ServiceNow Ticketing Connector Enhancements
Overview
The Balbix ServiceNow RITM integration via the D3 Connector enables organizations to streamline the creation of ServiceNow Requested Item (RITM) tickets from Balbix vulnerability insights. By working at the RITM level, the integration aligns directly with ServiceNow’s fulfillment model, offering precise control over how remediation tasks are assigned, tracked, and resolved.
This integration emphasizes structured workflows, field-level flexibility, and governance — capabilities that are especially valuable when managing large-scale vulnerability remediation across dynamic IT environments.
Understanding RITM in ServiceNow
In ServiceNow:
A Request (REQ) represents the overall submission from the service catalog.
Each Requested Item (RITM) within the request is an individual item or service with its own lifecycle.
RITMs support independent fulfillment, tasking, and SLAs — providing better granularity in execution and reporting.
By ticketing at the RITM level, organizations can assign precise responsibility, map vulnerability remediation tickets to the correct catalog workflows, and avoid the inefficiencies of umbrella-style requests that lack structure or specificity.
Why Use Ticketing Templates
Ticketing templates define the structure, content, and logic for how tickets are created. Balbix uses a template-first model to promote consistency, streamline user workflows, and enable automation without sacrificing flexibility.
Key Benefits
Consistent Ticket Quality Templates standardize which fields are filled, how they’re formatted, and what values are applied — reducing ambiguity and ensuring cleaner handoffs to IT fulfillment teams.
Operational Efficiency Teams avoid repetitive data entry and can spin up tickets more quickly with confidence that required data is already in place.
Ready for Automation Templates form the foundation for automated ticket generation, allowing organizations to define conditions for when and how tickets are created (e.g., severity, asset group, exposure type).
ServiceNow-Centric Alignment Templates are directly mapped to ServiceNow’s catalog hierarchy (Catalogs, Categories, Items), allowing security workflows to integrate smoothly into existing ITSM structures — without requiring custom mappings or overrides.
Granular Field-Level Control For each ticket field, teams can specify whether it should be:
Shown or hidden
Required or optional
Populated by default
This enables leaner ticket forms for users while still enforcing the inclusion of key remediation data.
Reusable and Governed Framework Templates can be used across multiple tickets, teams, and automation rules, helping maintain consistency across organizational units and over time.
This model helps bridge the gap between vulnerability management and IT operations — offering a path to scale ticketing processes in a structured, governed manner, without requiring manual configuration for every new issue.
Integration Features
1. Smarter Field Handling
Dynamically pulls fields from ServiceNow, ensuring alignment with the live schema.
Flexible and intuitive configuration, modeled after the Jira connector.
2. Ticket Templates for Reusability
Define catalog selections, field defaults, and field visibility.
Apply templates across workflows, reducing duplication and error.
3. Streamlined Ticketing Rule Configuration
Configure rules with pre-populated field values.
Auto-fill mandatory fields and hide non-relevant ones.
Maintain clean UI and consistent data input.
4. Enhanced User Experience
Auto-populates the “User” field with integration_user.
Removes clutter by hiding VSET... fields.
5. Dropdown Field Enhancements
Application and Application Owner fields are shown as dropdowns.
Populated dynamically from ServiceNow for faster and more accurate entry.
6. Improved CSV Handling
CSVs generated from Balbix are now attached at the RITM level, not the REQ.
7. Granular Field Visibility
Hide optional/required fields with pre-filled fixed values (e.g., Security Tool Source = Balbix).
8. Enhanced Toggle Controls
Enable/disable toggles available per field.
Required fields must be populated before disabling.
9. Ticketing Details Page
Tickets display all fields in a key-value format.
Designed for audit and review use cases.
Creating a Ticketing Template
Step 1: Create a New Ticketing Rule
Go to Company Settings > Exposure Management > Project/Ticketing Rules and click Create Rule
Enter:
A Rule Name
The Exposure Type (e.g., Asset Vulnerabilities)
Step 2: Select the Ticketing System and Instance
Choose:
Ticketing System: ServiceNow Ticketing
Instance: the applicable integration (e.g., NOW_RITM_Edit)
This supports environments with multiple ServiceNow instances or segmented workflows.
Step 3: Configure Ticket Fields
Select field values from ServiceNow’s live catalog:
Catalog, Category, and Item
Additional specs like Request Type, Security Severity, Environment and other fields
Dropdowns are dynamically populated to reflect current values, ensuring only valid configurations are available at ticket time.
Step 4: Control Field Visibility and Behavior
Each field can be:
Required: user must fill or confirm the value, required fields indicated with an (*)
Optional: value can be skipped or overridden
Hidden: not shown to the user but set in the backend
This allows teams to reduce UI clutter while still enforcing data completeness.
Step 5: Review and Finalize the Template
Balbix provides a comprehensive summary showing:
All configured fields
Field behaviors and values
Dropdown mappings and defaults
Once confirmed, the template becomes available for ticket creation (manual or automated).
Creating a Ticket Using a Template
Step 1: Go to Asset Vulnerabilities
From the Asset Vulnerabilities view, select vulnerabilities to be addressed and click Create Tickets.
Step 2: Choose Ticket Creation Method
Select:
From Ticketing Rule: applies an existing ticketing rule
From Scratch: allows manual field entry
Using a template reduces effort and promotes uniformity across tickets.
Step 3: Review and Modify Auto-Filled Fields
Fields are auto-filled from the template, but you can override them as needed for this specific ticket.
Changes made here do not modify the original template.
This supports flexibility for edge cases while maintaining overall structure.
Step 4: Confirm and Submit the Ticket
Preview all ticket fields and associated vulnerability data. Confirm when ready.
Step 5: Ticket Appears in the List
After submission, the ticket appears in the Tickets list. Users can:
Track status
Edit certain metadata
View associated attachments
View Ticket in List
Once created, the ticket will appear in the list of tickets under the applicable section.
Ticket creation time may vary depending on the number of vulnerabilities included. The ticket will transition to active status once fully processed by ServiceNow.
Edit Meta Data (Where Allowed)
Some metadata fields can still be edited after ticket creation.
Select Edit Columns to adjust the attributes displayed for each ticket within the Tickets table view, as desired.
Wait for Ticket to Fully Populate
Depending on the number of vulnerability instances linked to the ticket, the creation process may take time before the ticket becomes fully populated and active. The ticket creation times are dependent on the associated number of remediation instances. It could vary from a few minutes for a few thousand instances up to an hour for over a million instances.
Summary
The Balbix ServiceNow RITM connector provides a structured and governed approach to transforming vulnerability data into actionable remediation tickets. It supports:
Reusable ticketing templates with dynamic field control
Tight integration with ServiceNow’s catalog structure
Automation-ready design for scheduled or condition-based ticketing
Flexibility to balance consistency with one-off adjustments
The integration is well-suited to organizations looking to scale remediation workflows across diverse teams, while maintaining high data quality and alignment with IT service processes.