---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MISP administration

# MISP administration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can set up MISP integration in the ServiceNow AI Platform to perform
a sighting search, observable enrichment, and to create and update events in MISP.
* **[Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og)**   
  Review the following information before you set up your MISP integration for Security Operations.
* **[Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A)**   
  Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.
* **[Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w)**   
  Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.
* **[Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg)**   
  Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.
* **[Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile)**   
  Configure the ServiceNow AI Platform to automatically create events in MISP.
* **[MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag)**   
  You can review the MISP event data so that you can see detailed information about the MISP events.
* **[Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ)**   
  You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.
* **[MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w)**   
  You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.
* **[Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw)**   
  Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.
* **[Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw)**   
  This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.

**Related concepts**   

* [Using MISP to investigate and analyze threats](https://servicenow-prod.fluidtopics.net/QK06OJh2T2VgChDVp6ldYQ "You can use the MISP data across the ServiceNow AI Platform Threat Intelligence module and the ServiceNow AI Platform SIR module to investigate and analyze threats to your organization.")

