---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Getting started with MISP integration for Security Operations

# Getting started with MISP integration for Security Operations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Review the following information before you set up your MISP integration for Security Operations.
{#get-started-with-misp-integration-for-security-operations__table_k2d_1bk_ynb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform, Threat Intelligence, and Security Incident Response roles. | The following roles are used across the MISP features on the ServiceNow AI Platform: * The administrator (admin) installs the applications from the ServiceNow Store and assigns the security incident administrator (sn_si.admin) and threat intelligence administrator (sn_ti.admin) roles. * sn_si.admin and sn_ti.admin can configure the integration and set up the automatic MISP event creation profiles. * sn_sec_misp.write - The MISP analyst role has read and write permissions for MISP data that includes the event and attribute data. {#get-started-with-misp-integration-for-security-operations__ul_qrb_3ck_ynb} For more information, see [Setup Threat Intelligence](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#c_GetStartedWithThreatIntel "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source."). |
| Assign the required MISP user roles. | [Review the MISP user roles and the permissions required to use the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/2KlTp_H05hz5YKtE5U7caw "Review the user roles that are required in the MISP integration for Security Operations integration."). Note: For more information about the user roles in MISP, see the Roles section in the [MISP documentation website](https://www.circl.lu/doc/misp/administration/#roles). |
| Verify that you are using MISP version 2.4.137 or later. | The MISP integration for Security Operations is tested with a minimum [MISP version 2.4.137](https://www.misp-project.org/2021/01/20/MISP.2.4.137.released.html). |
| Verify that the ServiceNow core applications that are required to support the MISP module are installed and activated. | Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. * Security Incident Response * ServiceNow IntegrationHub Runtime (com.glide.hub.integration.runtime) * ServiceNow IntegrationHub Action Step - REST (com.glide.hub.action_step.rest) {#get-started-with-misp-integration-for-security-operations__ul_jyq_3bk_ynb} For more information on setting up your ServiceNow AI Platform instance for the integration, see [get entitlement for a Security Operations product](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") or application and [activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
| Domain separation | Verify the [domain separation section](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.") if you intend to separate data, processes, and administrative tasks. |
[Table 1. Checklist]

{#get-started-with-misp-integration-for-security-operations__table_k2d_1bk_ynb}
* **[MISP user roles and permissions](https://servicenow-prod.fluidtopics.net/2KlTp_H05hz5YKtE5U7caw)**   
  Review the user roles that are required in the MISP integration for Security Operations integration.

**Related concepts**   

* [MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag "You can review the MISP event data so that you can see detailed information about the MISP events.")
* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A "Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.")
* [Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w "Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.")
* [Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg "Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.")
* [Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile "Configure the ServiceNow AI Platform to automatically create events in MISP.")  
**Related reference**   

* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

