---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Get AutoFocus Session Info Enrichment Flow

# Get AutoFocus Session Info Enrichment Flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If
AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.

## Before you begin

Role required: sn_si.analyst

## About this task

The Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed when the Source IP field in a security incident is modified and the record is
updated. The flow fetches the IP address and submits a query request to AutoFocus. If AutoFocus has previously identified sessions originating from the IP address, a JSON-formatted report is returned.

## Procedure

1. Navigate to AllSecurity IncidentShow Open Incidents.
2. Select the Indicators of Compromise tab and populate the Source IP field.
3. Select Update.  
   AutoFocus scans the information from the IP address and a text file in JSON format is attached to the security incident.

   Actions specific to this integration are described here. For more information on other
   actions, see [Common Security Operations integration flows and orchestration activities](https://servicenow-prod.fluidtopics.net/VeHrUh9NzKmFfa~3wxWcqQ "Many of the flows associated with third-party integrations include the same activities. For example, activities for beginning and completing processing.").
{#search-for-malicious-content__steps_dq4_x2k_pw}

## AutoFocus Search Session action {#ariaid-title2}

The AutoFocus Search Session flow action uploads information from an IP address assigned to a security incident to AutoFocus and queues it for a search query.

### Input variables

Note:  
When the action executes, it queues a search query with AutoFocus for gathering information for a specified source IP. If AutoFocus has previously identified sessions originating from that IP address, a JSON-formatted report is
returned.

Input variables determine the initial behavior of the action.
{#af-search-session-activity__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| searchSessionQuery \[string\] | The search query for session information. |
[Table 1. Input variables]

{#af-search-session-activity__table_pgm_tfy_jr}

## Fetch Search Results action {#ariaid-title3}

The Fetch Search Results flow action fetches search results identified by a cookie to the search query initiated by the AutoFocus Search Session action.

### Input variables

Input variables determine the initial behavior of the action.
{#get-af-session-info-enrich__table_pgm_tfy_jr__entry__2}

| Variable | Description |
|-|-|
| afcookie \[string\] | The AutoFocus cookie for the search request generated by the [AutoFocus Search Session action](https://servicenow-prod.fluidtopics.net/lng~fJasO6Lollc7Q3zhng#af-search-session-activity "The AutoFocus Search Session flow action uploads information from an IP address assigned to a security incident to AutoFocus and queues it for a search query."). |
[Table 2. Input variables]

{#get-af-session-info-enrich__table_pgm_tfy_jr}

### Output variables

The output variables contain data that can be used in subsequent actions.
{#get-af-session-info-enrich__table_bnj_jfy_jr__entry__2}

| Variable | Description |
|-|-|
| searchPending \[Boolean\] | True if the search request is still processing in AutoFocus. |
| result \[string\] | The search results data. |
| status \[Boolean\] | True if the search is completed and results have been successfully generated. |
| error \[string\] | The error, if any, that occurred in the action. |
[Table 3. Output variables]

{#get-af-session-info-enrich__table_bnj_jfy_jr}

*[\>]: and then


