You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何创建Elastic至ServiceNow的自定义连接器以实现事件自动创建?

从Elastic告警到ServiceNow事件的自定义连接器配置指南

第一步:解析Elastic Webhook的告警Payload

Elastic触发告警时会通过webhook发送JSON格式的Payload,先触发一次测试告警,确认具体数据结构。常见关键字段包括:

  • alert.id: 告警唯一ID
  • alert.name: 告警规则名称
  • alert.description: 告警描述
  • host.name: 触发告警的主机名
  • @timestamp: 告警触发时间
  • message: 告警详情内容

第二步:完善ServiceNow POST脚本API

在ServiceNow的脚本API中编写代码,完成接收Payload、提取信息、创建事件的流程,示例代码如下:

(function process(/*RESTAPIRequest*/ request, /*RESTAPIResponse*/ response) {
    // 解析Elastic发送的JSON数据
    var elasticAlert = request.body.data;
    
    // 提取核心告警字段(根据实际Payload结构调整)
    var alertInfo = {
        alertId: elasticAlert.alert.id,
        ruleName: elasticAlert.alert.name,
        alertDesc: elasticAlert.alert.description || elasticAlert.message,
        sourceHost: elasticAlert.host?.name || '未知主机',
        triggerTime: elasticAlert['@timestamp']
    };
    
    // 创建ServiceNow事件记录
    var eventRecord = new GlideRecord('em_event');
    eventRecord.initialize();
    eventRecord.source = 'Elastic Security';
    eventRecord.event_class = 'Security Alert';
    eventRecord.message = `Elastic规则告警:${alertInfo.ruleName}`;
    eventRecord.description = alertInfo.alertDesc;
    eventRecord.node = alertInfo.sourceHost;
    eventRecord.time_of_event = new GlideDateTime(alertInfo.triggerTime);
    eventRecord.severity = 3; // 1-5对应不同严重级别,可根据Elastic告警级别调整
    
    var eventSysId = eventRecord.insert();
    
    // 返回创建结果
    response.setBody({
        status: 'success',
        servicenow_event_id: eventSysId
    });
})(request, response);

第三步:配置Elastic Webhook的关键参数

在Elastic的webhook设置中完成以下配置:

  • 目标URL:填写ServiceNow脚本API的完整地址(格式如https://<你的实例名>.service-now.com/api/自定义API路径)
  • 请求头部:添加Authorization: Basic <base64编码的用户名:密码>用于ServiceNow认证,同时设置Content-Type: application/json
  • 触发条件:确保关联到需要推送告警的Elastic规则

第四步:端到端测试与问题排查

  1. 在Elastic中手动触发测试告警,验证webhook请求是否发送成功
  2. 查看ServiceNow的em_event表,确认事件是否生成
  3. 若失败,检查ServiceNow系统日志(系统日志>应用日志)和Elastic webhook日志,排查认证错误、字段缺失、格式不匹配等问题

内容的提问来源于stack exchange,提问作者Naveen Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 11:57:02