---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Review the MISP integration settings

# Review the MISP integration settings {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Review the MISP integration for Security Operations settings and modify the default system
properties to suit your environment.

## Before you begin

Role required: sn_si.admin, sn_ti.admin

## Procedure

1. Navigate to AllMISP IntegrationIntegration Settings.
2. Modify the following settings as required.  
   {#review-the-misp-integration-settings__table_smd_tdf_kqb__entry__2}

   | Property name || Description |
   |-|-|-|
   | Observable Enrichment | Time (in hours) before fetching new data | Time in hours before you can fetch new data. Type: integer Default value: 24 |
   | Sighting Search | Run Sighting Search automatically when new observables are associated with the security incident | Sighting search that runs whenever a new observable is associated with a security incident. Default value: Yes |
   | Sighting Search | Search Interval (in days) for sighting search in MISP | Number of days that the sighting search data is searched in MISP. Use this option only for the automatic sighting search feature. Default value: 90 |
   | Data synchronization | Interval period (in minutes) for tags to be fetched and synchronized with MISP | MISP tags that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes. Default value: 1440 (minutes or 24 hours) |
   | Data synchronization | Interval period (in minutes) to refresh MISP galaxies from configured sources | MISP galaxies that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes. Default value: 1440 (minutes or 24 hours) |
   | Data synchronization | Interval period (in minutes) for organizations to be fetched and synchronized with MISP | MISP organizations that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes. Default value: 1440 (minutes or 24 hours) |
   | MITRE™ Technique Extraction | Rollup MITRE-ATT\&CK techniques automatically from MISP Observable Enrichment Results (Tags) to security incident | Rollup of MITRE-ATT\&CK information from MISP observable enrichment results (tags) to the security incident. Default value: Yes |
   | MITRE™ Technique Extraction | Rollup MITRE-ATT\&CK techniques automatically from MISP Observable Enrichment Results (Galaxies) to security incident | Rollup of MITRE-ATT\&CK information from the MISP observable enrichment results (galaxies) to the security incident. Default value: Yes |
   [Table 1. MISP Integration settings]

   {#review-the-misp-integration-settings__table_smd_tdf_kqb}  
   Note:  
   * To use the MITRE™ technique extraction features in MISP, you must [enable the MITRE-ATT\&CK feature in the Threat Intelligence module](https://servicenow-prod.fluidtopics.net/T674GxzcCWVAwSySD~RCVg "Review the following information before you start setting up your MITRE-ATT&CK framework.").
   * The MISP integration for Security Operations introduces two base system MITRE-ATT\&CK technique extraction rules for MISP - MISP galaxies and MISP tags. For more information on auto-extraction rules in MITRE-ATT\&CK, see [auto-extract technique rules for importing MITRE-ATT\&CK
     information](https://servicenow-prod.fluidtopics.net/XoPRv_3BTjVwjxRxeqq~kA#auto-extract-technique-rules "Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.").
   {#review-the-misp-integration-settings__ul_pf2_41x_nqb}
3. Click Save.

## Result

Your modified integration settings are saved and applied.
**Related concepts**   

* [MISP event data](https://servicenow-prod.fluidtopics.net/vO7Gn3bAzNeDSfQ6VkL_ag "You can review the MISP event data so that you can see detailed information about the MISP events.")
* [Troubleshooting MISP integration](https://servicenow-prod.fluidtopics.net/W5V1EqvFYQGGq7dNvNSUNw "This section covers important troubleshooting tips that can help you resolve common issues you can encounter when setting up or running MISP integration.")  
**Related tasks**   

* [Install and configure the MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/zOAgaNpmJ0mhPEIijntI9A "Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.")
* [Configure MISP sighting searches](https://servicenow-prod.fluidtopics.net/KDGj2G5G~7HoYTKuecE6bg "Configure the ServiceNow AI Platform to do sighting searches for observables in the MISP instance. With this information, you can determine how often threats occur.")
* [Configure how an automatic event is created](https://servicenow-prod.fluidtopics.net/MEkw3eZtEjMG30VJSZAlNg#configure-automatic-event-creation-profile "Configure the ServiceNow AI Platform to automatically create events in MISP.")  
**Related reference**   

* [Getting started with MISP integration for Security Operations](https://servicenow-prod.fluidtopics.net/EFFaGnNJvZjqxuXFXJT3Og "Review the following information before you set up your MISP integration for Security Operations.")
* [Associated MISP events](https://servicenow-prod.fluidtopics.net/cUrghVC4~oQonIE2_u3kpQ "You can use the associated MISP events list view to view the events that have been created manually or automatically in the context of a security incident.")
* [MISP user information](https://servicenow-prod.fluidtopics.net/sMMXkR0Wmfb~llmc4~6S7w "You can use the MISP user information page to view all the associated users for the ServiceNow AI Platform MISP integration for Security Operations.")
* [Domain separation and MISP](https://servicenow-prod.fluidtopics.net/Cs4ZJeHmQkXB9cNNcFHTgw "Domain separation is supported in MISP. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.")

*[\>]: and then


