<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491691#M60505</link>
    <description>&lt;P&gt;Was able to find this out by reading some additional documentation that is not part of the release notes or upgrade notes for 5.0 of add on. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usescriptedalerts"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usescriptedalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In version 3.1 you did not need to specify the account name directly in your searches in order to use scripted alert action "snow_incident.py"&lt;/P&gt;

&lt;P&gt;This is quite a simple fix but it is not clearly documented and should be part of the release/upgrade notes. If you use "snow_incident.py" and are migrating to version 5.0 from 3.1 or earlier you must specify the account name in your search.&lt;BR /&gt;
&lt;STRONG&gt;| eval account = "accountname"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The account name is the name you gave the account when you set up the  integration in the add on.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 02:38:11 GMT</pubDate>
    <dc:creator>gstefancyk</dc:creator>
    <dc:date>2019-11-21T02:38:11Z</dc:date>
    <item>
      <title>Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491686#M60500</link>
      <description>&lt;P&gt;snow_incident.py is no longer able to run after updating to add-on version 5.0. It cannot actually find the configured account in the add-on. Has anyone run into this issue? &lt;/P&gt;

&lt;P&gt;2019-11-20 08:20:11,022 ERROR pid=175755 tid=MainThread file=snow_ticket.py:_get_service_now_account:226 | Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_snow/bin/snow_ticket.py", line 170, in _get_service_now_account&lt;BR /&gt;
    raise Exception("Account name cannot be empty. Enter a configured account name or create new account by going to Configuration page of the Add-on.")&lt;BR /&gt;
Exception: Account name cannot be empty. Enter a configured account name or create new account by going to Configuration page of the Add-on.&lt;/P&gt;

&lt;P&gt;There is definitely an account configured in the add on and it is working. &lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Gary S. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491686#M60500</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2020-09-30T03:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491687#M60501</link>
      <description>&lt;P&gt;Have you upgraded your ServiceNow Add-on from 3.1.0 to 5.0.0? If yes, then you need to reconfigure your previously configured ServiceNow account. The link for the doc is:  &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Releasenotes#Upgrade"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Releasenotes#Upgrade&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 16:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491687#M60501</guid>
      <dc:creator>uagrawal_splunk</dc:creator>
      <dc:date>2019-11-20T16:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491688#M60502</link>
      <description>&lt;P&gt;Hi @uagrawal_splunk  we have already done that as that is a requirement when upgrading. We are able to pull data using the same exact user account as well. &lt;/P&gt;

&lt;P&gt;We just cannot execute the script "snow_ticket.py" as it cannot find the user account. We use this as a scripted input on our alerts to trigger SNOW tickets. &lt;/P&gt;

&lt;P&gt;GS&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 17:24:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491688#M60502</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2019-11-20T17:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491689#M60503</link>
      <description>&lt;P&gt;I tried but unable to reproduce the issue. Maybe I am missing something.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 18:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491689#M60503</guid>
      <dc:creator>uagrawal_splunk</dc:creator>
      <dc:date>2019-11-20T18:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491690#M60504</link>
      <description>&lt;P&gt;Do you happen to know the difference between these files?&lt;/P&gt;

&lt;P&gt;service_now.conf&lt;BR /&gt;&lt;BR /&gt;
splunk_ta_snow_settings.conf&lt;/P&gt;

&lt;P&gt;It appears in the new version of the add on splunk_ta_snow_settings.conf was added. Notice when restarting splunk it also complains about all of the settings in the "service_now.conf"&lt;/P&gt;

&lt;P&gt;nvalid key in stanza [snow_account] in /opt/splunk/etc/apps/Splunk_TA_snow/local/service_now.conf, line 4: password  (value:  ).&lt;BR /&gt;
                Invalid key in stanza [snow_account] in /opt/splunk/etc/apps/Splunk_TA_snow/local/service_now.conf, line 5: release  (value:  Madrid).&lt;BR /&gt;
                Invalid key in stanza [snow_account] in /opt/splunk/etc/apps/Splunk_TA_snow/local/service_now.conf, line 6: url  (value:  &lt;A href="https://x.x.x.service-now.com" target="_blank"&gt;https://x.x.x.service-now.com&lt;/A&gt;).&lt;BR /&gt;
                Invalid key in stanza [snow_account] in /opt/splunk/etc/apps/Splunk_TA_snow/local/service_now.conf, line 7: username  (value:  &lt;ENCRYPTED&gt;).&lt;/ENCRYPTED&gt;&lt;/P&gt;

&lt;P&gt;That is making me think that that service_now.conf is deprecated or something? Nothing is noted in the documentation though. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491690#M60504</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2020-09-30T03:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add On For ServiceNow 5.0 | snow_incident.py no account found</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491691#M60505</link>
      <description>&lt;P&gt;Was able to find this out by reading some additional documentation that is not part of the release notes or upgrade notes for 5.0 of add on. &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usescriptedalerts"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usescriptedalerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In version 3.1 you did not need to specify the account name directly in your searches in order to use scripted alert action "snow_incident.py"&lt;/P&gt;

&lt;P&gt;This is quite a simple fix but it is not clearly documented and should be part of the release/upgrade notes. If you use "snow_incident.py" and are migrating to version 5.0 from 3.1 or earlier you must specify the account name in your search.&lt;BR /&gt;
&lt;STRONG&gt;| eval account = "accountname"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;The account name is the name you gave the account when you set up the  integration in the add on.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 02:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-On-For-ServiceNow-5-0-snow-incident-py-no-account/m-p/491691#M60505</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2019-11-21T02:38:11Z</dc:date>
    </item>
  </channel>
</rss>

