The ServiceNow integration lets Qevlar use your SOC's historic case data during live investigations. Once connected, Qevlar's AI agents can pull prior case history associated with the users and devices in an alert, and use closed ServiceNow cases as evidence to inform investigation verdicts.
What this integration does
Connecting ServiceNow enables two capabilities:
Historic Context for verdicts. Qevlar queries closed ServiceNow security cases relevant to the current investigation and uses them as evidence when deciding the final outcome. Every revised verdict shows which past cases informed the decision, with a direct link back to the ServiceNow record.
On-demand asset and user lookups. During triage and investigation, Qevlar's agents query ServiceNow to retrieve prior case history associated with the specific users and devices in the alert. This surfaces context such as previous incidents involving the same machine or account, so the investigation reflects what your team already knows.
Prerequisites
Before you start, make sure you have:
- A ServiceNow instance where your team manages security cases.
- A ServiceNow user account Qevlar can authenticate with. We recommend creating a dedicated read-only service account so access can be audited and revoked independently.
- The service account must have read access to the case fields Qevlar uses, including
resolution_codes. Read access toresolution_notesis optional but recommended. Without it, the integration still works but uses resolution codes alone for context. - A Qevlar account with permission to access the Integration Center.
How to connect ServiceNow
- In Qevlar, open the Integration Center from the left-hand navigation and find the ServiceNow card (tagged ITSM).
- Enter your Credentials:
-
Instance URL -
https://<instance>.service-now.com - Username - the Qevlar service account username
- Password - the service account password
-
Instance URL -
- Click Test to validate the credentials without saving, or Test & Save to validate and activate the integration in one step. If the test fails, the UI will surface the specific backend error to help you debug (see Troubleshooting below).
- Once saved, ServiceNow appears as a connected source.
Your password is encrypted at rest and is never visible to anyone, including the Qevlar team.
The integration begins informing investigations on the next alert ingested. No backfill is required. Qevlar queries ServiceNow live as needed.
How the data is used
When a new alert is investigated, Qevlar:
- Identifies the users and devices involved in the alert.
- Queries ServiceNow for closed security cases that match those entities, plus closed cases with resolution codes relevant to the alert type.
- Surfaces the most relevant past cases to its investigation agents as evidence points.
- Where appropriate, revises the final verdict (for example, from
NOT_HARMFULtoSUSPICIOUS) based on what the case history shows.
Every evidence point sourced from ServiceNow is tagged with a SERVICE_NOW_CASES source label in the investigation report and includes a clickable link to the original case.
Where to see it in the product
- Investigation report: ServiceNow-sourced evidence points appear in the Historic Context section, alongside any evidence from Qevlar's own alert history.
- Verdict explanation: If a verdict was revised based on ServiceNow data, the report highlights which past cases drove the change.
- Integration Center: Connection status, last successful sync, and any current errors are visible on the ServiceNow source card.
Troubleshooting
"Credentials are incorrect" Double-check the instance URL, username, and password. The Integration Center will surface the backend error from ServiceNow (e.g. invalid credentials, MFA required, IP allowlist blocking) to help narrow down the cause.
"Insufficient rights to query records" Your service account does not have read access to one of the fields Qevlar requested. Most commonly this affects resolution_notes. Grant the relevant ACL or remove the field from the account's restricted list. Qevlar will continue to work with reduced context until permissions are extended.
No historic context appearing in reports Confirm that:
- The ServiceNow source is shown as Connected in the Integration Center.
- Your ServiceNow instance has closed security cases involving the same users or devices as the alerts being investigated.
Security and data handling
- Qevlar only reads from ServiceNow. The integration never modifies, creates, or deletes records.
- Credentials are stored encrypted and are only used to authenticate API calls.
- You can revoke access at any time by disabling the service account in ServiceNow or disconnecting the source in the Integration Center.
Need help?
If you run into issues connecting ServiceNow or have questions about how the integration uses your data, contact your Qevlar CSM or email support@qevlar.com.