---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure the MISP integration for Security Operations

# Install and configure the MISP integration for Security Operations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start
investigating security incidents using the MISP data.

## Before you begin

Ensure that you've installed the valid SSL certificates on the MISP server.

Role required: sn_si.admin

## Procedure

1. Download the MISP integration for Security Operations from the ServiceNow Store and install it.
2. Navigate to Security OperationsIntegrationsIntegration Configurations.
3. Search for the MISP -SIR/TI Integration tile and click Configure.
4. On the form, fill in the fields.  
   {#install-and-configure-misp__table_kyc_qbg_pa1__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the MISP instance configuration. |
   | MISP Server URL | URL for the MISP server that serves as the REST endpoint for the MISP server. |
   | API Key | API key that is configured for your user account on the MISP server. The API key corresponds to the Authkey in the MISP server. |
   | On Premises Deployment | Option that you can select if your MISP server is deployed in an on-premise instance. When you select the On Premises Deployment option, you must use the MID Server to connect to the MISP server. |
   | MID Application | String field that identifies the MID Application name that is used to communicate with MISP. This field is required when you select the On Premises Deployment option. For information on how to configure the MID server for your application, see [Configure a MID Server for each application](https://www.servicenow.com/docs/access?context=t_SpecifyMIDServerApplications&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US) |
   [Table 1. MISP - SIR/TI Integration Configuration form]

   {#install-and-configure-misp__table_kyc_qbg_pa1}
5. Click Submit.

## Result

After you successfully validate and submit the configuration, the MISP - SIR/TI Integration is saved on the Security Integrations page as a tile.
**Related concepts**   

* [MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag "You can review the MISP event data so that you can see detailed information about the MISP events.")
* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w "Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.")
* [Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg "Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.")
* [Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile "Configure the ServiceNow AI Platform to automatically create events in MISP.")  
**Related reference**   

* [Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og "Review the following information before you set up your MISP integration for Security Operations.")
* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


