<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple incident creation on servicenow through  splunk in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Multiple-incident-creation-on-servicenow-through-splunk/m-p/534350#M9598</link>
    <description>&lt;DIV&gt;&lt;DIV&gt;Hi All,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;I'm working on a requirement to create a Splunk Alert which triggers/Creates the Incident in Service Now portal.&lt;BR /&gt;I want the alert to create multiple incidents for each result.&lt;BR /&gt;My Findings : The alert creates Single Incident with multiple events for each result in ServiceNow.&lt;BR /&gt;Requirement : Alert should be able to create Incident for each result in ServiceNow.&lt;/DIV&gt;&lt;DIV&gt;How can this be achieved?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 29 Dec 2020 13:14:35 GMT</pubDate>
    <dc:creator>yashaswinig2210</dc:creator>
    <dc:date>2020-12-29T13:14:35Z</dc:date>
    <item>
      <title>Multiple incident creation on servicenow through  splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Multiple-incident-creation-on-servicenow-through-splunk/m-p/534350#M9598</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;Hi All,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;I'm working on a requirement to create a Splunk Alert which triggers/Creates the Incident in Service Now portal.&lt;BR /&gt;I want the alert to create multiple incidents for each result.&lt;BR /&gt;My Findings : The alert creates Single Incident with multiple events for each result in ServiceNow.&lt;BR /&gt;Requirement : Alert should be able to create Incident for each result in ServiceNow.&lt;/DIV&gt;&lt;DIV&gt;How can this be achieved?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Dec 2020 13:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Multiple-incident-creation-on-servicenow-through-splunk/m-p/534350#M9598</guid>
      <dc:creator>yashaswinig2210</dc:creator>
      <dc:date>2020-12-29T13:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple incident creation on servicenow through  splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Multiple-incident-creation-on-servicenow-through-splunk/m-p/535059#M9607</link>
      <description>&lt;P&gt;After creating the correlation search and alert action to be service now incident,&lt;/P&gt;&lt;P&gt;goto setting-&amp;gt; search,reports and alerts, find you search. Click on it, scroll down and change the trigger to each result from once and it should create one incident per row of your result&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 15:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Multiple-incident-creation-on-servicenow-through-splunk/m-p/535059#M9607</guid>
      <dc:creator>rajashekar_s</dc:creator>
      <dc:date>2021-01-07T15:10:14Z</dc:date>
    </item>
  </channel>
</rss>

