificate-based architectures. Martini can consume authenticated ServiceNow APIs and expose secured REST endpoints for callbacks.
- Use dedicated integration users with least-privilege roles.
- Validate table and field ACLs, OAuth scopes, application permissions, and REST access settings.
- Verify access to related Users, Groups, Configuration Items, Tasks, and domain-separated data.
- Keep credentials, tokens, certificates, and environment values in secure Martini configuration.
Application-specific permissions
Successful authentication does not guarantee authorization. Security Incidents, Vulnerable Items, Threat Indicators, and Security Tasks may require different product-specific roles and permissions.
Operational considerations for ServiceNow Security Operations integrations
Reliability and scale
- Use bounded pagination and incremental filters rather than unbounded ServiceNow queries.
- Persist cursors, timestamps, source identifiers, and ServiceNow sys_id relationships.
- Use overlap windows with deterministic deduplication for time-based polling.
- Control concurrency and apply bounded exponential backoff for throttling or transient failures.
Data and schema behavior
- Separate authentication, authorization, validation, conflict, rate-limit, and server errors.
- Account for mandatory fields, choice values, business rules, assignment rules, notifications, and Flow Designer side effects.
- Reconcile Import Set rows individually when asynchronous processing produces partial results.
- Transfer attachments separately and define size, replacement, and retry behavior.
- Test release, plugin, scoped-application, customization, ACL, and domain-separation changes in a non-production instance.
Why use Martini instead of scripts or point-to-point integrations?
Centralized orchestration
Scripts and point-to-point integrations often duplicate authentication, mapping, retry, correlation, and monitoring logic. Martini provides reusable workflows that can consume ServiceNow APIs, receive configured callbacks, transform security data, apply business rules, and write to multiple systems.
Maintainable integration assets
- Separate API transport from canonical mappings and business rules.
- Reuse workflows for incidents, vulnerability findings, indicators, tasks, and attachments.
- Expose controlled API façades instead of distributing direct ServiceNow access across applications.
- Handle pagination, idempotency, retries, validation, and operational failures consistently.
- Use environment-specific authentication and configuration without hard-coding credentials or endpoints.
Frequently asked questions
ServiceNow Security Operations can be integrated through ServiceNow REST APIs, application-specific APIs, Table and Import Set APIs, the Attachment API, SOAP web services, and selected outbound REST or notification mechanisms. Martini can consume these endpoints, expose APIs for ServiceNow callbacks, orchestrate scheduled synchronization, transform JSON or XML, and coordinate writes to security and IT systems.
Yes. Martini can integrate with ServiceNow Security Operations through its confirmed REST, SOAP, Import Set, Attachment, authentication, and configurable outbound integration mechanisms. The exact tables, APIs, roles, and fields must be verified for the target ServiceNow release, licensed modules, and instance configuration.
No. A dedicated ServiceNow Security Operations connector is not required. Martini can use ServiceNow's native REST or SOAP APIs, Import Set and Attachment APIs, and configured outbound REST or notification mechanisms, while exposing secured Martini REST APIs when ServiceNow needs to call a workflow.
Lonti does not charge an additional per-connector or per-vendor fee to integrate ServiceNow Security Operations. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from ServiceNow, cloud infrastructure, or other third-party systems depending on subscription, usage, and deployment model.
REST APIs are generally the preferred method, with application-specific Security Operations APIs used where available and the Table API used only when its schema, ACLs, mandatory fields, and side effects are understood. Import Set APIs are relevant for higher-volume ingestion, SOAP is mainly for legacy requirements, and the Attachment API handles files separately.
ServiceNow supports selected, configurable event and outbound-notification patterns through business rules, Flow Designer triggers, platform events, notifications, and outbound REST messages. This is not universal webhook coverage for every Security Operations object. Martini can receive configured HTTP requests or poll REST APIs when notification coverage is incomplete.
Synchronization can use outbound notifications, scheduled polling, filters such as sys_updated_on, states, or sys_id, and bounded pagination. Martini can persist source identifiers and ServiceNow sys_id relationships, use overlap windows for delayed updates, and apply idempotent upserts rather than relying on display names, short descriptions, or incident text.
Yes. Martini can expose a secured REST API that provides a controlled interface for ServiceNow or other systems. The façade can validate requests, hide downstream complexity, apply authorization and business rules, transform payloads, invoke workflows, and return a consistent response while the underlying ServiceNow APIs remain protected.
Related Martini documentation
APIs
Transformation
Operations
Integrate ServiceNow Security Operations with Martini
Use Martini to build maintainable ServiceNow Security Operations integrations across REST APIs, configurable callbacks, batch imports, attachments, security tools, and IT workflows.