The following are prerequisites for the Infoblox SOC Insights integration:
Infoblox
Infoblox BloxOne with one of the following
BloxOne Threat Defense Business Cloud + BloxOne Threat Defense Ecosystem + SOC Insights
BloxOne Threat Defense Advanced + BloxOne Threat Defense Ecosystem + SOC Insights
An OPH (On-Prem Host) with the Data Connector service enabled. For deploying the Data Connector, refer to this guide.
A valid Infoblox API key with SOC Insight access. For generating API Key, refer Configuring User API Keys.
ServiceNow
Generate the following
servicenowInstance: URL of the ServiceNow instance
servicenowUsername: Username for authenticating against the ServiceNow instance
servicenowPassword: Password for the ServiceNow user
servicenowTableName (Only Incident and Security Incident are supported)