---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Carbon Black Integration - Get Running Processes Flow

# Security Operations Carbon Black Integration - Get Running Processes Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations Carbon Black Integration - Get Running Processes is the implementation for the Carbon Black integration launched by the Security Operations Integration - Get Running Process flow.
Role required: sn_si.analyst
Figure 1. Carbon Black Get Running Processes Actions specific to this flow are described here. For more information on other actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
* **[Collect Carbon Black Configurations Flow Action](https://servicenow-prod.fluidtopics.net/IY98X3yK1bEQPPVoOyBWXg)**   
  The Collect Carbon Black Configurations flow action gathers configuration information to use in the flow.
* **[Check MID Server Status](https://servicenow-prod.fluidtopics.net/Cyltefx3Z8WX5gVtsbUZYw)**   
  Determines whether the MID Server identified in the MID Server Host field of the integration's configuration is up and running. If the field is set to Any, the flow action verifies that any MID Server is up and running.
* **[Get Sensor ID Flow Action](https://servicenow-prod.fluidtopics.net/L729n5LhucJxwQ6xiOKoTA)**   
  The Get Sensor ID flow action gathers sensor identifiers to use in the flow.
* **[Create Session Flow Action](https://servicenow-prod.fluidtopics.net/zvThXFGNdrzhRIuf61R~1g)**   
  The Create Session flow action establishes a Carbon Black session to use in the flow.
* **[Check Session Status Flow Action](https://servicenow-prod.fluidtopics.net/1xQe~qhmaL218nvc3Poi5Q)**   
  Determines the status of a Carbon Black session within the flow.
* **[Create Command Process Flow Action](https://servicenow-prod.fluidtopics.net/XizGsQSXG0GuRp8PiNNDCw)**   
  The Create Command Process flow action create a Carbon Black command process to use in the flow .
* **[Check Command Status and Get Process Flow Action](https://servicenow-prod.fluidtopics.net/HdLKvigE8kTA2mwKhvytxg)**   
  Checks the Carbon Black command status and retrieves processes to use in the flow.
* **[Map Processes Data Flow Action](https://servicenow-prod.fluidtopics.net/dhxo9~tqjGqcrS92oC__aw)**   
  The Map Processes Data flow action maps Carbon Black process data within the flow.
* **[Legacy: Capability Execution Tracking - Complete Flow Action](https://servicenow-prod.fluidtopics.net/hi~3oNvz8X_cfiTlXQAn2w)**   
  The Capability Execution Tracking - Complete flow action updates the audit record when the flow is complete.
* **[Close Session Flow Action](https://servicenow-prod.fluidtopics.net/d9sVc9hI5QbvUfgvGcbiqw)**   
  Closes a Carbon Black session within the flow.

