Skip to main content

Overview

The Freshservice integration enables ThreatAware to connect with your Freshservice Support Portal, enabling visibility into IT service management, support tickets, and asset management. This integration helps correlate security findings with service management workflows.
Connection Method: API Key Setup Time: 15 minutes Access Required: Freshservice Administrator account

Data collected

The Freshservice integration provides:
  • Company and department information
  • Service management and ticket data
  • Asset inventory information
  • Support request and incident tracking

Use cases

IT Service Integration

Sync security findings with IT service tickets and track remediation

Asset Management Correlation

Correlate assets in ThreatAware with Freshservice asset records

Department Organisation

Organise and track security findings by department or business unit

Compliance Tracking

Link security compliance items to service management workflows

Setup instructions

1

Log in to ThreatAware

Access the ThreatAware dashboard.
  • Navigate to Settings > Systems
  • Search for “Freshservice”
  • Click Connect to open the connection dialog
2

Obtain Freshservice Base URL

Log in to your Freshservice Support Portal with an administrator account.
  • Look at the URL in your browser address bar
  • The base URL is typically: CompanyName.freshservice.com
  • If you use a custom DNS name (e.g., helpdesk.CompanyName.com):
    • Use the original domain: CompanyName.freshservice.com
  • Copy your base URL for the next steps
If you’re unsure of your base domain, check your Freshservice confirmation email or documentation.
3

Access Profile Settings

While logged into Freshservice:
  • Click your profile picture in the top right corner
  • Select Profile settings from the dropdown menu
4

Generate API Key

In your Profile Settings:
  • Look for the API Key section on the right side of the page
  • You may need to complete a Captcha verification to view it
  • Copy the API Key displayed
  • Store it securely
Save your API Key immediately. Treat it as a sensitive credential.
5

Retrieve Department ID

To find the Department ID:
  • Use the Search Bar in Freshservice
  • Type the name of the company/department you want to monitor
  • Ensure Companies is selected in the search filter
  • Navigate to the company’s page
  • Look at the URL in your browser
  • The Department ID is displayed in the URL path
  • Copy the Department ID
Example URL: https://yourcompany.freshservice.com/companies/123456 The Department ID in this example is: 123456
6

Input Details in ThreatAware

Return to the ThreatAware connection form and enter:
  • Base URL: The Freshservice domain (e.g., companyname.freshservice.com)
  • API Key: The key obtained from your profile settings
  • Department ID: The ID retrieved from the company page URL
  • Click Connect to establish the integration
7

Verify Connection

After connecting, verify the integration is working correctly.
  • Check that the Integration Status in ThreatAware shows as Active
  • Wait 5-10 minutes for initial data synchronization
  • Verify Freshservice company and department data appears in ThreatAware

Required credentials

Field Name: Freshservice Base URL Type: String Description: The domain URL for your Freshservice portalFormat: <companyname>.freshservice.com Example: acme.freshservice.com Note: Do not include https:// or trailing slashesIf you use a custom domain, use the underlying Freshservice domain.
Field Name: Freshservice API Key Type: String (sensitive) Description: The API key from your Freshservice profile settings
Store this key securely in your organisation’s password manager. It provides access to your Freshservice data.
Field Name: Freshservice Department ID Type: String Description: The ID for the company/department to monitorFormat: Numeric identifier Where to find: Visible in the company page URL (e.g., /companies/12345) Example: 12345
You can enter multiple Department IDs separated by commas if monitoring multiple departments.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Systems in ThreatAware
    • Confirm the Freshservice integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 10 minutes for the initial data poll
    • Look for Freshservice company and department data appearing in ThreatAware
    • Verify the data matches your Freshservice portal
  3. Test Queries
    • Create a test query to filter by department
    • Verify the results match your Freshservice data
    • Search for specific companies to confirm data accuracy

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the API Key is correctly copied without extra spaces
  • Ensure the key hasn’t expired
  • Confirm you generated the key while logged in as an administrator
  • Try regenerating a new API Key from your profile settings
  • Check that your Freshservice account is active and not suspended
Symptoms: Cannot find or reach the Freshservice URLSolutions:
  • Verify the domain format: companyname.freshservice.com
  • Do not include https:// protocol
  • Check for typos in the company name
  • If using a custom domain, use the underlying Freshservice domain
  • Test the URL in a browser with https:// to verify it’s accessible
Symptoms: Integration connects but no company data appearsSolutions:
  • Verify the Department ID is correct
  • Navigate to the company page and check the URL for the correct ID
  • Ensure the company actually exists in Freshservice
  • Confirm the API key has permission to access the specified department
  • Try searching for the company name to find the correct ID
Symptoms: Integration shows active but no data is visibleSolutions:
  • Verify companies exist in your Freshservice instance
  • Wait at least 10 minutes for initial data synchronization
  • Confirm the Department ID is valid and corresponds to an existing company
  • Check that the API key has read permissions for companies
  • Review Freshservice API documentation for permission requirements

Additional resources

Freshservice Documentation

Official Freshservice documentation for API configuration

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Credential Management
  • Use an administrator account to generate the API Key
  • Store the API Key securely in your organisation’s password manager
  • Rotate API keys annually or per your security policy
  • Document which accounts can generate API keys
  • Monitor for authentication failures in ThreatAware regularly
Integration Management
  • Start by monitoring one department to test integration
  • Expand to additional departments once testing is successful
  • Regularly verify the Department IDs are still valid
  • Update Department IDs if company structure changes
  • Archive or remove integrations for departments no longer needed