---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure

# Get started with the Carbon Black integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Carbon Black is an advanced security system easily integrating with Security Operations. Before you can use the Carbon Black integration, you must download the integration from the ServiceNow Store and add the appropriate Endpoint Base and API Token.

## Before you begin

Role required: sn_si_admin

## Procedure

1. [Download the integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. When the installation is complete, access the Carbon Black website and obtain the Endpoint Base URL and API Token under your profile.
3. In your instance, navigate to Security OperationsIntegrationsIntegration Configurations.  
   The available security integrations appear as a series of cards. {#activate-configure-carbonblack__Nav-To}
{#activate-configure-carbonblack__Nav-To}
4. In the Carbon Black card, click New.  
5. Fill in the fields, as needed.  
   {#activate-configure-carbonblack__table_l2p_dcs_ns__entry__2}

   | Field | Description |
   |-|-|
   | Name | The name of this configuration. |
   | Endpoint Base | The endpoint base you acquired from the Carbon Black site. |
   | API Token | The API token you acquired from the Carbon Black site. |
   | Use MID Server | Select this check box if it is not already checked. |
   | MID Server | Select Any to use any active MID Server, or select a specific MID Server name. |
   | Enable Isolate Host | Select this check box to allow selected configuration items to be isolated from the Configuration Items related list tab in a security incident. |
   [ ]

   {#activate-configure-carbonblack__table_l2p_dcs_ns}  
   Note:  
   Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.
6. Select Submit.  
   The integration configuration card displays.
7. To return to the original list of integration configuration cards, select No from the Show Configurations drop-down list.
{#activate-configure-carbonblack__steps_gfz_1yn_vw}

*[\>]: and then


