<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure a lookup in Splunk Add-on for ServiceNow ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300621#M90506</link>
    <description>&lt;P&gt;Refer below doc and try to place lookup at specified position:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Apr 2018 12:30:31 GMT</pubDate>
    <dc:creator>p_gurav</dc:creator>
    <dc:date>2018-04-04T12:30:31Z</dc:date>
    <item>
      <title>How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300617#M90502</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;Got a request to configure a lookup called cmdb_ci_computer.csv  that containing anything with subcategory of computer in a sourcetype=cmdb_ci_list? This should be configured under Splunk_TA_snow/local/savedsearch.conf.&lt;BR /&gt;
Could please guide me how to create and configure this lookup.&lt;/P&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300617#M90502</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T18:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300618#M90503</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;
Can anyone guide me on this &lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 17:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300618#M90503</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-04-02T17:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300619#M90504</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;

&lt;P&gt;Any help will be much appreciated. &lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 10:35:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300619#M90504</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-04-03T10:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300620#M90505</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;

&lt;P&gt;Can anyone throw me some lights on this, I want to know to how to configure a lookup in splunk_TA_servicenow.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:46:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300620#M90505</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2020-09-29T18:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300621#M90506</link>
      <description>&lt;P&gt;Refer below doc and try to place lookup at specified position:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups"&gt;https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Lookups&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 12:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300621#M90506</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-04T12:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300622#M90507</link>
      <description>&lt;P&gt;Hi Gurav, thanks for your inputs, but I had gone through this document and created the below steps, could please guide me whether steps are correct .&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1) Create a empty csv file under Splunk_TA_snow/lookup/cmdb_ci_computer.csv 
2) Create a Eventtype [snow_cmdb_ci_Computer]
     search = sourcetype=snow:cmdb_ci_Computer
3) Map the eventtype in the /local/savedsearches.conf 
[ServiceNow CMDB CI Computer]
disabled = 0
action.email.reportServerEnabled = 0
action.email.useNSSubject = 1
alert.track = 0
cron_schedule = 0 * * * *
description = Saved search which populates the CMDB CI Computer from ServiceNow
dispatch.earliest_time = 0
dispatch.latest_time = now
display.general.type = statistics
display.visualizations.show = 0
enableSched = 1
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = eventtype=snow_cmdb_ci_computer | dedup sys_id | fields - _bkt, _cd,_indextime,_kv,_raw,_serial,_si,_sourcetype,_subsecond, punct, index, source, sourcetype  | inputlookup append=t cmdb_ci_computer_lookup | dedup sys_id | outputlookup cmdb_ci_computer_lookup 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Apr 2018 12:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300622#M90507</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-04-04T12:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300623#M90508</link>
      <description>&lt;P&gt;Do you want to create new lookup or use existing in query?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 13:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300623#M90508</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-04T13:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300624#M90509</link>
      <description>&lt;P&gt;I want to use existing in the query &lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 13:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300624#M90509</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-04-04T13:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a lookup in Splunk Add-on for ServiceNow ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300625#M90510</link>
      <description>&lt;P&gt;Hi Gurav, the below steps helped me to get the required output.&lt;/P&gt;

&lt;P&gt;Procedure : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;1) First executed a simple search command to filter the sourcetype containing only with the field values called Computer from the seleclted field=subcategory

    sourcetype=snow:cmdb_ci_list subcategory=Computer

2) Created a Eventtype in the props.conf with the sourcetype=snow:cmdb_ci_list subcategory=Computer along with other exesisting eventtype in the Splunk_Ta_Snow app

     Eventtype [snow_cmdb_ci_Computer]
     search = sourcetype=snow:cmdb_ci_list subcategory=Computer

3) Created a Savedsearch query with the newly created eventtype to filter the events contains anything with subcategory of "Computer". 

[ServiceNow CMDB CI SUB COMP List]
disabled = 0
action.email.reportServerEnabled = 0
action.email.useNSSubject = 1
alert.track = 0
cron_schedule = 0 * * * *
description = Saved search which populates the CMDB CI contains anything with subcategory of "Computer"
dispatch.earliest_time = 0
dispatch.latest_time = now
display.general.type = statistics
display.visualizations.show = 0
enableSched = 1
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = eventtype=snow_cmdb_ci_Computer | dedup sys_id | fields - _bkt, _cd,_indextime,_kv,_raw,_serial,_si,_sourcetype,_subsecond, punct, index, source, sourcetype  | inputlookup append=t cmdb_ci_list_lookup | dedup sys_id | outputlookup cmdb_ci_list_lookup

4) After finishing with the above steps the app was pushed to the search head cluster environement via deployer. 

 /opt/splunk/bin
./splunk apply shcluster-bundle --answer-yes -target &lt;A href="https://splunkinstancename:8089" target="test_blank"&gt;https://splunkinstancename:8089&lt;/A&gt; -auth admin:password 

5) We are able to see the required output in splunk with the events containing the field values called Computer from the seleclted field=subcategory.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Apr 2018 14:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-configure-a-lookup-in-Splunk-Add-on-for-ServiceNow/m-p/300625#M90510</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-04-05T14:41:00Z</dc:date>
    </item>
  </channel>
</rss>

