Alright, I've seen this question come up in various forms for years—how to get your ThreatConnect cases to show up as Incidents or even Security Events in ServiceNow. Most of the official documentation points you toward the official app or API-heavy scripts that require a dedicated middleware instance. That's overkill for a lot of teams, and the licensing cost for the app isn't always in the cards.
Here's the blunt truth: if you just need a one-way, fire-and-forget push from ThreatConnect to create a record in ServiceNow, you can bypass a lot of complexity with webhooks. I set this up after a previous integration failed because the middleware server became a single point of failure and a maintenance nightmare. The webhook method uses what's already there and stable.
The core of it is using ThreatConnect's **Webhook Action** within a Playbook. You craft a JSON payload that matches what the ServiceNow REST API expects for creating an incident. The key is mapping the ThreatConnect case fields to the correct ServiceNow fields.
Here's a stripped-down example of the payload I use in the Playbook's Webhook Action. You'll need to adjust field names to match your ServiceNow table schema.
```json
{
"short_description": "ThreatConnect Case: {case[name]} - ID: {case[id]}",
"description": "Case Created By: {case[owner][name]}\nSeverity: {case[severity]}\n\n{case[description]}\n\nTags: {case[tag][names]}",
"urgency": "{case[severity]}",
"comments": "Initial creation from ThreatConnect. Case Link: {case[webLink]}",
"contact_type": "Other",
"caller_id": "your.servicenow.user.sys_id"
}
```
You'll need to handle authentication. I use a basic authentication header with a ServiceNow integration user's credentials, but OAuth is possible if you want to configure it. The webhook URL will look something like:
` https://yourinstance.service-now.com/api/now/table/incident`
**Critical lessons from the trenches:**
* **Field Mapping is 80% of the Work:** Your ThreatConnect case severity (Low, High, etc.) likely doesn't map 1:1 to ServiceNow's urgency/impact. You'll need logic in your Playbook to translate. I use a separate data lookup or a conditional block before the webhook to set a variable like `sn_urgency`.
* **Idempotency is Your Friend:** If a case is updated in ThreatConnect, you need a strategy. Do you update the ServiceNow ticket? We only create on initial case creation and use the `{case[webLink]}` for analysts to reference. Updating requires tracking the ServiceNow SysID back in ThreatConnect, which adds more moving parts.
* **Fail Open?:** Decide what happens if the ServiceNow API call fails. Do you want the Playbook to fail and alert, or log the error and continue? In a security workflow, I'd rather know it failed, so we set it to raise an alert.
This isn't a full bi-directional sync. It's a simple, resilient push that gets the ticket created where the IT team lives. It solved our immediate need without a six-month integration project. The maintenance burden is near zero because it relies on core, well-tested features of both platforms.
—BW
Migrate once, test twice.