<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ServiceNow Event Integration in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ServiceNow-Event-Integration/m-p/568779#M10326</link>
    <description>&lt;P&gt;Hi Splunkers, How to create Incidents on SNOW from Splunk SPL? We have "ServiceNow Event Integration" alert action in use which creates incidents when an alerts triggers an event but trying to use the same from Splunk search.&lt;/P&gt;&lt;P&gt;Tried using sendalert command as below and got an error:&lt;/P&gt;&lt;P&gt;| sendalert servicenow param.severity="4" param.assigned_to="Assignment group" param.short_description="Alert Name" param.description="This is a test"&lt;BR /&gt;param.u_environment="Dev" param.node=hostname param.resource="Nothing" param.type="Name"&lt;/P&gt;&lt;P&gt;Error:&amp;nbsp;Error in 'sendalert' command: Alert action "Servicenow" not found.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 15:47:00 GMT</pubDate>
    <dc:creator>vamshikn72</dc:creator>
    <dc:date>2021-09-28T15:47:00Z</dc:date>
    <item>
      <title>ServiceNow Event Integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ServiceNow-Event-Integration/m-p/568779#M10326</link>
      <description>&lt;P&gt;Hi Splunkers, How to create Incidents on SNOW from Splunk SPL? We have "ServiceNow Event Integration" alert action in use which creates incidents when an alerts triggers an event but trying to use the same from Splunk search.&lt;/P&gt;&lt;P&gt;Tried using sendalert command as below and got an error:&lt;/P&gt;&lt;P&gt;| sendalert servicenow param.severity="4" param.assigned_to="Assignment group" param.short_description="Alert Name" param.description="This is a test"&lt;BR /&gt;param.u_environment="Dev" param.node=hostname param.resource="Nothing" param.type="Name"&lt;/P&gt;&lt;P&gt;Error:&amp;nbsp;Error in 'sendalert' command: Alert action "Servicenow" not found.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 15:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ServiceNow-Event-Integration/m-p/568779#M10326</guid>
      <dc:creator>vamshikn72</dc:creator>
      <dc:date>2021-09-28T15:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: ServiceNow Event Integration</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ServiceNow-Event-Integration/m-p/568796#M10327</link>
      <description>&lt;P&gt;Have a look at this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usecustomsearchcommands" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usecustomsearchcommands&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 16:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ServiceNow-Event-Integration/m-p/568796#M10327</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-09-28T16:38:48Z</dc:date>
    </item>
  </channel>
</rss>

