The following are prerequisites for the Infoblox SOC Insights integration:
Infoblox
Infoblox BloxOne with one of the following
BloxOne Threat Defense Business Cloud + BloxOne Threat Defense Ecosystem + SOC Insights
BloxOne Threat Defense Advanced + BloxOne Threat Defense Ecosystem + SOC Insights
An OPH (On-Prem Host) with the Data Connector service enabled. For deploying the Data Connector, refer to this guide.
Generate the CSP API Token.
Log in to your Infoblox BloxOne portal.
Navigate to **API Keys** under your user profile.
Create a new API key and copy the CSP token.
ServiceNow
Permission to create scans, access scan results, and manage assets.
Generate the following
servicenowInstance: URL of the ServiceNow instance
servicenowUsername: Username for authenticating against the ServiceNow instance
servicenowPassword: Password for the ServiceNow user
servicenowTableName (Only Incident and Security Incident are supported)