Use email notifications to send selected users email notifications about specific tasks within the application, such as updates to observables/indicators/various other objects.
Role required: admin
Hinweis:
As a System Administrator you can view, create or edit the email notification rule details in the classic view of the application.
Threat Intelligence Security Center provides rules driven email notifications which are sent to individual email addresses or a list of email addresses. Usually, Dissemination of Threat Intel information to internal
users are sent typically in the form of an email. The process involves in delivering the threat intelligence data to users according to their specified format and time lines.
Email notifications allow administrators to specify:
When to send the notification
Who receives the notification
What content is in the notification
Hinweis:
If you want to make changes, then you need to configure whom the email should be sent by modifying the base system rules based on your requirements.
For more information, see Create an email notification section on ServiceNow AI Platform administration documentation.
The following table details the email notification rules that are provisioned in the base system.
Tabelle : 1. Email Notifications
Name
Table
RSS Feeds with Zero Day mention
sn_sec_tisc_rss_feed
High Risk Malicious URL Observable
sn_sec_tisc_url
High Risk Malicious IPV6 Observable
sn_sec_tisc_ipv6_address
Threat Reports with Zero Day mention
sn_sec_tisc_threat_report
High Risk Malicious IPV4 Observable
sn_sec_tisc_ipv4_address
High Risk Malicious SHA512 Observable
sn_sec_tisc_sha512_hash
High Risk Malicious Domain Observable
sn_sec_tisc_domain_name
Notifying on case updation
sn_sec_tisc_case
Abbildung : 1. Email Notifications
Hinweis:
Clicking on each email notification will take you to the classic UI, so that you can take necessary actions such as viewing or editing or creating the notifications.