Define schedule for the Secureworks CTP Ticket ingestion
Verify the default settings for ticket retrieval or modify the scheduling as needed. This step permits you to filter your ticket retrieval based on a date range and a polling interval.
Before you begin
Role required: sn_si.admin
About this task
You also choose how often you will poll for future tickets that match the ticket profile configuration. Configure these polling intervals on a per-profile basis. When scheduling, you may prefer to balance system load against incident urgency. A one-minute default value is set for any profile, but you may prefer to modify this setting based on the urgency of the incident and the anticipated load on your system.
Procedure
If the Scheduling page on the progress bar is not displayed, select Scheduling.
Choose one to schedule how and when tickets are pulled from the Secureworks CTP portal.
| Option | Description |
|---|---|
| Ongoing ticket ingestion selected | Based on the default setting, the ServiceNow AI Platform instance pulls from the Secureworks CTP portal for new tickets every five minutes. Security incidents are created if tickets are found and incident generation filtering criteria are matched. To balance ticket ingestion against server load, and to pull the most current data, five minutes is the setting you may prefer. However, this value can be modified as needed. |
| **- Ongoing ticket ingestion selected - Set initial ticket ingestion time ** | Initial ingestion timeIf you want to schedule the initial ingestion at a specific time, follow these steps:
As an example for scheduling, if you have a daily ticket job that runs once a day at 4 AM local time, you can set up the corresponding ticket profile in your ServiceNow AI Platform instance to run at 4:05 AM local time to capture the ticket right away and create a security incident. Enter 04 05 00 in the Initial ticket ingestion field. In the Polling increment (minutes) field, enter 1440 (24 hours) to schedule the next ticket ingestion for 24 hours from the initial ticket ingestion. Both the initial ticket ingestion time and next ticket ingestion time are displayed in the fields. To configure the settings in this example, follow these steps:
|
- Select Continue to navigate to the Additional Options page.