---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get Network Statistics flow

# Security Incident Response- Get Network Statistics flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Incident ResponseGet Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.

## Before you begin

Role required: sn_si.analyst

## About this task

For new security incidents that contain configuration items, the flow runs automatically when the state changes to Analysis.

Existing security incidents are automatically updated when you are in the
Analysis state and you add a new configuration item.
Figure 1. Get Network Statistics  
The flow process actions include:

* [Get Configuration Item FQDN Flow Action](https://servicenow-prod.fluidtopics.net/7GZL7Gz2ajrpPq5qbM14cA "The Security Common Orchestration > Get Configuration Item FQDN flow action retrieves the fully qualified domain name (FQDN) of a configuration item. This flow action can accelerate the investigation and remediation process.")
* Determine Shell Script by OS
* If statement is executed by Powershell
* [Legacy: Execution Tracking - Begin Flow Action](https://servicenow-prod.fluidtopics.net/f7TxzucZqzu26uA35DrhKQ "The Execution Tracking - Begin flow action starts the auditing process for a Security Operations Integration flow that operates on observables.")
* [Get Network Statistics via netstat Flow Action](https://servicenow-prod.fluidtopics.net/adZ~9zbxSoJC2pp_Y_VY4g "The Security Common Orchestration - Get Network Statistics via netstat flow action retrieves the network statistics for an affected resource on a Windows-based system. This flow action can accelerate the investigation and remediation process.")
* [Legacy: Capability Execution Tracking- Failure Flow Action](https://servicenow-prod.fluidtopics.net/C3BSyydAkhR9MTCoL9oX5A "The Capability Execution Tracking - Failure flow action records a failure to the audit record.")
* [Create Enrichment Data records Flow Action](https://servicenow-prod.fluidtopics.net/h3kXRsAWR1dhXEvLPyb4AA "The Create enrichment data records flow action creates or updates enrichment records to use in the flow.")
* [Legacy: Capability Execution Tracking- Failure Flow Action](https://servicenow-prod.fluidtopics.net/C3BSyydAkhR9MTCoL9oX5A "The Capability Execution Tracking - Failure flow action records a failure to the audit record.") - Returns enrichment ID.
* [Legacy: Capability Execution Tracking - Complete Flow Action](https://servicenow-prod.fluidtopics.net/hi~3oNvz8X_cfiTlXQAn2w "The Capability Execution Tracking - Complete flow action updates the audit record when the flow is complete.")

## Procedure

1. Open a security incident.
2. Update the State to Analysis, if necessary.
3. Add a configuration item (computer, server, or similar).
4. Click Update.  
   Security Incident Response Orchestration provides network statistics information in the Related LinksSecurity Incident Enrichments tab. For more information see, [Security Operations enrichment data mapping](https://servicenow-prod.fluidtopics.net/tQ0eKbOQeuPSLf~YhSyydw "Enrichment Data Mapping transforms data from XML, JSON, or Properties files to ServiceNow records. Security Operations workflows use enrichment data maps and provide output data to security incidents.").

   Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
{#obtain-network-statistics-workflow__steps_skz_r1t_5v}
**Related concepts**   

* [Run procdump flow](https://servicenow-prod.fluidtopics.net/aGD1CMxnZpthCSQW8buCTg "The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.")  
**Related tasks**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/swGPjdmlpa4BbNNdveRajg "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

*[\>]: and then


