Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Get started with the Carbon Black integration

Carbon Black is an advanced security system easily integrating with Security Operations. Before you can use the Carbon Black integration, you must download the integration from the ServiceNow Store and add the appropriate Endpoint Base and API Token.

Before you begin

Role required: sn_si_admin

Procedure

  1. Download the integration from the ServiceNow Store.

  2. When the installation is complete, access the Carbon Black website and obtain the Endpoint Base URL and API Token under your profile.

  3. In your instance, navigate to Security Operations > Integrations > Integration Configurations.

    The available security integrations appear as a series of cards.

  4. In the Carbon Black card, click New.

Image omitted: carbonblack-config.png
Configure Carbon Black integration
  1. Fill in the fields, as needed.

    FieldDescription
    NameThe name of this configuration.
    Endpoint BaseThe endpoint base you acquired from the Carbon Black site.
    API TokenThe API token you acquired from the Carbon Black site.
    Use MID ServerSelect this check box if it is not already checked.
    MID ServerSelect Any to use any active MID Server, or select a specific MID Server name.
    Enable Isolate HostSelect this check box to allow selected configuration items to be isolated from the Configuration Items related list tab in a security incident.

    Note: Configuring this integration activates workflows. To manage the workflows, navigate to the Workflow Editor.

  2. Select Submit.

    The integration configuration card displays.

  3. To return to the original list of integration configuration cards, select No from the Show Configurations drop-down list.