Alerting

Is it possible to configure the ServiceNow Incident Integration trigger action via the API?

mp32
New Member

I have the Service Now add-on for Splunk installed and I'm referencing this document for configuring  ServiceNow as a trigger action. Here's a screenshot from the doc for reference:

Screenshot 2023-02-13 at 11.33.10 AM.png

 

My question is, can steps 7 and 8 be done via the Splunk the API? I have about 100 alerts and what I'd like to do is perform steps 7 and 8 programmatically (Where I create a trigger action that uses ServiceNow Incident Integration and populates some of the values)

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...