---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Automatic security incident observable log data enrichment

# Automatic security incident observable log data enrichment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

When certain applications and integrations are set up, including Threat Intelligence and the Palo Alto Networks - Firewall integration, observables
information in a security incident can be automatically enriched with threat log data whenever
the Source IP for its observables is modified.

When a modification occurs, a business rule initiates a workflow that retrieves data from
threat logs on your firewall and enriches the observables information in the security
incident.  
Before observables can be enriched, the following steps must be performed.

* [Threat Intelligence](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#install-threat-lp5 "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store.") must be activated.
* The [Palo Alto Networks Firewall](https://servicenow-prod.fluidtopics.net/2wo5fr8sNO1YlH4rJOe25A "The Integration Configuration feature allows you to quickly activate and set up third-party security integrations, including Palo Alto Networks - Firewall. Before you can use the Palo Alto Networks - Firewall, you must download it from the ServiceNow Store.") integration must be activated and configured. This can also include [Set up SSH credentials to the MID Server](https://servicenow-prod.fluidtopics.net/2d~6OzIGIbNcUB42_oiSRg "Palo Alto Networks Firewall sends API calls to the MID Server. As such, ensure that SSH credentials have been created for the MID Server.").
{#si-observ-data-enrich__ul_rfj_ytx_1x}

After that setup has been completed, the act of changing the Source IP of observables
associated with a security incident causes a business rule to execute the Security Operations Palo Alto Networks - Get Log Data workflow. Workflow activities queue up
a search query on the firewall and return a Job ID that is used to retrieve threat logs data from
the firewall and attach them as an XML file to the security incident.
**Related tasks**   

* [Get AutoFocus Session Info Enrichment Flow](https://servicenow-prod.fluidtopics.net/lng~fJasO6Lollc7Q3zhng#search-for-malicious-content "When the Security Operations Palo Alto Networks- Get AutoFocus Session Info Enrichment flow is executed, it queues a search query with AutoFocus for gathering information about a specified source IP. If AutoFocus has knowledge about previous sessions originating from that IP address, a JSON-formatted report is returned.")
* [Palo Alto Networks Firewall Launcher Workflow](https://servicenow-prod.fluidtopics.net/A_608z~NjGZCzIWoioBHHw "Security Operations Integration Palo Alto Networks Firewall Launcher workflow is the Palo Alto Networks Firewall implementation launched by the Security Operations Integration - Block Request capability workflow.")
* [Get Log Data Flow](https://servicenow-prod.fluidtopics.net/yVFX2KOcrVs1W2YtILr0pg#get-threat-log-data "If Security Incident Response, Threat Intelligence, and Palo Alto Networks - Firewall are activated, the Security Operations Palo Alto Networks - Get Log Data flow automatically executes when the Source IP for observables in a security incident is changed.")
* [Get WildFire Data Enrichment Flow](https://servicenow-prod.fluidtopics.net/ia_NL2ox9J1_pF6CGV92eA#enrich-wildfire-data "When the Security Operations Palo Alto Networks - Get WildFire Data Enrichment flow is executed, a hash file is uploaded to WildFire. The data is enriched, and reports are downloaded to the instance to aid in processing potential malware attacks.")

