DataBee Remediation Actions
  • 01 Apr 2025
  • 3 Minutes to read
  • Dark
    Light

DataBee Remediation Actions

  • Dark
    Light

Article summary

Introduction

DataBee Remediation Actions is a feature designed to empower organizations by automating their response workflow and IT operations challenges. This feature enhances response efficiency by allowing users to create automated actions based on specifically crafted data queries within the DataBee platform. These actions can generate ServiceNow tickets tailored to predefined criteria, reducing manual effort and speeding up resolution times.

The queries driving these remediation actions can be executed against various data tables, such as a CDP (Core Data Product), OCSF or CCM (Continuous Controls Monitoring) table, offering flexibility in how organizations leverage their data to trigger automated responses.

Key Features

  • Automated Response Actions: Automatically generate ServiceNow tickets based on custom data queries.

  • ServiceNow Integration: Seamlessly connect with ServiceNow ITSM to create and manage tickets.

  • Scheduling Capabilities: Define specific days and times for remediation actions to run automatically.

  • Action Management: Gain a comprehensive view of all configured actions, including their connection details, schedules, severity levels, and statuses.

How It Works

The DataBee platform processes data from multiple sources, normalizes it, and transforms it into actionable outcomes. The data flow pipeline consists of the following steps:

  1. Data Collection:

    1. Sources: Data is gathered from systems like Quali's vulnerability scanner (security vulnerability data), ServiceNow CMDB (asset and application management), and Workday (user and organizational data).

  2. Real-Time Processing:

    1. Collected data is processed in real time and normalized into a unified schema.

  3. Remediation Action Configuration:

    1. Create a Remediation Action based upon a DataBee query. Records that match the query, will be sent to the output.

  4. Outputs:

    1. Ticket Creation: Automated generation of ServiceNow tickets for incidents or IT operations requiring attention.

This automated workflow minimizes manual processes, accelerates response times, and strengthens organizational security and operational efficiency.

Setup Instructions

Follow these steps to configure a remediation action in DataBee:

Setting Up ServiceNow Integration

To integrate ServiceNow with Databy, follow these steps:

  1. Log In: Access the Databy console.

  2. Access Settings: Click the gearbox icon (configuration settings) in the top right corner.

  3. Navigate to Integrations: In the System settings, select the Integrations tab on the left.

  4. Select ServiceNow: Click the ServiceNow ITSM integration card.

  5. Configure OAuth: Enter the OAuth configuration details for your ServiceNow instance.

  6. Test Connection: Click Test connection to verify the setup.

  7. Save: If successful, click Submit to save the configuration.

Creating a Remediation Action

To create a new remediation action, follow these steps:

  1. Navigate: Go to the Data menu and select the Remediation Actions tab.

  2. Start New Action: Click the New button.

  3. Choose Connection: Select the ServiceNow connection from the dropdown.

  4. Name and Describe: Enter an Action Name and Description.

  5. Define Query: Craft a query to specify the conditions for ticket creation.

  6. Configure Ticket Fields:

    • Incident Title: Enter the mandatory ticket title.

    • Incident Description: Provide the mandatory ticket description.

    • Additional Fields: Optionally, add key-value pairs relevant to ServiceNow ITSM tickets.

  7. Schedule: Choose the day and time for the action to run.

  8. Save: Click Save to activate the remediation action.

Example Use Case

Imagine you need to automatically notify a team member, Mike, about vulnerabilities requiring remediation. Here’s how DataBee Remediation Actions can help:

  • Scenario: Create a ServiceNow ticket for vulnerabilities with a compliance_status = false and assigned to Mike.

  • Setup:

    • Query: Define a query like compliance_status = false AND owner = 'Mike'.

    • Ticket Details:

      • Incident Title: "Vulnerability Remediation Required"

      • Incident Description: "Vulnerability Category, Affected Asset: [Asset Types]"

    • Schedule: Run daily at 9:00 AM.

  • Outcome: Mike receives a ServiceNow ticket each day listing vulnerabilities he owns that need attention, streamlining the remediation process.

Managing Remediation Actions

Once actions are configured, you can monitor and manage them within the DataBee console:

  • Action Overview:

    • Navigate to the Actions page for a holistic view of all remediation actions.

    • Review details such as the assigned connection, schedule, severity, and current status.

  • Action History:

    • Click the History button for any action to access a detailed history table.

    • View information including:

      • ServiceNow ticket numbers generated.

      • Number of records attached to each ticket.

      • Error details (if any) from previous runs.

    • Use filtering and search options to analyze specific actions or runs.

This visibility ensures you can track the performance and effectiveness of your automated responses.

Conclusion

DataBee Remediation Actions offers a robust solution for automating response and IT operations tasks. By integrating with ServiceNow and utilizing data-driven queries, it reduces manual workloads, enhances efficiency, and helps organizations maintain a proactive stance on security and operational management. We hope this documentation equips you to fully leverage this feature for your organization’s needs.


Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Eddy AI, facilitating knowledge discovery through conversational intelligence