Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Get started with the Carbon Black - Incident Enrichment integration

The Carbon Black incident enrichment facilitates the investigation of a security incident by querying logs for potentially malicious indicators. Before you can use the Carbon Black - Incident Enrichment integration, you must download it from the ServiceNow Store and add the appropriate Endpoint Base URL and MID server.

Before you begin

Role required: sn_si_admin

Procedure

  1. Download the integration from the ServiceNow Store.

  2. When the download is complete, access the Carbon Black website and obtain the Endpoint Base URL and API Token under your profile.

  3. In your instance, navigate to Security Operations > Integrations > Integration Configuration.

  4. In the Carbon Black - Incident Enrichment card, click Configure.

Image omitted: carbonblack-config-inc.png
Configure Carbon Black - Incident Enrichment integration
  1. Fill in the fields, as needed.

    FieldDescription
    NameThe name of this configuration.
    Endpoint BaseThe endpoint URL you acquired from the Carbon Black site.
    Link URLThe Link URL that links to a Carbon Black instance, when available.
    API TokenThe API token you acquired from the Carbon Black site.
    Max RowsThe maximum number of rows you want to search. The default is 1000 rows.
    Earliest Result (days)The earliest results you want to see in number of days.
    Perform binary and process searchSelect this to perform binary searches to find binary files such as file hashes, and process searches for .exe processes that may have run.
    Include raw data samples in search resultsSelect this to include samples of raw data in your sightings search results. The amount of data returned depends on your setting in the number of rows of raw data property in Security Incident Response properties.
    MID ServerSelect Any to use any active MID Server, or select a specific MID Server name.

    Note: Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.

  2. Click Submit.

    The integration configuration card displays.

  3. To return to the original list of integration configuration cards, select No from the Show Configurations drop-down list.