Alerting

Sending Splunk Alert to SNOW and automatically create an incident ticket

spl_unker
Explorer

Hello Splunkers ,

I want to like to integrate Splunk and ServiceNow and  send the triggered alerts to SNOW as an incident. I know there is an app in Splunkbase to integrate with SNOW. But i dont find the steps on how to configure to send the alerts as an incident in SNOW. 

Can someone help me with the high level steps?

 

Thanks in Advance

Labels (1)
Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Latest version of splunk add-on for servicenow is 6.0.3

okay, follow below steps:

  • configure your servicenow instance with app recommended in add-on doc.
  • once servicenow instance is configured, you will get URL and credentials. 
  • install TA on search head
  • Configure URL and credentials in TA.
  • create a search and save it as alert.
  • add alert action incident create from servicenow
  • fill details 

if you found this useful, up vote.

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

do you have enterprise security in place ? 

which version of Splunk add-on for service now are you using?

————————————
If this helps, give a like below.
0 Karma

spl_unker
Explorer

No , I  have a Non-ES Splunk. Im yet to install the SNOW add-on . Just exploring the steps before installing the SNOW. However i will be using the latest version 4.0.3.

 

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...