Configure the RiskSense Web Service Connector to Import RBVM Events
2 min
2023 3 updated the way communicates with neurons for rbvm if you have 2023 1 already installed, 2023 3 will not make changes to your existing integration 2023 3 includes two new web service connections risksense create security events calls the neurons for rbvm api and creates new security events or updates existing security events by sourceid if a security event is set to closed in but not in neurons for rbvm, a new security event is created with the same sourceid next time the schedule entry job runs if the security incident record is set to resolved risksense security event details updates the security event record by filling in the description , event severity and risk score fields with details from neurons for rbvm via the neurons for rbvm api risksense cis by security event either finds cis within that are associated with the sourceid in risksense and updates the ci record or creates a new ci record if the risk score and event severity are above 9, a security incident record is automatically created you can edit those thresholds in the triggered actions of the security event business object when the security event record is created, the system will associate the affected cis in the record's ci tab rbvm integration using export api new for 2023 3, this api offers better mapping of imported data into fields in security event forms this also allows for better reporting and more detailed dashboards if you installed 2023 3 over a previous version, you have to update the schedule entry to use the new web service connections you can also leave the web service connections from older versions in place if you prefer when a security event is created, two business rule triggered action are initiated risksense update start date updates the record filling in the event start date field with the current date/time risksense create/update cis calls the risksense cis by security event workflow and either finds cis within that are associated with the sourceid in risksense and updates the record or creates a new ci record to import risksense events open the integration tools workspace and select web service connections refer to about configuring data integration docid\ g6i68njtolujzngtisr3s and working with incoming web service connections docid\ j7tnsjafp3ohqrnokepmv for more information a three connections were installed with 2023 1 risksense cis by security event, risksense create security events, and risksense security event details b edit the risksense integration c on the integration details page, select next d on the integration script page, edit the api call settings to add the risksense api url and the api key e select next f in the schedule settings window, select next g create a schedule to import these events on a regular basis refer to creating a schedule in about the schedule entry and scheduled jobs workspaces docid\ oly9b8ak4f7dbrbymcikf if you installed 2023 1 over 2022 2, you need to update the integration tab h select yes in the confirmation window i on the review and publish page, select publish j select ok on the data import confirmation window open the integration queue workspace refer to viewing the integration status and history docid 5iads1vlkbibhfonuatnr a select refresh to see the running risksense integration you may need to do this several times b you can also open the integration history workspace to verify the integration has finished running c if the import fails, open the integration log workspace to check for error stats if the import fails, try changing the date format to mm/dd/yyyy on the integration script page to view the imported events, open the events workspace when a security event is imported from risksense, an incident is automatically created set the risksense integration schedule a search for risksense in the schedule entry workspace and open the risksense integration job b in the integration tab, link the risksense create security events job c set the recurring schedule as desired refer to creating a schedule in about the schedule entry and scheduled jobs workspaces docid\ oly9b8ak4f7dbrbymcikf if you installed 2023 1 over 2022 2, you have to update the integration tab to link risksense create security events job
