Freshservice Integration with DefectDojo
Freshservice Integration with DefectDojo
Freshservice is an IT service management (ITSM) platform from Freshworks, delivered as a cloud service. IT and operations teams use it to run their service desk: tickets, agent groups, workspaces, priorities, and business rules that route and escalate work. DefectDojo Pro connects to Freshservice through a Downstream Connector that pushes DefectDojo Findings and Finding Groups out to Freshservice as tickets assigned to the agent group you choose. Nothing is imported from Freshservice into DefectDojo.
Freshservice Integration with DefectDojo
We connected DefectDojo to Freshservice because a lot of our remediation is done by IT operations, not developers, and IT operations works from the service desk. Patching a server or reconfiguring a network device was getting lost when it lived only as a Finding. Now DefectDojo opens a Freshservice ticket for the right agent group, maps the Finding's severity to ticket priority, and closes the ticket when the Finding is resolved, so the work and its status stay in the tool the assignees already use every day.
Why Freshservice Matters
For many organizations, the service desk is where infrastructure work gets assigned, prioritized, and measured.
- Agent groups already reflect who handles servers, endpoints, networks, and applications, which is exactly the routing security findings need.
- Priorities and business rules in Freshservice drive how fast work is picked up, so findings that become tickets inherit an established process.
- Operations teams report on their ticket queues. Security work that sits outside those queues is invisible to the people measuring throughput.
- Asking IT staff to log into a separate security tool to find their work is a reliable way to slow remediation down.
Advantages of This Integration
What the Freshservice Downstream Connector gives a DefectDojo Pro team:
- Tickets routed to the right group. Every ticket is assigned to the Freshservice agent group set in the Issue Tracker Mapping, and multiple mappings can send different Assets to different groups.
- Severity becomes priority. DefectDojo severities map to Freshservice priority codes, so Critical findings arrive as Urgent tickets by default.
- Status kept in step. Finding status maps to ticket status, so a closed, false positive, or risk-accepted Finding is reflected on the ticket.
- Full content updates. Updates sync the full ticket content, because Freshservice allows the subject and description to be edited after creation.
- Clean closures. Tickets are closed rather than deleted when a Finding is removed, and a resolution note is attached automatically so accounts that require one accept the close.
- Priority that sticks. If a business rule or Impact and Urgency matrix overrides the priority sent at creation, DefectDojo detects it and re-applies the mapped priority with a follow-up update.
How This Integration Works
Downstream Connectors are a DefectDojo Pro feature, configured under Connect > Downstream. Setup has three parts: an Integration Instance, an Issue Tracker Mapping, and an Issue Tracker Assignment.
1. Create the Integration Instance. Give it a label and set the Location to your Freshservice URL (for example https://yourcompany.freshservice.com). Add a Freshservice API key: in Freshservice, click your profile picture, open Profile settings, and find the key below the Delegate Approvals section. If no key is shown, API access may be disabled at the account level and an administrator has to enable it. Enter a Requester Email; Freshservice requires a requester on every ticket, so DefectDojo creates tickets on behalf of this address.
2. Create the Issue Tracker Mapping. Enter the numeric Group ID of the agent group that should receive tickets (it appears in the URL when you view the group under Admin > Agent Groups). On multi-workspace accounts, optionally enter a Workspace ID; leave it empty to use the primary workspace. Review the severity and status mappings.
3. Assign Assets or Engagements. Create an Issue Tracker Assignment for each Asset or Engagement that should send tickets. Choose whether Findings are pushed only explicitly, automatically when created, automatically when an existing link is edited, or automatically on both.
4. Push. With an assignment in place, Findings and Finding Groups in that Asset or Engagement show a Push to Integrator option for manual pushes, and automatic options handle the rest. Push filters on the assignment can limit automatic creation to a Minimum Severity and to active Findings only.
Data Granularity: What Gets Sent
| DefectDojo Side | Freshservice Side | Notes |
|---|---|---|
| Finding or Finding Group | Ticket | Created by Push to Integrator or automatically |
| Issue Tracker Mapping Group ID | Agent group | Every ticket is assigned to this group |
| Workspace ID (optional) | Workspace | Primary workspace when empty |
| Requester Email | Ticket requester | Required by Freshservice on every ticket |
| Severity Info / Low | Priority 1 (Low) |
Default mapping |
| Severity Medium | Priority 2 (Medium) |
Default mapping |
| Severity High | Priority 3 (High) |
Default mapping |
| Severity Critical | Priority 4 (Urgent) |
Default mapping |
| Status Active | Status 2 (Open) |
Default mapping |
| Status Closed / False Positive | Status 5 (Closed) |
Default mapping |
| Status Risk Accepted | Status 3 (Pending) |
Default mapping |
| Ticket link | Ticket ID and URL | Shown in the Integrator Tickets column with a changelog |
Priority and status names are accepted as well as the numeric codes. Tickets that are already Resolved or Closed in Freshservice are left untouched when DefectDojo closes a Finding.
Use Cases
Infrastructure remediation: Findings from network and host scanners on server Assets are pushed to the infrastructure agent group. Operations staff work them like any other ticket, and DefectDojo tracks the SLA against the Finding.
Routing by ownership: Separate Issue Tracker Mappings point endpoint Assets at the desktop support group and cloud Assets at the platform group, so each ticket lands with the team that can fix it.
Grouped work: Pushing a Finding Group creates one ticket for many related Findings, such as the same missing patch across a fleet, instead of a ticket per host.
Risk acceptance visibility: When a Finding is risk-accepted in DefectDojo, its ticket moves to Pending by default, which tells the operations team the work is parked rather than forgotten.
Operational Tips
- Confirm API access is enabled at the account level before setup. A missing API key on the profile page usually means an administrator has turned it off.
- Use a dedicated requester address, such as a security team mailbox, so tickets created by DefectDojo are easy to filter in Freshservice.
- Start automatic creation with a Minimum Severity of High and Active findings only, then widen it once the receiving group is comfortable with the volume.
- Check the default status mapping. False Positive maps to Closed and Risk Accepted to Pending; change these if your service desk uses different conventions.
- If your account computes priority from an Impact and Urgency matrix, expect a follow-up update on new tickets as DefectDojo re-applies the mapped priority.
- Watch the Total Errors column on the Issue Tracker Mappings page for authentication or permission failures, and use Diagnostics to see failures across every connector.