Product documentation Docs
    • English
    • Deutsch
    • 日本語
    • 한국어
    • Français
  • More Sites
    • Now Community
    • Developer Site
    • Knowledge Base
    • Product Information
    • ServiceNow.com
    • Training
    • Customer Success Center
    • ServiceNow Support Videos
  • Log in

Product documentation

  • Home
How search works:
  • Punctuation and capital letters are ignored
  • Special characters like underscores (_) are removed
  • Known synonyms are applied
  • The most relevant topics (based on weighting and matching to search terms) are listed first in search results
Topics are ranked in search results by how closely they match your search terms
  • A match on the entire phrase you typed
  • A match on part of the phrase you typed
  • A match on ALL of the terms in the phrase you typed
  • A match on ANY of the terms in the phrase you typed

Note: Matches in titles are always highly ranked.

  • Release version
    Table of Contents
    • Security Operations
Table of Contents
Choose your release version
    Home London Security Incident Management Security Operations Security Incident Response Security Incident Response integrations HPE Security ArcSight ESM - Email Parser integration

    HPE Security ArcSight ESM - Email Parser integration

    • Save as PDF Selected topic Topic & subtopics All topics in contents
    • Unsubscribe Log in to subscribe to topics and get notified when content changes.
    • Share this page

    HPE Security ArcSight ESM - Email Parser integration

    The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents.

    Related concepts
    • Carbon Black - Incident Enrichment integration
    • Check Point Next Generation Threat Prevention integration
    • Check Point Anti-bot - Email Parser integration
    • Hybrid Analysis integration
    • LogRhythm integration
    • McAfee ePO integration
    • McAfee ESM - Email Parser integration
    • Microsoft Exchange Online integration
    • Palo Alto Networks next-generation firewall integration
    • PhishTank integration
    • Reverse Whois integration
    • RISKIQ and WHOISIQ integration
    • Shodan integration
    • Get started with the ServiceNow Security Operations add-on for Splunk
    • Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow
    • Tanium Integration V2
    • Threat Crowd integration
    Related reference
    • Carbon Black integration
    • CrowdStrike Falcon Host integration
    • Elasticsearch Incident Enrichment integration
    • HPE ArcSight Logger - Incident Enrichment integration
    • IBM QRadar - Incident Enrichment Integration
    • McAfee ESM - Incident Enrichment Integration
    • Microsoft Exchange On-Premises integration
    • Palo Alto Networks - AutoFocus integration
    • Palo Alto Networks - Firewall integration
    • Palo Alto Networks - WildFire integration
    • Security Operations Have I been pwned? integration
    • Splunk - Incident Enrichment integration
    • Tanium Endpoint Platform integration

    Get started with the HPE Security ArcSight ESM - Email Parser integration

    HPE Security ArcSight ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.

    Before you begin

    Role required: sn_si_admin

    About this task

    An HPE Security ArcSight ESM - Email Parser template is provided to use for the integration. It must be configured and activated before the integration takes place. Updating the parser activates it.

    Procedure

    1. Navigate to Security Operations > Integrations > Integration Configurations.
      The available security integrations appear as a series of cards.
      HPE Security Arcsight ESM - Email Parser card
    2. In the HPE Security ArcSight ESM - Email Parser card, click Configure.
    3. In the HPE Security ArcSight ESM - Email Parser Configuration dialog box, click the Configure Email Parser link.
    4. Click the ArcSight ESM link to edit the settings in the template email parser provided. At a minimum, fill in the Email is from field.
      To create you own email parser, see Create email parsers in Security Operations.
    5. Check the Active box.
    6. Click Update in the Email Parser form.
      The email parser is active. You do not need to return to Integration Configurations.

    Tags:

    Feedback
    On this page

    Previous topic

    Next topic

    • Contact Us
    • Careers
    • Terms of Use
    • Privacy Statement
    • Sitemap
    • © ServiceNow. All rights reserved.

    Release version
    Choose your release version

      HPE Security ArcSight ESM - Email Parser integration

      • Save as PDF Selected topic Topic & subtopics All topics in contents
      • Unsubscribe Log in to subscribe to topics and get notified when content changes.
      • Share this page

      HPE Security ArcSight ESM - Email Parser integration

      The HPE Security ArcSight ESM - Email Parser integration is supported using an email parser that consumes email notifications from ESM to create security incidents.

      Related concepts
      • Carbon Black - Incident Enrichment integration
      • Check Point Next Generation Threat Prevention integration
      • Check Point Anti-bot - Email Parser integration
      • Hybrid Analysis integration
      • LogRhythm integration
      • McAfee ePO integration
      • McAfee ESM - Email Parser integration
      • Microsoft Exchange Online integration
      • Palo Alto Networks next-generation firewall integration
      • PhishTank integration
      • Reverse Whois integration
      • RISKIQ and WHOISIQ integration
      • Shodan integration
      • Get started with the ServiceNow Security Operations add-on for Splunk
      • Splunk Enterprise Event Ingestion integration for Security Operations by ServiceNow
      • Tanium Integration V2
      • Threat Crowd integration
      Related reference
      • Carbon Black integration
      • CrowdStrike Falcon Host integration
      • Elasticsearch Incident Enrichment integration
      • HPE ArcSight Logger - Incident Enrichment integration
      • IBM QRadar - Incident Enrichment Integration
      • McAfee ESM - Incident Enrichment Integration
      • Microsoft Exchange On-Premises integration
      • Palo Alto Networks - AutoFocus integration
      • Palo Alto Networks - Firewall integration
      • Palo Alto Networks - WildFire integration
      • Security Operations Have I been pwned? integration
      • Splunk - Incident Enrichment integration
      • Tanium Endpoint Platform integration

      Get started with the HPE Security ArcSight ESM - Email Parser integration

      HPE Security ArcSight ESM - Email Parser integration uses email notifications from ESM to drive enrichment, and response workflows.

      Before you begin

      Role required: sn_si_admin

      About this task

      An HPE Security ArcSight ESM - Email Parser template is provided to use for the integration. It must be configured and activated before the integration takes place. Updating the parser activates it.

      Procedure

      1. Navigate to Security Operations > Integrations > Integration Configurations.
        The available security integrations appear as a series of cards.
        HPE Security Arcsight ESM - Email Parser card
      2. In the HPE Security ArcSight ESM - Email Parser card, click Configure.
      3. In the HPE Security ArcSight ESM - Email Parser Configuration dialog box, click the Configure Email Parser link.
      4. Click the ArcSight ESM link to edit the settings in the template email parser provided. At a minimum, fill in the Email is from field.
        To create you own email parser, see Create email parsers in Security Operations.
      5. Check the Active box.
      6. Click Update in the Email Parser form.
        The email parser is active. You do not need to return to Integration Configurations.

      Tags:

      Feedback

          Share this page

          Got it! Feel free to add a comment
          To share your product suggestions, visit the Idea Portal.
          Please let us know how to improve this content

          Check any that apply

          To share your product suggestions, visit the Idea Portal.
          Confirm

          We were unable to find "Coaching" in Jakarta. Would you like to search instead?

          No Yes
          • Contact Us
          • Careers
          • Terms of Use
          • Privacy Statement
          • Sitemap
          • © ServiceNow. All rights reserved.

          Subscribe Subscribed Unsubscribe Last updated: Tags: January February March April May June July August September October November December No Results Found Versions Search preferences successfully updated My release version successfully updated My release version successfully deleted An error has occurred. Please try again later. You have been unsubscribed from all topics. You are now subscribed to and will receive notifications if any changes are made to this page. You have been unsubscribed from this content Thank you for your feedback. Form temporarily unavailable. Please try again or contact  docfeedback@servicenow.com  to submit your comments. The topic you requested does not exist in the release. You were redirected to a related topic instead. The available release versions for this topic are listed There is no specific version for this documentation. Explore products Click to go to the page. Release notes and upgrades Click to open the dropdown menu. Delete Remove No selected version Reset This field is required You are already subscribed to this topic Attach screenshot The file you uploaded exceeds the allowed file size of 20MB. Please try again with a smaller file. Please complete the reCAPTCHA step to attach a screenshot
          Log in to personalize your search results and subscribe to topics
          No, thanks Login