<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to integrate Incident management ticketing tool with splunk enterprise? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453744#M78583</link>
    <description>&lt;P&gt;I have tried to find an app that can integrate Incident management ticketing tool with splunk but couldn'd. Is there any other option that can be used to do so?&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2019 12:01:37 GMT</pubDate>
    <dc:creator>Vinesh93</dc:creator>
    <dc:date>2019-05-13T12:01:37Z</dc:date>
    <item>
      <title>How to integrate Incident management ticketing tool with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453744#M78583</link>
      <description>&lt;P&gt;I have tried to find an app that can integrate Incident management ticketing tool with splunk but couldn'd. Is there any other option that can be used to do so?&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 12:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453744#M78583</guid>
      <dc:creator>Vinesh93</dc:creator>
      <dc:date>2019-05-13T12:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate Incident management ticketing tool with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453745#M78584</link>
      <description>&lt;P&gt;Quite few lot of options&lt;/P&gt;

&lt;P&gt;High level, two ways&lt;BR /&gt;
1. Pull option . =&amp;gt; You poll regularly from the Incident Management tool into Splunk (eg API of your tool, SOAP, directly Database etc.)&lt;BR /&gt;
2. Push option . =&amp;gt; The Tool can send the data to you (mostly HEC)&lt;/P&gt;

&lt;P&gt;For option1, lot of incident management tools have addons (TA) for example &lt;A href="https://splunkbase.splunk.com/app/1928/"&gt;ServiceNow Addon&lt;/A&gt; which can you just configure with credentials to pull information on regular basis.&lt;BR /&gt;
There are &lt;A href="https://splunkbase.splunk.com/apps/#/search/incident/"&gt;other few as well&lt;/A&gt; apps too. &lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 13:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453745#M78584</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-13T13:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate Incident management ticketing tool with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453746#M78585</link>
      <description>&lt;P&gt;It would help if you said what incident management tool you use.  If you don't find an app in splunkbase, you still have a few options:&lt;/P&gt;

&lt;P&gt;1) Contact the vendor to see if they have an app for Splunk&lt;BR /&gt;
2) Install a universal forwarder on the system hosting the IM software and forward logs/files to Splunk&lt;BR /&gt;
3) Use the vendor's API to create a modular input to extract the information you desire&lt;BR /&gt;
4) Use DB Connect to extract data from the IM system's SQL database.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 13:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-Incident-management-ticketing-tool-with-splunk/m-p/453746#M78585</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-13T13:20:49Z</dc:date>
    </item>
  </channel>
</rss>

