Configure and enable Elasticsearch integration
Elasticsearch is a distributed, RESTful search and analytics engine that easily integrates with Security Operations.
Before you begin
Before you can use the Elasticsearch, you must download it from the ServiceNow Store.
Role required: sn_sec_tisc.admin
Important:
- The Threat Intelligence Security Center plugin must be installed and activated before you can use the Elasticsearch integration.
- Obtain the Elasticsearch API Base URL, Kibana Base URL, Username, and Password under your Elasticsearch profile.
Procedure
Result
After it is configured, Elasticsearch can be selected for performing sighting search on observables in Threat Intelligence Security Center.