Inbound Integration for Data Loss Prevention Incident Response
Summarize
Summarized using AI
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.
Summary of Inbound Integration for Data Loss Prevention Incident Response
The Inbound Integration for Data Loss Prevention (DLP) Incident Response allows ServiceNow customers to create single or multiple DLP incidents using the Inbound REST API. This integration is essential for efficiently managing data loss incidents and ensuring a prompt response.
Show less
Key Features
- Create Single DLP Incident: Use the POST method to send a request to the specified URL with necessary parameters such as application window title, assigned user, destination, and detection date.
- Create Multiple DLP Incidents: Allows for the creation of multiple incidents in a single request. Parameters must be defined for each incident within a records array.
- Asynchronous Transformation: By default, the transformation of incidents is asynchronous, but can be configured to synchronous if required.
Key Outcomes
ServiceNow customers can expect to streamline their incident response processes, enhancing efficiency in managing DLP incidents. Successful API calls will return information about the incident, including identifiers and status, enabling tracking and further action as necessary.
Create single or multiple DLP incidents by using the Inbound REST API.
Create a single DLP incident
Role required: sn_dlir.api_integration_user.
To create a single DLP incident, define the following parameters as necessary:
| Field | Description |
|---|---|
| HTTP Method | POST |
| URL | https://{instance}/api/now/import/sn_dlir_incident_import |
| Request Header |
|
| Sample Payload | |
| Sample Response | |
Create multiple DLP incidents
Role required: sn_dlir.api_integration_user.
To create multiple DLP incidents from the same request, define the following parameters as
necessary:
| Field | Description |
|---|---|
| HTTP Method | POST |
| URL | https://{instance}/api/now/import/sn_dlir_incident_import/insertMultiple |
| Request Header |
|
| Sample Payload | |
| Sample Response | |
Note:
By default, the transformation is asynchronous. To set synchronous
transformation, create a new record in the REST Insert Multiples
[sys_rest_insert_multiple] table, select the source table as
sn_dlir_incident_import, and set the transformation to
synchronous.