Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Install and configure the MISP integration for Security Operations

Install and configure the MISP integration for Security Operations from the ServiceNow Store on your ServiceNow AI Platform instance so that you can start investigating security incidents using the MISP data.

Before you begin

Ensure that you’ve installed the valid SSL certificates on the MISP server.

Role required: sn_si.admin

Procedure

  1. Download the MISP integration for Security Operations from the ServiceNow Store and install it.

  2. Navigate to Security Operations > Integrations > Integration Configurations.

  3. Search for the MISP -SIR/TI Integration tile and click Configure.

  4. On the form, fill in the fields.

FieldDescription
NameName for the MISP instance configuration.
MISP Server URLURL for the MISP server that serves as the REST endpoint for the MISP server.
API KeyAPI key that is configured for your user account on the MISP server. The API key corresponds to the Authkey in the MISP server.
On Premises DeploymentOption that you can select if your MISP server is deployed in an on-premise instance. When you select the On Premises Deployment option, you must use the MID Server to connect to the MISP server.
MID ApplicationString field that identifies the MID Application name that is used to communicate with MISP.This field is required when you select the On Premises Deployment option. For information on how to configure the MID server for your application, see Configure a MID Server for each application
  1. Click Submit.

Result

After you successfully validate and submit the configuration, the MISP - SIR/TI Integration is saved on the Security Integrations page as a tile.

Parent Topic:MISP administration

Related topics

Getting started with MISP integration for Security Operations

Review the MISP integration settings

Configure MISP sighting searches

Configure how an automatic event is created

MISP event data

Associated MISP events

MISP user information

Domain separation and MISP

Troubleshooting MISP integration