Create a Security Operations enrichment data map Transform data from JSON, XML, or Properties file format to ServiceNow records using enrichment data maps. Before you beginRole required: sn_sec_cmn.write About this task Existing enrichment data maps are used by workflows provided within Security Operations. You can view the list under Enrichment Data Mapping. To use a map, you need a trigger, either a business rule or workflow. Procedure Navigate to Security Operations > Utilities > Enrichment Data Mapping. Click New. Fill in the fields, as appropriate. Table 1. Creating an enrichment data map Field Description Name Name of this enrichment data map. Description Description of the data map. Input format Choose a format from the list: JSON (default) XML Properties File format Prefix key Use to limit the input data set to a specified key. The root of the input data set is set to this key. In this example, if you entered file_info, then the input values would be limited to those values within file_info. <?xml version="1.0" encoding="UTF-8"?> <malware> <version>2.0</version> <file_info> <malware>yes</malware> <sha1>24c051142583e10451a53893fed3aa5d80bfb1f6</sha1> <filetype>PE</filetype> <sha256>be9bd96808173e2d967feef8c8c5b8c4d73b621584fb11eb68434da1e6a0a930</sha256> <md5>ee8c91751b3010e38c479cf9ab09827a</md5> <size>546304</size> </file_info> </malware> Target table Choose a table from the list. Active When checked, this mapping is available for use. Click Submit. The Enrichment Data Mapping Fields tab appears. Click New. Fill in the fields on the form, as appropriate. Table 2. Enrichment data mapping fields Field Description Mapping Name of the enrichment data map. Target table The table the fields to map come from. Transform type Choose from the list: Populate target field with field value Populate target field with static value Populate target field with static value plus field value Field is an array or object (raw data nesting) Each choice has different entries. Target field values, and arrays, or objects require a Property key. Property key Determines the key for the input data search and the value written to the target field. Target field Choose the field to write to from the list. Target Mapping Used with the Field is an array or an object (raw data nesting) transform type. Choose an existing mapping or create another mapping. This target map becomes a child of the current map. Click Submit. The following is an example of an enrichment data map.