Monitor security events
-
- UpdatedFeb 1, 2024
- 4 minutes to read
- Washington DC
- Platform Security
Analyze the event metrics in your instance so that you can identify and prevent potential security events.
Instance Security Center (ISC) has reached the end of sales as of September 2024, and is no longer supported or available for new activation.
ServiceNow Security Center (SSC) is the recommended solution going forward. For more information, see Instance Security Center to ServiceNow Security Center migration.- For each event metric, a real-time single score count appears, indicating how many times that the event occurred during the day in this instance. These single score reports are updated automatically as the corresponding events take place.
- Each event metric also contains compliance trend and graph information over a range of dates. This information updates on a daily basis when you run the performance analytics job. To learn more, see the Analyzing event trend detail section.
Event types
You can monitor at least six of the following types of events. For more than six events, use the left or right arrows below the event ribbon to scroll through them. To learn how to configure the event ribbon, see Configure the security event ribbon.
Analyzing event trend detail
To view trend details for an event metric, click the event count to access the Analytics Hub page. The details that appear for the instance depend on the type of metric.
Example
- Select the Failed Logins metric.
- In the Analytics Hub page, click Show Records.
- Click one of the failed login attempts.
- The detail includes the name of the user who attempted to log in, their IP address, and the table name that they tried to access.
You can set up event threshold triggers in the Analytics Hub to provide alerts when a certain event occurs within a range of scores for an indicator. You can also set targets that enable you to visualize the difference between the desired score and the actual score of an event.
Example
For example, you can set a threshold of 10 for the Failed Logins metric. When ten or more failed login attempts occur during the day, an alert is sent to specific security personnel. You can also set a similar target that provides a visual highlight in the Analytics Hub when 10 failed logins occur during a day.
On this page
Related Content
- Instance Security Center to ServiceNow Security Center migration
Learn the key differences when migrating from Instance Security Center (ISC) to ServiceNow Security Center (SSC).
- Check the daily compliance score and configure security property settings
Review the Daily Compliance Score metric and security configuration properties to see if your instance complies with the suggested security requirements. You can affect the daily compliance score by updating non-compliant security properties in the Hardening Compliance Configurations page.
- Scan for incorrect security definitions
Run the Auditor to scan your instance and find incorrect security definitions. It provides findings you can correct to help improve the security posture of your instance.
- Monitor instance metrics
Monitor user, export, authentication, email, and antivirus metrics for your instance. For example, you can monitor your email security by checking metrics for spam, external emails, and inbound emails from untrusted and trusted domains for your instance. Analyze these metrics to look for anomalous security behaviors that are related to activities that take place in your instance.
- Activate the ISC Virtual Agent interface
If you have the admin role, you can activate the ISC Virtual Agent Conversations plugin (com.glide.isc_virtualagent). Activating this plugin installs the Virtual Agent and Natural Language Understanding (NLU) content packs, providing Virtual Agent access from the Instance Security Center.
- Other settings and security resources
This section contains security properties you set outside of the Instance Security Center, and also contains other security-related resources.
- Instance Security Hardening Settings
The Instance Security Hardening Settings content contains detailed descriptions and compliance values for the security-related system properties and plugins in the Now Platform. You can set most of these properties in the Hardening Compliance Configuration page in the Instance Security Center.
- Instance Security Center
Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.
- Now Intelligence
- Analytics Hub
- Performance Analytics targets and thresholds