<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264429#M1990</link>
    <description>&lt;P&gt;My thoughts exactly, but my Service Now in house SME states that the Service Now Security Operations app requires a Service Now add on we do not have.  Looking for feedback on what Service Now side apps the Splunk app requires.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Dec 2016 01:33:08 GMT</pubDate>
    <dc:creator>nychawk</dc:creator>
    <dc:date>2016-12-09T01:33:08Z</dc:date>
    <item>
      <title>What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264424#M1985</link>
      <description>&lt;P&gt;Hello;&lt;/P&gt;

&lt;P&gt;I am running Splunk Enterprise Security and would like to enable security events to trigger events in Service Now, and create a ServiceNow ticket.&lt;BR /&gt;
I would like to also allow users and other non-ES applications to create ServiceNow tickets.&lt;/P&gt;

&lt;P&gt;I was wondering what the differences between this app, and &lt;A href="https://splunkbase.splunk.com/app/3192/"&gt;https://splunkbase.splunk.com/app/3192/&lt;/A&gt; are?  &lt;/P&gt;

&lt;P&gt;Incidentally, I am running Helsinki; in case that matters.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 20:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264424#M1985</guid>
      <dc:creator>nychawk</dc:creator>
      <dc:date>2016-12-06T20:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264425#M1986</link>
      <description>&lt;P&gt;Hi @nychawk&lt;/P&gt;

&lt;P&gt;To clarify for other users, are you trying to compare ServiceNow Security Operations with the Splunk App for ServiceNow? or are you trying to compare ServiceNow Security Operations with Splunk Enterprise Security? &lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 20:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264425#M1986</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-12-06T20:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264426#M1987</link>
      <description>&lt;P&gt;I've been playing with both, it seems the security app is more focused as a "alert action" or ES action item for notable events. The Splunk app and addon for ServiceNow seem to be focused on monitoring your servicenow environment using Splunk similar to other apps (such as the infrastructure focused apps), and working as an alternative to SNOWs reporting and performance analytics items. It also has the added benefits of creating incidents and events, though I don't think it is as refined as the "Security" app (but it is only for incidents). &lt;/P&gt;

&lt;P&gt;I'm definitely interested to hear about this from an expert though. In my experience so far, if you're very good with the SNOW app for Splunk then you don't need to use the Security app, however the Security app is much easier to setup and use. In my situation, I'm planning on using the SNOW app on our "regular" search head for all of those items, but using the "Security" SNOW app on the ES search head to save time and resources on the devices.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 20:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264426#M1987</guid>
      <dc:creator>goodsellt</dc:creator>
      <dc:date>2016-12-06T20:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264427#M1988</link>
      <description>&lt;P&gt;Thanks for the info. I added the official app tags for Splunk Enterprise Security and Splunk App for ServiceNow to get more visibility on you question. Hope you find an answer soon!&lt;/P&gt;

&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 20:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264427#M1988</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-12-06T20:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264428#M1989</link>
      <description>&lt;P&gt;I am looking for differences between ServiceNow Security Operations and the Splunk App for ServiceNow&lt;/P&gt;

&lt;P&gt;Both of these allow creation of new tickets, the second one above seems to a lot of work to implement, the first I "believe" requires a Snow add on, not sure&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 01:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264428#M1989</guid>
      <dc:creator>nychawk</dc:creator>
      <dc:date>2016-12-09T01:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264429#M1990</link>
      <description>&lt;P&gt;My thoughts exactly, but my Service Now in house SME states that the Service Now Security Operations app requires a Service Now add on we do not have.  Looking for feedback on what Service Now side apps the Splunk app requires.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 01:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264429#M1990</guid>
      <dc:creator>nychawk</dc:creator>
      <dc:date>2016-12-09T01:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: What are the differences between the Splunk App for ServiceNow and ServiceNow Security Operations?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264430#M1991</link>
      <description>&lt;P&gt;The Splunk Add-on for ServiceNow and the Splunk App for ServiceNow are built and supported by Splunk.  The ServiceNow Security Operations app was built by ServiceNow.  The Helsinki release of ServiceNow introduced a different class of incidents and events that were more geared toward security rather than general.  These integration endpoints for these classes of of incidents and events are different.  So, ServiceNow created an app to integrate directly with these.&lt;/P&gt;

&lt;P&gt;Check out the release notes for Helsinki here where the Splunk integration is mentioned -&amp;gt; &lt;A href="https://docs.servicenow.com/bundle/helsinki-release-notes/page/release-notes/security-operations/r_SecurityIncidentResponseRN.html"&gt;https://docs.servicenow.com/bundle/helsinki-release-notes/page/release-notes/security-operations/r_SecurityIncidentResponseRN.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Summary:&lt;BR /&gt;
The &lt;STRONG&gt;Splunk Add-on for ServiceNow&lt;/STRONG&gt; is the foundation that collects data from ServiceNow and integrates with their APIs.  There is very little user interface involved here and no out-of-the-box intelligence about the data.  This add-on is built and supported by Splunk.&lt;/P&gt;

&lt;P&gt;The &lt;STRONG&gt;Splunk App for ServiceNow&lt;/STRONG&gt; depends on the Splunk Add-on for ServiceNow to collect data.  The Splunk App for ServiceNow has out-of-the-box intelligence about the ServiceNow data and several dashboards.  This app is built and supported by Splunk.&lt;/P&gt;

&lt;P&gt;The &lt;STRONG&gt;ServiceNow Security Operations&lt;/STRONG&gt; app adds security-specific incident and event integration.  This app is Splunk Certified, but it is built and supported by ServiceNow.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2016 16:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/What-are-the-differences-between-the-Splunk-App-for-ServiceNow/m-p/264430#M1991</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2016-12-09T16:06:52Z</dc:date>
    </item>
  </channel>
</rss>

