---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Security Operations Carbon Black Integration - Isolate Host Flow

# Security Operations Carbon Black Integration - Isolate Host Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Security Operations Carbon Black Integration - Isolate Host is the implementation for the Carbon Black integration launched by the Security Operations Integration - Isolate Host flow.

## Before you begin

Role required: sn_si.analyst

## About this task

The flow process activities include:

* [Legacy: Execution Tracking - Begin (CIs) Flow Action](https://servicenow-prod.fluidtopics.net/km6zEwwRv_t2iYF6c9oEJQ "The Execution Tracking - Begin (CIs) flow action starts the auditing process for a Security Operations Integration flow that operates on configuration items (CIs).")
* [Get IP from CI](https://servicenow-prod.fluidtopics.net/GJWaUxxzzgkzfjOL5AMf7Q "The Get IP from CI flow activity gathers the IP address from configuration items (CIs) to use in the flow.")
* [Collect Carbon Black configurations](https://servicenow-prod.fluidtopics.net/IY98X3yK1bEQPPVoOyBWXg "The Collect Carbon Black Configurations flow action gathers configuration information to use in the flow.")
* [Legacy: Capability Execution Tracking- Failure Flow Action](https://servicenow-prod.fluidtopics.net/C3BSyydAkhR9MTCoL9oX5A "The Capability Execution Tracking - Failure flow action records a failure to the audit record.")
* [Get Sensor ID](https://servicenow-prod.fluidtopics.net/L729n5LhucJxwQ6xiOKoTA "The Get Sensor ID flow action gathers sensor identifiers to use in the flow.")
* [Set Network Isolation Enabled activity](https://servicenow-prod.fluidtopics.net/8LGC7XybapyJBDx0dkOkwg "The Set Network Isolation Enabled workflow activity enables network isolation.")
* [Update Sensor](https://servicenow-prod.fluidtopics.net/lUVTIexB0Yatz6t1god4JQ "The Update Sensor workflow activity updates the sensor to isolate hosts or endpoints.") - returns Isolate Host result.
* [Legacy: Capability Execution Tracking - Complete Flow Action](https://servicenow-prod.fluidtopics.net/hi~3oNvz8X_cfiTlXQAn2w "The Capability Execution Tracking - Complete flow action updates the audit record when the flow is complete.")
{#secops-integration-cb-isolate-host-workflow__ul_csb_5zq_1z}

Activities specific to this flow are described here. For more information on other activities, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
* **[Get Sensor ID Flow Action](https://servicenow-prod.fluidtopics.net/L729n5LhucJxwQ6xiOKoTA)**   
  The Get Sensor ID flow action gathers sensor identifiers to use in the flow.
* **[Set Network Isolation Enabled activity](https://servicenow-prod.fluidtopics.net/8LGC7XybapyJBDx0dkOkwg)**   
  The Set Network Isolation Enabled workflow activity enables network isolation.
* **[Update Sensor activity](https://servicenow-prod.fluidtopics.net/lUVTIexB0Yatz6t1god4JQ)**   
  The Update Sensor workflow activity updates the sensor to isolate hosts or endpoints.

