---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automatic security incident observable log data enrichment

# Automatic security incident observable log data enrichment {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

When certain applications and integrations are set up, including Threat Intelligence and the Palo Alto Networks - Firewall integration, observables
information in a security incident can be automatically enriched with threat log data whenever
the Source IP for its observables is modified.

When a modification occurs, a business rule initiates a workflow that retrieves data from
threat logs on your firewall and enriches the observables information in the security
incident.  
Before observables can be enriched, the following steps must be performed.

* [Threat Intelligence](https://servicenow-prod.fluidtopics.net/sfMp70weBwCOyElcZDpN_w#install-threat-lp5 "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store.") must be activated.
* The [Palo Alto Networks Firewall](https://servicenow-prod.fluidtopics.net/qdiEJnWFPhIHMmvLRbwv1g "The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - Firewall. Before you can use the Palo Alto Networks - Firewall, you must download it from the ServiceNow Store.") integration must be activated and configured. This can also include [Set up SSH credentials to the MID Server](https://servicenow-prod.fluidtopics.net/ompX~qZIwS3ijWV54pY3KQ "Palo Alto Networks Firewall sends API calls to the MID Server. As such, ensure that SSH credentials have been created for the MID Server.").
{#si-observ-data-enrich__ul_rfj_ytx_1x}

After that setup has been completed, the act of changing the Source IP of observables
associated with a security incident causes a business rule to execute the Security Operations Palo Alto Networks - Get Log Data workflow. Workflow activities queue up
a search query on the firewall and return a Job ID that is used to retrieve threat logs data from
the firewall and attach them as an XML file to the security incident.
**Tarefas relacionadas**   

* [Get AutoFocus Session Info Enrichment Flow](https://servicenow-prod.fluidtopics.net/iUZlNNZ6v2WiIdNklxv73w#search-for-malicious-content "When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.")
* [Palo Alto Networks Firewall Launcher Workflow](https://servicenow-prod.fluidtopics.net/Atip0YPx7ceKsxpm3OukkA "Security Operations Integration Palo Alto Networks Firewall Launcher workflow is the Palo Alto Networks Firewall implementation launched by the Security Operations Integration - Block Request capability workflow.")
* [Security Operations Palo Alto Networks - Check and Block Value Workflow](https://servicenow-prod.fluidtopics.net/3mCof37K0PQL9tmNZyUfmw#check-and-block-values "As security incidents are created and triaged to identify potential threats, you can use the Security Operations Palo Alto Networks - Check and Block Value workflow to automatically check and update IP addresses, URLs, and domains using External Dynamic Lists defined in Palo Alto Networks - Firewall.")
* [Get Log Data Flow](https://servicenow-prod.fluidtopics.net/K7SGNJRBz8rGHFXpW5YoSA#get-threat-log-data "If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.")
* [Get WildFire Data Enrichment Flow](https://servicenow-prod.fluidtopics.net/rs4tU6nuJ4ILBxlVG2pP8A#enrich-wildfire-data "When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.")

