---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure custom MISP API feed

# Configure custom MISP API feed {#ariaid-title1}

* Release version: Australia
* 
* Updated March 5, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The Malware Information Sharing Platform (MISP) API feed enables you to import events from the MISP server, along with their associated attributes and objects, into the TISC library.

## Before you begin

Role required: sn_sec_tisc.admin

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security CenterIntegrations.
2. Select Custom.  
   Note:  
   By default, the MISP feed is inactive. You must edit the configuration to enable the feed.

3. Select the Edit button on the MISP Feed card.
4. Navigate to the Configuration Details section.
5. Update the REST endpoint URL field.
6. Add the required authentication details for the MISP server (if any).
7. Navigate to Additional Settings to configure the filters to fetch the data from MISP.  

   The Additional Settings tab is used to set up filters that determine which MISP events are ingested.
8. Select Edit Settings.  
9. Select the required filters.  
   Note:  
   All the filters configured will be applied in conjunction while ingesting the events.
   Review each option in the table to understand how the filters can be applied to optimize which MISP events are ingested into the TISC library.
10. Select the required values from the following available filters.  
    {#tisc-premium-misp__table_flc_vxs_z2c__entry__2}

    | Field | Description |
    |-|-|
    | Filters on events ||
    | Include unpublished events | Select this check box if you want to include unpublished events. |
    | Creator org name or ID | Enter a comma-separated list of organization names and/or IDs associated with the event. Note: If the organization name contains leading or trailing spaces, enclose the name in double quotes to verify proper processing. |
    | Tag name or ID | Enter a comma-separated list of tag names and/or tag IDs associated with the event. |
    | Threat level | Select a threat level to filter incoming events. Leaving this field empty includes events of all threat levels. |
    | Distribution level | Select a distribution level to limit events. Leaving this field empty includes events of all distribution levels. |
    [Table 1. Edit Additional Settings]

    {#tisc-premium-misp__table_flc_vxs_z2c}  
    Note:  
    After you have defined the Additional Settings following the instructions as explained in the previous step, you can duplicate the feed when creating another. For more information, see Step 13.
11. Select Update on the Additional Settings dialog box to save the modified additional settings.
12. Select Enable to enable the MISP feed for including the MISP events.  
    The TISC application uses the date configured in the Fetch data from field as the baseline for retrieving events and associated
    attributes.

    The Fetch data from date determines which events and associated attributes are retrieved. TISC compares this date with specific timestamps based on the event status:
    * Published events: Compared against the Published timestamp.
    * Unpublished events: Compared against the Last updated timestamp.

    {#tisc-premium-misp__ul_td2_xfc_m3c}

    An event is retrieved only if its relevant timestamp is later than the configured Fetch data from date.

    The system uses the appropriate timestamp for each event status to retrieve newly published events and recently updated unpublished events.
13. **Optional:** Select Duplicate to duplicate the feed.  
    For more information, see [Duplicate threat intelligence feeds](https://servicenow-prod.fluidtopics.net/i1sQhKIu6B2rTA~yqfCkYQ "Duplicate a threat feed to create an exact copy with all associated observables, indicators, and actors when you want to modify settings without affecting the original feed.").  
    Note:  
    * Each MISP event imported into the TISC library, whether as a Threat Report or Threat Event, includes an associated External Reference record.
    * This record is accessible via the Related Records tab and provides a direct URL link to the corresponding MISP event on the MISP server. This also enables quick access to the original event data.
    * For details on how MISP events, along with their associated attributes and objects, are mapped to TISC entities, refer to [KB2197697](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2197697).
    * Entity types that aren't included in the mapping described in the KB article aren't ingested into the TISC Library.
    {#tisc-premium-misp__ul_xxc_1nc_m3c}
{#tisc-premium-misp__steps_zny_gc1_tgc}

*[\>]: and then


