Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Review the MISP integration settings

Review the MISP integration for Security Operations settings and modify the default system properties to suit your environment.

Before you begin

Role required: sn_si.admin, sn_ti.admin

Procedure

  1. Navigate to All > MISP Integration > Integration Settings.

  2. Modify the following settings as required.

Property nameDescription
Observable EnrichmentTime \(in hours\) before fetching new dataTime in hours before you can fetch new data.Type: integer Default value: 24
Sighting SearchRun Sighting Search automatically when new observables are associated with the security incidentSighting search that runs whenever a new observable is associated with a security incident.Default value: Yes
Search Interval \(in days\) for sighting search in MISPNumber of days that the sighting search data is searched in MISP. Use this option only for the automatic sighting search feature.Default value: 90
Data synchronizationInterval period \(in minutes\) for tags to be fetched and synchronized with MISPMISP tags that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes.Default value: 1440 \(minutes or 24 hours\)
Interval period \(in minutes\) to refresh MISP galaxies from configured sourcesMISP galaxies that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes.Default value: 1440 \(minutes or 24 hours\)
Interval period \(in minutes\) for organizations to be fetched and synchronized with MISPMISP organizations that are fetched at the time of the integration configuration. After the data is in the ServiceNow AI Platform, this property defines the frequency at which the data with the MISP server is synchronized. The value is defined in minutes.Default value: 1440 \(minutes or 24 hours\)
MITRE™ Technique ExtractionRollup MITRE-ATT&CK techniques automatically from MISP Observable Enrichment Results \(Tags\) to security incidentRollup of MITRE-ATT&CK information from MISP observable enrichment results \(tags\) to the security incident.Default value: Yes
Rollup MITRE-ATT&CK techniques automatically from MISP Observable Enrichment Results \(Galaxies\) to security incidentRollup of MITRE-ATT&CK information from the MISP observable enrichment results \(galaxies\) to the security incident.Default value: Yes
**Note:**

-   To use the MITRE™ technique extraction features in MISP, you must [enable the MITRE-ATT&CK feature in the Threat Intelligence module](get-started-with-mitre.md).
-   The MISP integration for Security Operations introduces two base system MITRE-ATT&CK technique extraction rules for MISP - MISP galaxies and MISP tags. For more information on auto-extraction rules in MITRE-ATT&CK, see [auto-extract technique rules for importing MITRE-ATT&CK information](auto-extract-technique-rules.md).
  1. Click Save.

Result

Your modified integration settings are saved and applied.

Parent Topic:MISP administration

Related topics

Getting started with MISP integration for Security Operations

Install and configure the MISP integration for Security Operations

Configure MISP sighting searches

Configure how an automatic event is created

MISP event data

Associated MISP events

MISP user information

Domain separation and MISP

Troubleshooting MISP integration