All Apps and Add-ons

Allow non-Splunk Admins to add the ServiceNow action to alerts

mjones1
Engager

We have this stood up and working...sort of.  Splunk Admins can configure alerts to add the "ServiceNow Incident Integration" action, and we can create Incidents in Splunk.

The problem is, we have a lot of development teams that create/maintain their own alerts in Splunk.  When they go to add this action, they're not able to select the account to use when configuring the action...because they don't have read permission to the account.  Even if an Admin goes in and configures the action, it won't work at run-time, because the alert runs under the owner's permissions...which can't read the credentials to use to call ServiceNow.

Has anyone else ran into this issue?  How can this be setup to allow non-Admins to maintain alerts?

Labels (2)
0 Karma
1 Solution

Rdm
Engager

I faced this same issue. Resolved it by adding list_storage_passwords capability to Non-admin Role

View solution in original post

0 Karma

mjones1
Engager

Yeah, that is the solution we ended up with as well.

0 Karma

Rdm
Engager

I faced this same issue. Resolved it by adding list_storage_passwords capability to Non-admin Role

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...