如何创建Elastic至ServiceNow的自定义连接器以实现事件自动创建?
从Elastic告警到ServiceNow事件的自定义连接器配置指南
第一步:解析Elastic Webhook的告警Payload
Elastic触发告警时会通过webhook发送JSON格式的Payload,先触发一次测试告警,确认具体数据结构。常见关键字段包括:
alert.id: 告警唯一IDalert.name: 告警规则名称alert.description: 告警描述host.name: 触发告警的主机名@timestamp: 告警触发时间message: 告警详情内容
第二步:完善ServiceNow POST脚本API
在ServiceNow的脚本API中编写代码,完成接收Payload、提取信息、创建事件的流程,示例代码如下:
(function process(/*RESTAPIRequest*/ request, /*RESTAPIResponse*/ response) { // 解析Elastic发送的JSON数据 var elasticAlert = request.body.data; // 提取核心告警字段(根据实际Payload结构调整) var alertInfo = { alertId: elasticAlert.alert.id, ruleName: elasticAlert.alert.name, alertDesc: elasticAlert.alert.description || elasticAlert.message, sourceHost: elasticAlert.host?.name || '未知主机', triggerTime: elasticAlert['@timestamp'] }; // 创建ServiceNow事件记录 var eventRecord = new GlideRecord('em_event'); eventRecord.initialize(); eventRecord.source = 'Elastic Security'; eventRecord.event_class = 'Security Alert'; eventRecord.message = `Elastic规则告警:${alertInfo.ruleName}`; eventRecord.description = alertInfo.alertDesc; eventRecord.node = alertInfo.sourceHost; eventRecord.time_of_event = new GlideDateTime(alertInfo.triggerTime); eventRecord.severity = 3; // 1-5对应不同严重级别,可根据Elastic告警级别调整 var eventSysId = eventRecord.insert(); // 返回创建结果 response.setBody({ status: 'success', servicenow_event_id: eventSysId }); })(request, response);
第三步:配置Elastic Webhook的关键参数
在Elastic的webhook设置中完成以下配置:
- 目标URL:填写ServiceNow脚本API的完整地址(格式如
https://<你的实例名>.service-now.com/api/自定义API路径) - 请求头部:添加
Authorization: Basic <base64编码的用户名:密码>用于ServiceNow认证,同时设置Content-Type: application/json - 触发条件:确保关联到需要推送告警的Elastic规则
第四步:端到端测试与问题排查
- 在Elastic中手动触发测试告警,验证webhook请求是否发送成功
- 查看ServiceNow的
em_event表,确认事件是否生成 - 若失败,检查ServiceNow系统日志(系统日志>应用日志)和Elastic webhook日志,排查认证错误、字段缺失、格式不匹配等问题
内容的提问来源于stack exchange,提问作者Naveen Kumar
相关产品推荐
相关产品推荐

