---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MISP event data

# MISP event data {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

You can review the MISP event data so that you can see detailed
information about the MISP events.

## MISP event data in the list view {#misp-event-data__section_qj5_tfk_mqb}

Access the list view from MISPMISP Event Data.

Use the list view to get a quick overview of the MISP event data.
{#misp-event-data__table_bw5_bgk_mqb__entry__2}

| Field | Description |
|-|-|
| Event ID | Event ID that is assigned by MISP when the event was first created or imported into the MISP server. |
| Info | Short description of the event. |
| Analysis | Current stage of the analysis for the event with the following possible options: * Initial: The analysis is just beginning * Ongoing: The analysis is in progress * Completed: The analysis is complete {#misp-event-data__ul_asl_lgk_mqb} |
| Threat Level | Risk level of the event. Incidents can be categorized into three different threat categories (low, medium, high). This field can be left as undefined. The following are the options: * Low: General mass malware * Medium: Advanced Persistent Threats (APT) * High: Sophisticated APTs and 0-day attacks {#misp-event-data__ul_bmb_lgk_mqb} |
| MISP Tags | Tags that are associated with the MISP event. |
| MISP Galaxies | Galaxies that are associated with the MISP event. |
| Owner Org | Organization that owns the event on the MISP instance. This field is visible only to administrators. |
| Creator Org | Organization that created the event on the MISP instance. |
| Distribution | Distribution of the individual attribute. An attribute can have a different distribution level than the event. |
| MISP Event Hyperlink | Link to the MISP event that is stored on the MISP server. |
| MISP Source | MISP source where the event is created. |
[Table 1. MISP Events list view]

{#misp-event-data__table_bw5_bgk_mqb}

## MISP event data in the form view {#misp-event-data__section_m1z_23k_mqb}

Use the form view to get detailed information about the MISP events.
{#misp-event-data__table_ffz_j3k_mqb__entry__2}

| Field | Description |
|-|-|
| Event ID | Event ID that is assigned by MISP when the event was first created or imported into the MISP server. |
| UUID | ID that uniquely identifies events and attributes. |
| Creator Org | Organization that created the event on the MISP instance. |
| Owner Org | Organization that owns the event on the MISP instance. This field is visible only to administrators. |
| Creator User | User who created the event in MISP. |
| Last Change | Date that the event was last modified. |
| MISP Source | MISP source where the event is created. |
| Created date (in MISP) | Date that the event was created or first imported in the MISP server. |
| Threat Level | Risk level of the event. Incidents can be categorized into three different threat categories (low, medium, high). This field can be left as undefined. The following are the options: * Low: General mass malware * Medium: Advanced Persistent Threats (APT) * High: Sophisticated APTs and 0-day attacks {#misp-event-data__ul_mpb_x3k_mqb} |
| Analysis | Current stage of the analysis for the event with the following possible options: * Initial: The analysis is just beginning * Ongoing: The analysis is in progress * Completed: The analysis is complete {#misp-event-data__ul_mzn_x3k_mqb} |
| Distribution | Distribution of the individual attribute. An attribute can have a different distribution level than the event. |
| Published | Status of whether the event has been published or not. Publishing allows the attributes of the event to be used for all eligible exports and notifies users that have subscribed to the event alerts. |
| MISP Event Hyperlink | Link to the MISP event that is stored on the MISP server. |
| Info | Short description of the event. |
| Tags (Local) | Tags that are available on the host organization's MISP instance to enable tagging for synchronization and export filtering. MISP events are not modified when you use local tags. Local tags are always stripped before being synchronized with other MISP instances and sharing communities. |
| Tags (Global) | Tags that are available globally to be shared and synchronized with other MISP instances and sharing communities. When you add global tags to MISP instances, you can modify events. |
| Galaxies (Local) | Galaxies that are available on the host organization's MISP instance for synchronization and export filtering. MISP events are not modified when you use local galaxies. These local galaxies are always stripped before being synchronized with other MISP instances and sharing communities. |
| Galaxies (Global) | Galaxies that are available globally to be shared and synchronized with other MISP instances and sharing communities. When you add global galaxies, MISP you can modify events. |
[Table 2. MISP Event form view]

{#misp-event-data__table_ffz_j3k_mqb}
**Related concepts**   

* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A "Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.")
* [Review the MISP integration settings](https://servicenow-prod.fluidtopics.net/QxVygHLr4q6T8yd6jye~0w "Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.")
* [Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg "Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.")
* [Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile "Configure the ServiceNow AI Platform to automatically create events in MISP.")  
**Related reference**   

* [Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og "Review the following information before you set up your MISP integration for Security Operations.")
* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


