other can you please give me solution for this subject
We have a Splunk Dashboard so if two conditions displayed on the latter are true then a P2 ticket needs to be created in Service Now
I would say to create an alert with the same query as dashboard and use SNOW incident create alert action.
For me that's the right way to approach this.
Hope this helps. Please accept the solution if this resolves your issue.
Can you please elaborate on your question of what do you mean by generating incidents based on the Splunk dashboard?
In case you are looking for this:
- You can open the dashboard search by using the magnifier button at bottom of each panel on your dashboard and then in the search window you can use the below command syntax to create an incident as part of the search result on SNOW.
| snowincidentstream
Reference (Find description and examples here) - https://docs.splunk.com/Documentation/AddOns/released/ServiceNow/Usestreamingcommands