---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure

# Get started with the CrowdStrike Falcon X Sandbox integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Activate and set up the CrowdStrike Falcon X Sandbox to interface with your ServiceNow instance and Security Incident Response product.

## Before you begin

* Before you can use the CrowdStrike Falcon X Sandbox for Security Operations integration, you must download it from the [ServiceNow Store](https://servicenow-prod.fluidtopics.net/jBa~11BcDnkn~s9DxBYDkw "Starting with Madrid, all Security Operations applications and supported integrations are available for download from the ServiceNow Store. This allows you to obtain new and updated features more rapidly. Before you can use any Security Operations applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them), download them from the ServiceNow Store, and activate them.").
* Review the following setup checklist and verify that you have completed all the tasks for a smooth CrowdStrike Falcon X Sandbox integration.
{#crowdstrike-falcon-sandbox-getting-started__ul_srm_3nc_nsb} Role required: admin, sn_si.admin
{#crowdstrike-falcon-sandbox-getting-started__table_yvc_gb3_1nb__entry__2}

| Setup task | Description |
|-|-|
| Verify that you have assigned the required ServiceNow AI Platform and Security Incident Response roles. | The following roles are required for configuration and verification of the expected results: * The administrator (admin) installs the sandbox integration from the ServiceNow app store and assigns the security incident administrator (sn_si.admin) role. * The sn_si.admin creates and edits the configuration and global settings and then assigns the security incident analyst (sn_si.analyst) role. * The security incident analyst (sn_si.analyst) responds to security incidents, such as submitting files and URLs to the sandbox and analyzing the submission results. {#crowdstrike-falcon-sandbox-getting-started__ul_u5g_nc3_1nb} |
| Verify that the ServiceNow core applications that are required to support the integration are installed and activated before you configure this integration. | This integration is supported on Paris and Orlando releases. Ensure that these dependent plugins are installed. These plugins enable the execution of Integration Hub actions and flows: * ServiceNow IntegrationHub Action Step - REST (com.glide.hub.action_step.rest) * ServiceNow IntegrationHub Runtime (com.glide.hub.integration.runtime) {#crowdstrike-falcon-sandbox-getting-started__ul_pct_mb3_1nb} Note: If you can't find a plugin, you may have to request it from ServiceNow personnel. To request a plugin, follow the steps in [Request a plugin](https://www.servicenow.com/docs/access?context=t_RequestAPlugin&version=australia&pubname=australia-platform-administration&ft:locale=en-US). The Security Incident Response plugin (com.snc.security_incident) is required. This plugin automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before you install and activate the other Security Operations applications that are required by the integration. Verify that the following Security Operations applications are installed and activated from the ServiceNow Store. If not installed, install and activate one application at a time in the following order to ensure a smooth installation. 1. Security Incident Response Dependency (com.snc.si_dep) 2. Security Integration Framework 3. Security Support Common 4. Security Support Orchestration 5. Threat Intelligence Support Common (required to use the sandbox integration capabilities) 6. Trusted Security Circles 7. Security Operations Setup Assistant 8. Security Incident Response {#crowdstrike-falcon-sandbox-getting-started__ol_jbj_1c3_1nb} For more information on setting up your ServiceNow AI Platform instance for the integration, see [Get entitlement for a Security Operations product](https://servicenow-prod.fluidtopics.net/ZZVMDPCDs~BwBGv0OAhjuA "The first step in installing a Security Operations application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.") or application and [Activate a ServiceNow Store application](https://servicenow-prod.fluidtopics.net/RFo48XO5_M32aNft7_tP2A "After an application has been given entitlement, you must activate its dependencies plugin and activate the application. This process also applies to applications downloaded to sub-production instances."). |
| Verify that you're licensed for the Falcon Sandbox Private API key, and obtain the CrowdStrike Falcon X Sandbox full API key. | This integration supports the Falcon Sandbox Private Cloud only. Note: This release does not support Falcon X integration. CrowdStrike Falcon X Sandbox offers a self-signed restricted API key and an upgraded full API key. Use the full API key for this integration because it enables unrestricted access for automated submissions. For more information, see [CrowdStrike Falcon Sandbox Knowledge Base](https://www.falcon-sandbox.com/knowledge-base/issuing-full-api-key-for-automated-submissions). |
[Table 1. Checklist]

{#crowdstrike-falcon-sandbox-getting-started__table_yvc_gb3_1nb}

## Procedure

1. [Download the CrowdStrike Falcon Sandbox for Security Operations integration from the ServiceNow Store](https://servicenow-prod.fluidtopics.net/qGeljAXHdNqRLZ7BfdM03w "Downloading an application from the ServiceNow Store for the first time involves a number of easy steps. Some of the steps are performed on the ServiceNow Store and some in your instance.").
2. When the installation is complete, navigate to Security Operations \> Integrations \> Integration Configurations.
3. Search for the CrowdStrike Falcon X Sandbox integration tile, and select Configure.
4. Enter the following details to complete the configuration:  
   {#crowdstrike-falcon-sandbox-getting-started__table_ysg_hpy_ymb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of this integration, for example, <kbd class="ph userinput">demo-1</kbd>. While this is a unique name to identify the sandbox configuration, you can only configure one integration per ServiceNow instance. |
   | CrowdStrike Falcon Sandbox Base URL | Sandbox base URL. This URL is available after you configure the sandbox. For example, <kbd class="ph userinput">https://servicenow.falcon-sandbox.com</kbd> is a base URL. |
   | Client ID | OAuth2 API client ID. For more information see, [API Clients and Keys](https://falcon.crowdstrike.com/login/?next=/support/api-clients-and-keys). |
   | Client Secret | OAuth2 API client secret key. For more information see, [API Clients and Keys](https://falcon.crowdstrike.com/login/?next=/support/api-clients-and-keys). |
   [ ]

   {#crowdstrike-falcon-sandbox-getting-started__table_ysg_hpy_ymb}
5. Select Submit.  
   After the sandbox is successfully validated and submitted, it is saved on the Security Integrations page as a tile. You can now view the Sandbox module in the application navigator.

## What to do next

After you successfully complete the integration, the next step is to set up [Sandbox submission configurations](https://servicenow-prod.fluidtopics.net/q3Fhm5wlm9xMwFA04RFclQ "Set up the Sandbox configuration to define the analysis environment and runtime options for your security incident record submissions for the malware analysis.").

