Alerting

Sending Splunk Alert to SNOW and automatically create an incident ticket

spl_unker
Explorer

Hello Splunkers ,

I want to like to integrate Splunk and ServiceNow and  send the triggered alerts to SNOW as an incident. I know there is an app in Splunkbase to integrate with SNOW. But i dont find the steps on how to configure to send the alerts as an incident in SNOW. 

Can someone help me with the high level steps?

 

Thanks in Advance

Labels (1)
Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Latest version of splunk add-on for servicenow is 6.0.3

okay, follow below steps:

  • configure your servicenow instance with app recommended in add-on doc.
  • once servicenow instance is configured, you will get URL and credentials. 
  • install TA on search head
  • Configure URL and credentials in TA.
  • create a search and save it as alert.
  • add alert action incident create from servicenow
  • fill details 

if you found this useful, up vote.

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

do you have enterprise security in place ? 

which version of Splunk add-on for service now are you using?

————————————
If this helps, give a like below.
0 Karma

spl_unker
Explorer

No , I  have a Non-ES Splunk. Im yet to install the SNOW add-on . Just exploring the steps before installing the SNOW. However i will be using the latest version 4.0.3.

 

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...