The following are prerequisites for the Infoblox SOC Insights integration:
Infoblox
Infoblox BloxOne UDDI with one of the following
BloxOne Infoblox Threat Defense Business Cloud + BloxOne Infoblox Threat Defense Ecosystem + SOC Insights
BloxOne Infoblox Threat Defense Advanced + BloxOne Infoblox Threat Defense Ecosystem + SOC Insights
An OPH (On-Prem Host) A NIOS-X virtual server with the Data Connector service enabled. For deploying the Data Connector, refer to this guide.
Generate the CSP API Token.
Log in to your Infoblox BloxOne portal.
Navigate to **API Keys** under your user profile.
Create a new API key and copy the CSP token.
ServiceNow
Permission to create scans, access scan results, and manage assets.A valid Infoblox API key with SOC Insight access. For generating API Key, refer Configuring User API Keys.
ServiceNow
Generate the following
servicenowInstance: URL of the ServiceNow instance
servicenowUsername: Username for authenticating against the ServiceNow instance
servicenowPassword: Password for the ServiceNow user
servicenowTableName (Only Incident and Security Incident are supported)