<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manage engine ITSM in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746943#M118697</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310469"&gt;@Karthickb2308&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No one-click integration for CMDB or ticketing, but REST API and Splunk alert actions make it achievable.&lt;/P&gt;&lt;P&gt;Use the ServiceDeskPlus Splunk app for supported ticket actions(If you have Splunk SOAR), or build your own with Python/REST.&lt;/P&gt;&lt;P&gt;For CMDB, use exports/API to sync data into Splunk for enrichment and correlation.&lt;/P&gt;&lt;P&gt;Also a simple alternative -If you can’t use the API, configure Splunk to send alert emails to ManageEngine’s ticket creation email address (less flexible, but simple).&lt;/P&gt;</description>
    <pubDate>Tue, 27 May 2025 04:36:26 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-05-27T04:36:26Z</dc:date>
    <item>
      <title>Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746937#M118694</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need help with Manage engine ticketing tool integration with Splunk i have researched in Google did not find any exact document please provide your inputs if anyone has integrated these one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Goal&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) CMDB integration&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Automatically create a ticket for each splunk enterprise security alerts&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 03:04:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746937#M118694</guid>
      <dc:creator>Karthickb2308</dc:creator>
      <dc:date>2025-05-27T03:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746938#M118695</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310469"&gt;@Karthickb2308&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;To integrate ManageEngine ServiceDesk Plus CMDB with Splunk, the goal is typically to sync asset and configuration item (CI) data between the two systems for better incident context and correlation. Since no direct Splunk app exists for ManageEngine CMDB.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Log Forwarding from ManageEngine to Splunk&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://www.manageengine.com/products/self-service-password/adselfservice-plus-integrations.html" target="_blank"&gt;https://www.manageengine.com/products/self-service-password/adselfservice-plus-integrations.html&lt;/A&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A href="https://www.manageengine.com/products/ad-manager/help/admin-settings/third-party-integrations/splunk.html" target="_blank" rel="noopener"&gt;https://www.manageengine.com/products/ad-manager/help/admin-settings/third-party-integrations/splunk.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 03:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746938#M118695</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-27T03:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746939#M118696</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310469"&gt;@Karthickb2308&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no out of the box feature that lets you do this.&lt;/P&gt;&lt;P&gt;However, If you have a script that can create tickets in Manage Engine Service Desk, You can have your Splunk alert call that python script when the alert triggers&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.servicedeskplus.com/api/rest-api.html" target="_blank" rel="noopener"&gt;https://help.servicedeskplus.com/api/rest-api.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ManageEngine ServiceDesk Plus supports ticket creation via its REST API (endpoint: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/api/v3/requests&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 27 May 2025 03:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746939#M118696</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-27T03:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746943#M118697</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310469"&gt;@Karthickb2308&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No one-click integration for CMDB or ticketing, but REST API and Splunk alert actions make it achievable.&lt;/P&gt;&lt;P&gt;Use the ServiceDeskPlus Splunk app for supported ticket actions(If you have Splunk SOAR), or build your own with Python/REST.&lt;/P&gt;&lt;P&gt;For CMDB, use exports/API to sync data into Splunk for enrichment and correlation.&lt;/P&gt;&lt;P&gt;Also a simple alternative -If you can’t use the API, configure Splunk to send alert emails to ManageEngine’s ticket creation email address (less flexible, but simple).&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 04:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746943#M118697</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-05-27T04:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746945#M118698</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310469"&gt;@Karthickb2308&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As others have mentioned, there arent currently any Splunkbase apps to write back to ManageEngine ITSM with Splunk for CMDB synchronization and automated ticket creation from Enterprise Security alerts, however you can achieve this in a couple of ways:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Custom App&amp;nbsp;&lt;/STRONG&gt;- You could use the ManageEngine API (&lt;A href="https://www.manageengine.com/products/service-desk/sdpod-v3-api/SDPOD-V3-API.html" target="_blank"&gt;https://www.manageengine.com/products/service-desk/sdpod-v3-api/SDPOD-V3-API.html&lt;/A&gt;) to build a custom app using &lt;A href="https://splunk.github.io/addonfactory-ucc-generator/" target="_self"&gt;Splunk UCC Framework&lt;/A&gt; - UCC is a great way to start &lt;A href="https://splunk.github.io/addonfactory-ucc-generator/inputs/" target="_self"&gt;building inputs&lt;/A&gt; (to import your CMDB data) and also &lt;A href="https://splunk.github.io/addonfactory-ucc-generator/alert_actions/" target="_self"&gt;create modular alert actions&lt;/A&gt; (to raise incidents from Enterprise Security).&amp;nbsp; Also see&amp;nbsp;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtocreatemodpy/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtocreatemodpy/&lt;/A&gt;&amp;nbsp;for more background on creating inputs.&lt;/LI&gt;&lt;LI&gt;Use the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/1546/" target="_blank"&gt;REST API Modular Input add-on&lt;/A&gt;&amp;nbsp;app to use the same &lt;A href="https://www.manageengine.com/products/service-desk/sdpod-v3-api/SDPOD-V3-API.html" target="_self"&gt;Manage Engine API&lt;/A&gt;&amp;nbsp;from within SPL, you can use scheduled searches to utilise the app's "curl" command against ManageEngine's REST API to fetch &lt;A href="https://www.manageengine.com/products/service-desk/sdpod-v3-api/cmdb/configuration_item.html" target="_self"&gt;CMDB data&lt;/A&gt;. You could create a macro to write incidents using the same command and call this at the end of searches where you would normally create an alert action. Note - the curl command doesnt actually use curl, so not every parameter is supported, it uses python requests under-the-hood (see&amp;nbsp;&lt;A href="https://www.baboonbones.com/php/markdown.php?document=rest/README.md" target="_blank"&gt;https://www.baboonbones.com/php/markdown.php?document=rest/README.md&lt;/A&gt;)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Hopefully one of these two options helps you move forwards with your integration with ManageEngine into Splunk - please let me know you have any questions&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 07:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746945#M118698</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-27T07:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Manage engine ITSM</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746953#M118700</link>
      <description>&lt;P&gt;Thanks kiran for the support&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 07:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manage-engine-ITSM/m-p/746953#M118700</guid>
      <dc:creator>Karthickb2308</dc:creator>
      <dc:date>2025-05-27T07:40:26Z</dc:date>
    </item>
  </channel>
</rss>

