---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure how an automatic event is created

# Configure how an automatic event is created {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read

Configure the ServiceNow AI Platform to automatically create events in MISP.

## Before you begin

* [Review the MISP user role and permissions](https://servicenow-prod.fluidtopics.net/2KlTp_H05hz5YKtE5U7caw "Review the user roles that are required in the MISP integration for Security Operations integration.") that are required for using the MISP bi-directional features.
* Role required: sn_si.admin, sn_ti.admin
{#configure-automatic-event-creation-profile__ul_pld_fts_mqb}

## Procedure

1. Navigate to AllMISP IntegrationAutomatic Event Creation Profiles.
2. Click New.
3. On the form, fill in the fields.  
   {#configure-automatic-event-creation-profile__table_tzj_2ls_lqb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the automatic event creation profile. |
   | Description | Brief description about the profile. A more detailed description is shared through the attributes in the next stage of the event's creation. |
   | Order | Order of the profile when triggering conditions are met. The default is 100. Leave this setting at the default. If you create multiple profiles, this value provides a run-time execution priority when two or more profiles share triggering conditions. The profile with the lowest number has the highest priority. |
   | Source | MISP source for the event creation. |
   | Active | Option that indicates if the profile is active or inactive. The option is cleared by default to indicate that the profile is turned off. This profile is not active until you complete all the profile configuration steps and click Finish. |
   [Table 1. Name form]

   {#configure-automatic-event-creation-profile__table_tzj_2ls_lqb}
4. Click Continue.
**Related concepts**   

* [MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag "You can review the MISP event data so that you can see detailed information about the MISP events.")
* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A "Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.")
* [Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w "Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.")
* [Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg "Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.")  
**Related reference**   

* [Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og "Review the following information before you set up your MISP integration for Security Operations.")
* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

## Configure event trigger conditions {#ariaid-title2}

Configure the event trigger conditions in the ServiceNow AI Platform so that you can
automatically trigger an event in MISP when the conditions are
met.

### Before you begin

Role required: sn_sec_misp.write

### Procedure

1. On the Trigger Conditions form, fill in the details that can trigger an event.  
   You can build a compound logic by providing the trigger conditions that are based on security incident fields or observable fields. You can also create events in MISP if observables don't have a corresponding event in MISP. You can choose to build a compound logic by using a combination of the three trigger conditions - Trigger based on security incident fields, Trigger based on observable fields, and Create MISP event, if an observable doesn't have corresponding events in MISP. If you select multiple triggers, you can join them by using the AND condition. Consider creating a profile with new conditions if you must use the OR condition.{#event-trigger-conditions__table_bkc_wps_lqb__entry__2}

   | Field | Description |
   |-|-|
   | Trigger based on security incident fields | MISP event that you can create if all the security incident trigger conditions are met. |
   | Security Incident Trigger Conditions | Filters in the first row that you can set by using the lists and fields of the conditions builder. To add more conditions, click AND or OR. If AND is selected, all conditions must be matched. If OR is selected, either condition can be matched. To set a second filter condition, click New Criteria. |
   | Trigger based on observable fields | MISP event that you can create if all the observable trigger conditions are met. |
   | Observable Trigger Conditions | Filters in the first row that you can set by using the lists and fields of the conditions builder. To add more conditions, click AND or OR. If AND is selected, all conditions must be matched. If OR is selected, either condition can be matched. To set a second filter condition, click New Criteria. |
   | Create MISP event if observable doesn't have corresponding events in MISP | MISP event that you can create if an observable doesn't have corresponding events in MISP. |
   [Table 2. Event Trigger Conditions form]

   {#event-trigger-conditions__table_bkc_wps_lqb} Figure 1. Event trigger conditions

   The following example shows the event trigger conditions as you set up
   the MISP event creation profile.
2. Click Continue.

## Map the MISP event fields {#ariaid-title3}

Map the MISP event fields in the ServiceNow AI Platform so that
security incident information is available when MISP events are
created.

### Before you begin

Role required: sn_sec_misp.write

### Procedure

1. On the form, fill in the fields.  
   {#default-misp-event-field-mapping__table_lk1_5ss_lqb__entry__2}

   | Field | Description |
   |-|-|
   | Event Info | Event information that is automatically created from the ServiceNow AI Platform Security Incident Response. The Event Info field supports substitution variables by using $⁠{SIR FIELD LABEL}$. During an event creation, these variables are replaced with the actual security incident field values. The ${URL}$ substitution variable is replaced with the URL of the security incident. |
   | Distribution | Option that controls who can view this event after the event is published. This option also controls whether the event is synchronized to other servers. The distribution is inherited by the attributes, and the most restrictive setting wins. The distribution options are as follows: * Your organization only: Enables only members of your organization to view this event. The event can be pulled to another instance by one of your organization members where only your organization can have the access to view it. Events with this setting are not synchronized. * This community only: Enables users that are part of your MISP community to view the event, including your own organization, organizations on this MISP server, and organizations that run MISP servers that synchronize with this server. Any other organizations that connect to your linked servers are restricted from viewing the event. * Connected communities: Enables users that are part of your MISP community to view the event including all organizations on this MISP server, all organizations on the MISP servers that synchronize with this server, and the hosting organizations of servers that connect to any server that is two hops away. Any other organizations that are connected to the linked servers that are two hops away are restricted from viewing the event. * All communities: Shares the event with all MISP communities. {#default-misp-event-field-mapping__ul_w43_mts_lqb} |
   | Threat Level | Field that indicates the risk level of the event. You can categorize incidents into three different threat categories (low, medium, high). This field can also be left as undefined. The following are the options: * Low: General mass malware * Medium: Advanced Persistent Threats (APT) * High: Sophisticated APTs and 0-day attacks {#default-misp-event-field-mapping__ul_bvr_cts_lqb} |
   | Analysis Status | Current stage of the analysis for the event, with the following possible options: * Initial: The analysis is just beginning * Ongoing: The analysis is in progress * Completed: The analysis is complete {#default-misp-event-field-mapping__ul_ayc_zss_lqb} |
   [Table 3. Default MISP Event field mapping form]

   {#default-misp-event-field-mapping__table_lk1_5ss_lqb}  
   The following example shows the form that you can use to create an event in MISP.Figure 2. Default MISP Event field mapping
2. Click Continue.

## Map or associate SIR observables as attributes to MISP events {#ariaid-title4}

Map the Security Incident Response observable types to the MISP
attribute types because the MISP attribute types and the SIR observables may be different.

### Before you begin

Role required: sn_sec_misp.write

### About this task

The MISP integration for Security Operations provides a base system mapping that you use
when you add SIR observables as attributes to a MISP event.

You can choose to modify the base system mapping to suit your environment. For
example, you can map multiple SIR observables to only
one MISP attribute type. If any observable types are not mapped, the
other
MISP attribute type is selected by default.

### Procedure

1. On the Additional Options form, map the SIR observable and MISP attribute types.
2. Map the Security Incident Response observable types to the MISP attribute types as described in the following table.  
   {#sir-observable-and-misp-attribute-type-mapping__table_okz_5ws_lqb__entry__2}

   | Field | Description |
   |-|-|
   | Add all associated observables as attributes | Option that you enable to add available observables in a security incident to a MISP event as attributes. This option enables the mapping in the Observable Type to Attribute Type Mapping section. |
   | Observable Type To Attribute Type Mapping | Option to map the SIR observable types to the MISP attribute types. For example, you can map the CVE Number in SIR to the vulnerability attribute in MISP. You can add a SIR observable type to only one MISP attribute type. The base system provides a mapping of the SIR observable types to the MISP attribute types. If any SIR observable types are not mapped to a MISP attribute type, then the observable is mapped to the other attribute type in MISP. To add a new mapping, click Add Observable Type, search for the SIR observable type, and then map to the corresponding MISP attribute type. Click the Remove Mapping icon ![Remove mapping.]() to remove the SIR and MISP attribute mapping association. Note: For more information on MISP attribute types, see the [MISP documentation](https://www.circl.lu/doc/misp/categories-and-types/#types). |
   | Filter observables based on security tags | Option to filter the observables based on the selected security tags. Security tags: Add tags to filter the observables. For example, if you are adding a tag called 'Block from sharing' or 'TLP: White' then if one of the observables has any of these tags associated then these observables will not be added as an attribute to the MISP event during the MISP event creation. |
   | Set attribute IDS flag when observable finding is malicious | Option that lets you know that if an observable is marked as malicious in SIR, then the corresponding attribute in MISP has the IDS flag enabled. If the IDS flag is not set, the attribute is considered as contextual information and is not used for automatic intrusion detection. |
   [Table 4. SIR observable and MISP attribute type mapping]

   {#sir-observable-and-misp-attribute-type-mapping__table_okz_5ws_lqb}

   The following example shows how to navigate to the additional options
   page. On this page, you can enable the SIR observables and MISP attribute
   types mapping, add new SIR observable types,
   such as the IPV6 network and IPV4 network, and map it to the MISP attribute type domain IP address.
   Figure 3. Mapping SIR observables and MISP attribute types

## Synchronize MITRE-ATT\&CK information to MISP events {#ariaid-title5}

Synchronize the MITRE-ATT\&CK information with MISP
attributes for better security incident and threat analysis.

### Before you begin

Role required: sn_sec_misp.write

### Procedure

On the Additional Options form, review the options to synchronize the MITRE-ATT\&CK information with the MISP attributes.  
{#sync-mitre-att-ck-information-to-misp-events__table_l3g_c1t_mqb__entry__2}

| Field | Description |
|-|-|
| Sync Security Incident MITRE-ATT\&CK™ techniques as local galaxies to MISP event | Option to synchronize the ServiceNow AI Platform SIR security incident MITRE-ATT\&CK™ techniques as local galaxies in the MISP event. Note: To add local galaxies, the user who has configured the integration should belong to the host organization of the corresponding MISP server. |
| Sync Security Incident MITRE-ATT\&CK™ techniques as global galaxies to MISP event | Option to synchronize the ServiceNow AI Platform SIR security incident MITRE-ATT\&CK™ techniques as global galaxies in the MISP event. |
[Table 5. Advanced Options form]

{#sync-mitre-att-ck-information-to-misp-events__table_l3g_c1t_mqb}

### Result

You created a profile that enables you to automatically create events in MISP from the ServiceNow AI Platform. You can now view the events in the Associated MISP Events related list.

## Add MISP tags to events {#ariaid-title6}

Add MISP tags to the created MISP events.

### Before you begin

Role required: sn_sec_misp.write

### Procedure

1. On the Additional Options form, navigate to Select MISP tags to add to the event section on the form view.
2. Review the options to add tags to the created events.  
   {#misp-event-tags__table_l3g_c1t_mqb__entry__2}

   | Field | Description |
   |-|-|
   | Add tags to the created MISP event | Option that allows you to automatically add MISP tags to the events that are created from ServiceNow. |
   | Tags (Local) | The selected tags will be added as local tags to the MISP event. |
   | Tags (Global) | The selected tags will be added as global tags to the MISP event. |
   [Table 6. Advanced Options form]

   {#misp-event-tags__table_l3g_c1t_mqb}
3. Click Save.
{#misp-event-tags__steps_pmf_2c2_2cc}

### Result

Adding MISP tags helps in classification of the event.

*[\>]: and then


